575 MB
/srv/reproducible-results/rbuild-debian/r-b-build.Q8kIuHRE/b1/scap-security-guide_0.1.76-1_amd64.changes vs.
/srv/reproducible-results/rbuild-debian/r-b-build.Q8kIuHRE/b2/scap-security-guide_0.1.76-1_amd64.changes
824 B
Files
    
Offset 1, 6 lines modifiedOffset 1, 6 lines modified
  
1 ·d36714098310c5b17293d6acb293378c·153740·admin·optional·ssg-applications_0.1.76-1_all.deb1 ·7f504e58a8da5d2ba928e76b0e83de64·153736·admin·optional·ssg-applications_0.1.76-1_all.deb
2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb2 ·ea0c1f19113a8a6c0a6e8b10e8e208a9·32632·admin·optional·ssg-base_0.1.76-1_all.deb
3 ·abae8d0d223f94d2f794d05fe134db50·3724864·admin·optional·ssg-debderived_0.1.76-1_all.deb 
4 ·94bd4cf881119e3ff0b5dc31c11aa740·1230692·admin·optional·ssg-debian_0.1.76-1_all.deb 
5 ·90e485fe0aaf14a58be9ded81e6c460a·37097376·admin·optional·ssg-nondebian_0.1.76-1_all.deb3 ·afad260d53ada731e19bc8bcdf7c8468·3723808·admin·optional·ssg-debderived_0.1.76-1_all.deb
 4 ·8f218f5ee7f38699f32d8a104ba4aebf·1230304·admin·optional·ssg-debian_0.1.76-1_all.deb
 5 ·1cfcda0f157df7fb546d99fed310cda5·37092380·admin·optional·ssg-nondebian_0.1.76-1_all.deb
419 KB
ssg-applications_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1728·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0···151820·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0···151816·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
418 KB
data.tar.xz
418 KB
data.tar
76.5 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
76.4 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-chromium-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-chromium-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">28 ······<cpe-dict:cpe-item·name="cpe:/a:google:chromium-browser">
29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Google·Chromium·Browser</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-chromium-cpe-oval.xml">oval:ssg-installed_app_is_chromium:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_CHROMIUM"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Chromium</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Chromium.·It·is·a·rendering·of40 configuration·settings·for·Chromium.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 1675, 15 lines modifiedOffset 1675, 15 lines modified
1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">1675 ··········<xccdf-1.2:check·system="http://scap.nist.gov/schema/ocil/2">
1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>1676 ············<xccdf-1.2:check-content-ref·href="ssg-chromium-ocil.xml"·name="ocil:ssg-chromium_whitelist_plugin_urls_ocil:questionnaire:1"/>
1677 ··········</xccdf-1.2:check>1677 ··········</xccdf-1.2:check>
1678 ········</xccdf-1.2:Rule>1678 ········</xccdf-1.2:Rule>
1679 ······</xccdf-1.2:Group>1679 ······</xccdf-1.2:Group>
1680 ····</xccdf-1.2:Benchmark>1680 ····</xccdf-1.2:Benchmark>
1681 ··</ds:component>1681 ··</ds:component>
1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-02-28T20:08:00">1682 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-oval.xml"·timestamp="2025-03-01T22:08:00">
1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1683 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1684 ······<oval-def:generator>1684 ······<oval-def:generator>
1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1685 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>1686 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
1687 ········<oval:schema_version>5.11</oval:schema_version>1687 ········<oval:schema_version>5.11</oval:schema_version>
1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1688 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1689 ······</oval-def:generator>1689 ······</oval-def:generator>
Offset 2539, 264 lines modifiedOffset 2539, 264 lines modified
2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>2539 ········<oval-def:external_variable·id="oval:ssg-var_enable_encrypted_searching:var:1"·version="1"·datatype="string"·comment="Expected·search·provider·name"/>
2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>2540 ········<oval-def:external_variable·id="oval:ssg-var_extension_whitelist:var:1"·version="1"·datatype="string"·comment="Expected·approved·extensions"/>
2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>2541 ········<oval-def:external_variable·id="oval:ssg-var_auth_schema:var:1"·version="1"·datatype="string"·comment="Expected·HTTP·authentication·type"/>
2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>2542 ········<oval-def:external_variable·id="oval:ssg-var_trusted_home_page:var:1"·version="1"·datatype="string"·comment="Expected·home·page"/>
2543 ······</oval-def:variables>2543 ······</oval-def:variables>
2544 ····</oval-def:oval_definitions>2544 ····</oval-def:oval_definitions>
2545 ··</ds:component>2545 ··</ds:component>
2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-02-28T20:08:00">2546 ··<ds:component·id="scap_org.open-scap_comp_ssg-chromium-ocil.xml"·timestamp="2025-03-01T22:08:00">
2547 ····<ocil:ocil>2547 ····<ocil:ocil>
2548 ······<ocil:generator>2548 ······<ocil:generator>
2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2549 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2550 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2551 ········<ocil:schema_version>2.0</ocil:schema_version>2551 ········<ocil:schema_version>2.0</ocil:schema_version>
2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2552 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2553 ······</ocil:generator>2553 ······</ocil:generator>
2554 ······<ocil:questionnaires>2554 ······<ocil:questionnaires>
2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">2555 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">
2556 ··········<ocil:title>Disable·All·Extensions·by·Default</ocil:title>2556 ··········<ocil:title>Disable·Background·Processing</ocil:title>
2557 ··········<ocil:actions>2557 ··········<ocil:actions>
2558 ············<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>2558 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>
2559 ··········</ocil:actions>2559 ··········</ocil:actions>
2560 ········</ocil:questionnaire>2560 ········</ocil:questionnaire>
2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">2561 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
2562 ··········<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>2562 ··········<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
2563 ··········<ocil:actions>2563 ··········<ocil:actions>
2564 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>2564 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
2565 ··········</ocil:actions>2565 ··········</ocil:actions>
2566 ········</ocil:questionnaire>2566 ········</ocil:questionnaire>
2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">2567 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">
2568 ··········<ocil:title>Disable·Background·Processing</ocil:title>2568 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>
2569 ··········<ocil:actions>2569 ··········<ocil:actions>
2570 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>2570 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>
2571 ··········</ocil:actions>2571 ··········</ocil:actions>
2572 ········</ocil:questionnaire>2572 ········</ocil:questionnaire>
2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">2573 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
2574 ··········<ocil:title>Disable·Metrics·Reporting</ocil:title>2574 ··········<ocil:title>Disable·Metrics·Reporting</ocil:title>
2575 ··········<ocil:actions>2575 ··········<ocil:actions>
2576 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>2576 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
2577 ··········</ocil:actions>2577 ··········</ocil:actions>
2578 ········</ocil:questionnaire>2578 ········</ocil:questionnaire>
2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">2579 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
2580 ··········<ocil:title>Enable·the·Default·Search·Provider</ocil:title>2580 ··········<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
2581 ··········<ocil:actions>2581 ··········<ocil:actions>
2582 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>2582 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
2583 ··········</ocil:actions>2583 ··········</ocil:actions>
2584 ········</ocil:questionnaire>2584 ········</ocil:questionnaire>
2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">2585 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">
2586 ··········<ocil:title>Disable·3rd·Party·Cookies</ocil:title>2586 ··········<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>
2587 ··········<ocil:actions>2587 ··········<ocil:actions>
 2588 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>
 2589 ··········</ocil:actions>
 2590 ········</ocil:questionnaire>
 2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">
 2592 ··········<ocil:title>Disable·Popups</ocil:title>
 2593 ··········<ocil:actions>
2588 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>2594 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>
 2595 ··········</ocil:actions>
 2596 ········</ocil:questionnaire>
 2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">
 2598 ··········<ocil:title>Disable·Saved·Passwords</ocil:title>
 2599 ··········<ocil:actions>
 2600 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>
2589 ··········</ocil:actions>2601 ··········</ocil:actions>
2590 ········</ocil:questionnaire>2602 ········</ocil:questionnaire>
2591 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">2603 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">
2592 ··········<ocil:title>Enable·Encrypted·Searching</ocil:title>2604 ··········<ocil:title>Enable·Encrypted·Searching</ocil:title>
2593 ··········<ocil:actions>2605 ··········<ocil:actions>
2594 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>2606 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>
2595 ··········</ocil:actions>2607 ··········</ocil:actions>
2596 ········</ocil:questionnaire>2608 ········</ocil:questionnaire>
2597 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">2609 ········<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">
2598 ··········<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>2610 ··········<ocil:title>Disable·Location·Tracking</ocil:title>
2599 ··········<ocil:actions>2611 ··········<ocil:actions>
2600 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>2612 ············<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>
2601 ··········</ocil:actions>2613 ··········</ocil:actions>
2602 ········</ocil:questionnaire>2614 ········</ocil:questionnaire>
2603 ········<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">2615 ········<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">
2604 ··········<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>2616 ··········<ocil:title>Enable·the·Default·Search·Provider</ocil:title>
2605 ··········<ocil:actions>2617 ··········<ocil:actions>
2606 ············<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>2618 ············<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>
2607 ··········</ocil:actions>2619 ··········</ocil:actions>
2608 ········</ocil:questionnaire>2620 ········</ocil:questionnaire>
2609 ········<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">2621 ········<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">
2610 ··········<ocil:title>Enable·Saving·the·Browser·History</ocil:title>2622 ··········<ocil:title>Disable·Network·Prediction</ocil:title>
2611 ··········<ocil:actions>2623 ··········<ocil:actions>
2612 ············<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>2624 ············<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>
2613 ··········</ocil:actions>2625 ··········</ocil:actions>
Max diff block lines reached; 66583/78128 bytes (85.22%) of diff not shown.
68.0 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
67.9 KB
./usr/share/xml/scap/ssg/content/ssg-chromium-ocil.xml
Ordering differences only
    
Offset 3, 255 lines modifiedOffset 3, 255 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">
11 ······<ocil:title>Disable·All·Extensions·by·Default</ocil:title>11 ······<ocil:title>Disable·Background·Processing</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_firewall_traversal_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_approved_plugins_ocil:questionnaire:1">
17 ······<ocil:title>Disable·Chromium's·Ability·to·Traverse·Firewalls</ocil:title>17 ······<ocil:title>Enable·Only·Approved·Plugins</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_firewall_traversal_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_approved_plugins_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_background_processing_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">
23 ······<ocil:title>Disable·Background·Processing</ocil:title>23 ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title>
24 ······<ocil:actions>24 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_background_processing_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>26 ······</ocil:actions>
27 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_metrics_reporting_ocil:questionnaire:1">
29 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>29 ······<ocil:title>Disable·Metrics·Reporting</ocil:title>
30 ······<ocil:actions>30 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_metrics_reporting_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>32 ······</ocil:actions>
33 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_plugin_blacklist_ocil:questionnaire:1">
35 ······<ocil:title>Enable·the·Default·Search·Provider</ocil:title>35 ······<ocil:title>Disable·All·Plugins·by·Default</ocil:title>
36 ······<ocil:actions>36 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_plugin_blacklist_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>38 ······</ocil:actions>
39 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_thirdparty_cookies_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_automatic_installation_ocil:questionnaire:1">
41 ······<ocil:title>Disable·3rd·Party·Cookies</ocil:title>41 ······<ocil:title>Disable·Automatic·Search·And·Installation·of·Plugins</ocil:title>
42 ······<ocil:actions>42 ······<ocil:actions>
 43 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_automatic_installation_action:testaction:1</ocil:test_action_ref>
 44 ······</ocil:actions>
 45 ····</ocil:questionnaire>
 46 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·Popups</ocil:title>
 48 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_thirdparty_cookies_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>
 50 ······</ocil:actions>
 51 ····</ocil:questionnaire>
 52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_saved_passwords_ocil:questionnaire:1">
 53 ······<ocil:title>Disable·Saved·Passwords</ocil:title>
 54 ······<ocil:actions>
 55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_saved_passwords_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>56 ······</ocil:actions>
45 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_encrypted_searching_ocil:questionnaire:1">
47 ······<ocil:title>Enable·Encrypted·Searching</ocil:title>59 ······<ocil:title>Enable·Encrypted·Searching</ocil:title>
48 ······<ocil:actions>60 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_encrypted_searching_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>62 ······</ocil:actions>
51 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">
53 ······<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>65 ······<ocil:title>Disable·Location·Tracking</ocil:title>
54 ······<ocil:actions>66 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>68 ······</ocil:actions>
57 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-chromium_check_cert_revocation_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_search_provider_ocil:questionnaire:1">
59 ······<ocil:title>Enable·Online·OCSP/CRL·Certificate·Checks</ocil:title>71 ······<ocil:title>Enable·the·Default·Search·Provider</ocil:title>
60 ······<ocil:actions>72 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-chromium_check_cert_revocation_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-chromium_default_search_provider_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>74 ······</ocil:actions>
63 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-chromium_enable_browser_history_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_network_prediction_ocil:questionnaire:1">
65 ······<ocil:title>Enable·Saving·the·Browser·History</ocil:title>77 ······<ocil:title>Disable·Network·Prediction</ocil:title>
66 ······<ocil:actions>78 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-chromium_enable_browser_history_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_network_prediction_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>80 ······</ocil:actions>
69 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_3d_graphics_api_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-chromium_blacklist_extension_installation_ocil:questionnaire:1">
71 ······<ocil:title>Disable·the·3D·Graphics·APIs</ocil:title>83 ······<ocil:title>Disable·All·Extensions·by·Default</ocil:title>
72 ······<ocil:actions>84 ······<ocil:actions>
 85 ········<ocil:test_action_ref>ocil:ssg-chromium_blacklist_extension_installation_action:testaction:1</ocil:test_action_ref>
 86 ······</ocil:actions>
 87 ····</ocil:questionnaire>
 88 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">
 89 ······<ocil:title>Disable·Incognito·Mode</ocil:title>
 90 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_3d_graphics_api_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>92 ······</ocil:actions>
75 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_outdated_plugins_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_outdated_plugins_ocil:questionnaire:1">
77 ······<ocil:title>Disable·Outdated·Plugins</ocil:title>95 ······<ocil:title>Disable·Outdated·Plugins</ocil:title>
78 ······<ocil:actions>96 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_outdated_plugins_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_outdated_plugins_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>98 ······</ocil:actions>
81 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-chromium_disallow_location_tracking_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-chromium_policy_file_ocil:questionnaire:1">
83 ······<ocil:title>Disable·Location·Tracking</ocil:title>101 ······<ocil:title>Ensure·the·Chromium·Policy·Configuration·File·Exists</ocil:title>
84 ······<ocil:actions>102 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-chromium_disallow_location_tracking_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-chromium_policy_file_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>104 ······</ocil:actions>
87 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_popups_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cloud_print_sharing_ocil:questionnaire:1">
89 ······<ocil:title>Disable·Popups</ocil:title>107 ······<ocil:title>Disable·Cloud·Print·Sharing</ocil:title>
90 ······<ocil:actions>108 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_popups_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cloud_print_sharing_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>110 ······</ocil:actions>
93 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_cleartext_passwords_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_search_suggestions_ocil:questionnaire:1">
95 ······<ocil:title>Disable·Use·of·Cleartext·Passwords</ocil:title>113 ······<ocil:title>Disable·Search·Suggestion</ocil:title>
96 ······<ocil:actions>114 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_cleartext_passwords_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_search_suggestions_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>116 ······</ocil:actions>
99 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_incognito_mode_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-chromium_default_block_plugins_ocil:questionnaire:1">
101 ······<ocil:title>Disable·Incognito·Mode</ocil:title>119 ······<ocil:title>Block·Plugins·by·Default</ocil:title>
102 ······<ocil:actions>120 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_incognito_mode_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-chromium_default_block_plugins_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>122 ······</ocil:actions>
105 ····</ocil:questionnaire>123 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">124 ····<ocil:questionnaire·id="ocil:ssg-chromium_disable_protocol_schemas_ocil:questionnaire:1">
107 ······<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>125 ······<ocil:title>Disable·Insecure·And·Obsolete·Protocol·Schemas</ocil:title>
108 ······<ocil:actions>126 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>127 ········<ocil:test_action_ref>ocil:ssg-chromium_disable_protocol_schemas_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>128 ······</ocil:actions>
111 ····</ocil:questionnaire>129 ····</ocil:questionnaire>
Max diff block lines reached; 57440/69349 bytes (82.83%) of diff not shown.
89.8 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
89.7 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-eks-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-eks-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">28 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service:1">
29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">32 ······<cpe-dict:cpe-item·name="cpe:/a:amazon:elastic_kubernetes_service_node:1.21">
33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·1.21</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">36 ······<cpe-dict:cpe-item·name="cpe:/o:amazon:elastic_kubernetes_service_node:1">
37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Amazon·Elastic·Kubernetes·Service·Node</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml">oval:ssg-installed_app_is_eks_node:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_EKS"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Amazon·Elastic·Kubernetes·Service</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of48 configuration·settings·for·Amazon·Elastic·Kubernetes·Service.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 113, 24 lines modifiedOffset 113, 24 lines modified
113 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
114 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>114 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
115 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>115 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
116 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
118 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>118 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
119 ······<cpe-lang:platform-specification>119 ······<cpe-lang:platform-specification>
120 ········<cpe-lang:platform·id="not_ocp4-on-hypershift"> 
121 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
123 ··········</cpe-lang:logical-test> 
124 ········</cpe-lang:platform> 
125 ········<cpe-lang:platform·id="eks-node">120 ········<cpe-lang:platform·id="eks-node">
126 ··········<cpe-lang:logical-test·operator="AND"·negate="false">121 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_eks_node:def:1"/>122 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_eks_node:def:1"/>
128 ··········</cpe-lang:logical-test>123 ··········</cpe-lang:logical-test>
129 ········</cpe-lang:platform>124 ········</cpe-lang:platform>
 125 ········<cpe-lang:platform·id="not_ocp4-on-hypershift">
 126 ··········<cpe-lang:logical-test·operator="AND"·negate="true">
 127 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>
 128 ··········</cpe-lang:logical-test>
 129 ········</cpe-lang:platform>
130 ······</cpe-lang:platform-specification>130 ······</cpe-lang:platform-specification>
131 ······<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"/>131 ······<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"/>
132 ······<xccdf-1.2:platform·idref="cpe:/o:amazon:elastic_kubernetes_service_node:1"/>132 ······<xccdf-1.2:platform·idref="cpe:/o:amazon:elastic_kubernetes_service_node:1"/>
133 ······<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service:1"/>133 ······<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service:1"/>
134 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.76</xccdf-1.2:version>134 ······<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.76</xccdf-1.2:version>
135 ······<xccdf-1.2:metadata>135 ······<xccdf-1.2:metadata>
136 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>136 ········<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
Offset 1545, 15 lines modifiedOffset 1545, 15 lines modified
1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>1545 ··············<xccdf-1.2:check-content-ref·href="ssg-eks-ocil.xml"·name="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1"/>
1546 ············</xccdf-1.2:check>1546 ············</xccdf-1.2:check>
1547 ··········</xccdf-1.2:Rule>1547 ··········</xccdf-1.2:Rule>
1548 ········</xccdf-1.2:Group>1548 ········</xccdf-1.2:Group>
1549 ······</xccdf-1.2:Group>1549 ······</xccdf-1.2:Group>
1550 ····</xccdf-1.2:Benchmark>1550 ····</xccdf-1.2:Benchmark>
1551 ··</ds:component>1551 ··</ds:component>
1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-02-28T20:08:00">1552 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-oval.xml"·timestamp="2025-03-01T22:08:00">
1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">1553 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
1554 ······<oval-def:generator>1554 ······<oval-def:generator>
1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>1555 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>1556 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
1557 ········<oval:schema_version>5.11</oval:schema_version>1557 ········<oval:schema_version>5.11</oval:schema_version>
1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>1558 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
1559 ······</oval-def:generator>1559 ······</oval-def:generator>
Offset 2166, 314 lines modifiedOffset 2166, 314 lines modified
2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>2166 ········<oval-def:external_variable·id="oval:ssg-var_streaming_connection_timeouts:var:1"·version="1"·datatype="string"·comment="variable"/>
2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">2167 ········<oval-def:local_variable·id="oval:ssg-kubelet_read_only_port_secured_file_location:var:1"·version="1"·datatype="string"·comment="The·actual·path·of·the·file·to·scan.">
2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>2168 ··········<oval-def:literal_component>/etc/kubernetes/compliance-operator/kubeletconfig/openscap-kubeletconfig</oval-def:literal_component>
2169 ········</oval-def:local_variable>2169 ········</oval-def:local_variable>
2170 ······</oval-def:variables>2170 ······</oval-def:variables>
2171 ····</oval-def:oval_definitions>2171 ····</oval-def:oval_definitions>
2172 ··</ds:component>2172 ··</ds:component>
2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-02-28T20:08:00">2173 ··<ds:component·id="scap_org.open-scap_comp_ssg-eks-ocil.xml"·timestamp="2025-03-01T22:08:00">
2174 ····<ocil:ocil>2174 ····<ocil:ocil>
2175 ······<ocil:generator>2175 ······<ocil:generator>
2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>2176 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>2177 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
2178 ········<ocil:schema_version>2.0</ocil:schema_version>2178 ········<ocil:schema_version>2.0</ocil:schema_version>
2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>2179 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
2180 ······</ocil:generator>2180 ······</ocil:generator>
2181 ······<ocil:questionnaires>2181 ······<ocil:questionnaires>
2182 ········<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1"> 
2183 ··········<ocil:title>Ensure·Private·Endpoint·Access</ocil:title> 
2184 ··········<ocil:actions> 
2185 ············<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref> 
2186 ··········</ocil:actions> 
2187 ········</ocil:questionnaire> 
2188 ········<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1"> 
2189 ··········<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title> 
2190 ··········<ocil:actions> 
2191 ············<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref> 
2192 ··········</ocil:actions> 
2193 ········</ocil:questionnaire> 
2194 ········<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">2182 ········<ocil:questionnaire·id="ocil:ssg-configure_network_policies_namespaces_ocil:questionnaire:1">
2195 ··········<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>2183 ··········<ocil:title>Ensure·that·application·Namespaces·have·Network·Policies·defined.</ocil:title>
2196 ··········<ocil:actions>2184 ··········<ocil:actions>
2197 ············<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref>2185 ············<ocil:test_action_ref>ocil:ssg-configure_network_policies_namespaces_action:testaction:1</ocil:test_action_ref>
2198 ··········</ocil:actions>2186 ··········</ocil:actions>
2199 ········</ocil:questionnaire>2187 ········</ocil:questionnaire>
2200 ········<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1">2188 ········<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">
2201 ··········<ocil:title>Only·use·approved·container·registries</ocil:title>2189 ··········<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
2202 ··········<ocil:actions>2190 ··········<ocil:actions>
2203 ············<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref>2191 ············<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>
2204 ··········</ocil:actions>2192 ··········</ocil:actions>
2205 ········</ocil:questionnaire>2193 ········</ocil:questionnaire>
2206 ········<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">2194 ········<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">
2207 ··········<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>2195 ··········<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>
2208 ··········<ocil:actions>2196 ··········<ocil:actions>
2209 ············<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>2197 ············<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>
2210 ··········</ocil:actions>2198 ··········</ocil:actions>
2211 ········</ocil:questionnaire>2199 ········</ocil:questionnaire>
2212 ········<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">2200 ········<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">
2213 ··········<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>2201 ··········<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
2214 ··········<ocil:actions>2202 ··········<ocil:actions>
Max diff block lines reached; 81167/91801 bytes (88.42%) of diff not shown.
78.8 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
78.7 KB
./usr/share/xml/scap/ssg/content/ssg-eks-ocil.xml
Ordering differences only
    
Offset 3, 305 lines modifiedOffset 3, 305 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-endpoint_configuration_ocil:questionnaire:1"> 
11 ······<ocil:title>Ensure·Private·Endpoint·Access</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-endpoint_configuration_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1"> 
17 ······<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title> 
18 ······<ocil:actions> 
19 ········<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref> 
20 ······</ocil:actions> 
21 ····</ocil:questionnaire> 
22 ····<ocil:questionnaire·id="ocil:ssg-fargate_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policies_namespaces_ocil:questionnaire:1">
23 ······<ocil:title>Consider·Fargate·for·Untrusted·Workloads</ocil:title>11 ······<ocil:title>Ensure·that·application·Namespaces·have·Network·Policies·defined.</ocil:title>
24 ······<ocil:actions>12 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-fargate_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-configure_network_policies_namespaces_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>14 ······</ocil:actions>
27 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-approved_registries_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-kubelet_configure_client_ca_ocil:questionnaire:1">
29 ······<ocil:title>Only·use·approved·container·registries</ocil:title>17 ······<ocil:title>kubelet·-·Configure·the·Client·CA·Certificate</ocil:title>
30 ······<ocil:actions>18 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-approved_registries_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-kubelet_configure_client_ca_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>20 ······</ocil:actions>
33 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-iam_integration_ocil:questionnaire:1">
35 ······<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>23 ······<ocil:title>Manage·Users·with·AWS·IAM</ocil:title>
36 ······<ocil:actions>24 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-iam_integration_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>26 ······</ocil:actions>
39 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-kubelet_read_only_port_secured_ocil:questionnaire:1">
41 ······<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>29 ······<ocil:title>kubelet·-·Ensure·that·the·--read-only-port·is·secured</ocil:title>
42 ······<ocil:actions>30 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-kubelet_authorization_mode_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-kubelet_read_only_port_secured_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>32 ······</ocil:actions>
45 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-control_plane_access_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-file_owner_kubelet_conf_ocil:questionnaire:1">
47 ······<ocil:title>Restrict·Access·to·the·Control·Plane·Endpoint</ocil:title>35 ······<ocil:title>Verify·User·Who·Owns·The·Kubelet·Configuration·File</ocil:title>
48 ······<ocil:actions>36 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-control_plane_access_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-file_owner_kubelet_conf_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>38 ······</ocil:actions>
51 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1"> 
53 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>40 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_client_cert_rotation_ocil:questionnaire:1">
 41 ······<ocil:title>kubelet·-·Enable·Client·Certificate·Rotation</ocil:title>
54 ······<ocil:actions>42 ······<ocil:actions>
 43 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_client_cert_rotation_action:testaction:1</ocil:test_action_ref>
 44 ······</ocil:actions>
 45 ····</ocil:questionnaire>
 46 ····<ocil:questionnaire·id="ocil:ssg-kubelet_anonymous_auth_ocil:questionnaire:1">
 47 ······<ocil:title>Disable·Anonymous·Authentication·to·the·Kubelet</ocil:title>
 48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-kubelet_anonymous_auth_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-audit_logging_ocil:questionnaire:1">
59 ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>53 ······<ocil:title>Ensure·Audit·Logging·is·Enabled</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-audit_logging_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_worker_kubeconfig_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-image_scanning_ocil:questionnaire:1">
65 ······<ocil:title>Verify·Permissions·on·the·Worker·Kubeconfig·File</ocil:title>59 ······<ocil:title>Ensure·Image·Vulnerability·Scanning</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-file_permissions_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-image_scanning_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1"> 
71 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>64 ····<ocil:questionnaire·id="ocil:ssg-kubelet_authorization_mode_ocil:questionnaire:1">
 65 ······<ocil:title>Ensure·authorization·is·set·to·Webhook</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-kubelet_authorization_mode_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
 70 ····<ocil:questionnaire·id="ocil:ssg-control_plane_access_ocil:questionnaire:1">
 71 ······<ocil:title>Restrict·Access·to·the·Control·Plane·Endpoint</ocil:title>
 72 ······<ocil:actions>
 73 ········<ocil:test_action_ref>ocil:ssg-control_plane_access_action:testaction:1</ocil:test_action_ref>
 74 ······</ocil:actions>
 75 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_streaming_connections_deprecated_ocil:questionnaire:1">
77 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>77 ······<ocil:title>kubelet·-·Do·Not·Disable·Streaming·Timeouts</ocil:title>
78 ······<ocil:actions>78 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_streaming_connections_deprecated_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>80 ······</ocil:actions>
81 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-file_owner_worker_kubeconfig_ocil:questionnaire:1">
83 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>83 ······<ocil:title>Verify·User·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
84 ······<ocil:actions>84 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-file_owner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>86 ······</ocil:actions>
87 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-configure_network_policy_ocil:questionnaire:1">
89 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>89 ······<ocil:title>Ensure·Network·Policy·is·Enabled</ocil:title>
90 ······<ocil:actions>90 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-configure_network_policy_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>92 ······</ocil:actions>
93 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_server_cert_rotation_ocil:questionnaire:1"> 
95 ······<ocil:title>kubelet·-·Enable·Server·Certificate·Rotation</ocil:title>94 ····<ocil:questionnaire·id="ocil:ssg-file_groupowner_worker_kubeconfig_ocil:questionnaire:1">
 95 ······<ocil:title>Verify·Group·Who·Owns·The·Worker·Kubeconfig·File</ocil:title>
96 ······<ocil:actions>96 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_server_cert_rotation_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-file_groupowner_worker_kubeconfig_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>98 ······</ocil:actions>
99 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_iptables_util_chains_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_cert_rotation_ocil:questionnaire:1">
101 ······<ocil:title>kubelet·-·Allow·Automatic·Firewall·Configuration</ocil:title>101 ······<ocil:title>kubelet·-·Enable·Certificate·Rotation</ocil:title>
102 ······<ocil:actions>102 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_iptables_util_chains_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_cert_rotation_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>104 ······</ocil:actions>
105 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-kubelet_enable_protect_kernel_defaults_ocil:questionnaire:1">
107 ······<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>107 ······<ocil:title>kubelet·-·Enable·Protect·Kernel·Defaults</ocil:title>
108 ······<ocil:actions>108 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-secret_encryption_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-kubelet_enable_protect_kernel_defaults_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>110 ······</ocil:actions>
111 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-configure_tls_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-secret_encryption_ocil:questionnaire:1">
113 ······<ocil:title>Encrypt·Traffic·to·Load·Balancers·and·Workloads</ocil:title>113 ······<ocil:title>Ensure·Kubernetes·Secrets·are·Encrypted</ocil:title>
114 ······<ocil:actions>114 ······<ocil:actions>
Max diff block lines reached; 69804/80474 bytes (86.74%) of diff not shown.
2.53 KB
./usr/share/xml/scap/ssg/content/ssg-eks-xccdf.xml
2.43 KB
./usr/share/xml/scap/ssg/content/ssg-eks-xccdf.xml
Ordering differences only
    
Offset 72, 24 lines modifiedOffset 72, 24 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="not_ocp4-on-hypershift"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="eks-node">79 ····<cpe-lang:platform·id="eks-node">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_eks_node:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_eks_node:def:1"/>
87 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
 84 ····<cpe-lang:platform·id="not_ocp4-on-hypershift">
 85 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-eks-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>
 87 ······</cpe-lang:logical-test>
 88 ····</cpe-lang:platform>
89 ··</cpe-lang:platform-specification>89 ··</cpe-lang:platform-specification>
90 ··<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"/>90 ··<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service_node:1.21"/>
91 ··<xccdf-1.2:platform·idref="cpe:/o:amazon:elastic_kubernetes_service_node:1"/>91 ··<xccdf-1.2:platform·idref="cpe:/o:amazon:elastic_kubernetes_service_node:1"/>
92 ··<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service:1"/>92 ··<xccdf-1.2:platform·idref="cpe:/a:amazon:elastic_kubernetes_service:1"/>
93 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.76</xccdf-1.2:version>93 ··<xccdf-1.2:version·update="https://github.com/ComplianceAsCode/content/releases/latest">0.1.76</xccdf-1.2:version>
94 ··<xccdf-1.2:metadata>94 ··<xccdf-1.2:metadata>
95 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>95 ····<dc:publisher>SCAP·Security·Guide·Project</dc:publisher>
54.8 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
54.7 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-firefox-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-firefox-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">28 ······<cpe-dict:cpe-item·name="cpe:/a:mozilla:firefox">
29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Mozilla·Firefox</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-firefox-cpe-oval.xml">oval:ssg-installed_app_is_firefox:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_FIREFOX"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Firefox</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Firefox.·It·is·a·rendering·of40 configuration·settings·for·Firefox.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 3488, 15 lines modifiedOffset 3488, 15 lines modified
3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>3488 ··············<xccdf-1.2:check-content-ref·href="ssg-firefox-ocil.xml"·name="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"/>
3489 ············</xccdf-1.2:check>3489 ············</xccdf-1.2:check>
3490 ··········</xccdf-1.2:Rule>3490 ··········</xccdf-1.2:Rule>
3491 ········</xccdf-1.2:Group>3491 ········</xccdf-1.2:Group>
3492 ······</xccdf-1.2:Group>3492 ······</xccdf-1.2:Group>
3493 ····</xccdf-1.2:Benchmark>3493 ····</xccdf-1.2:Benchmark>
3494 ··</ds:component>3494 ··</ds:component>
3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-02-28T20:08:00">3495 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-oval.xml"·timestamp="2025-03-01T22:08:00">
3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">3496 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
3497 ······<oval-def:generator>3497 ······<oval-def:generator>
3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>3498 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>3499 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
3500 ········<oval:schema_version>5.11</oval:schema_version>3500 ········<oval:schema_version>5.11</oval:schema_version>
3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>3501 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
3502 ······</oval-def:generator>3502 ······</oval-def:generator>
Offset 5198, 176 lines modifiedOffset 5198, 176 lines modified
5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>5198 ··············<oval-def:literal_component>/distribution</oval-def:literal_component>
5199 ············</oval-def:concat>5199 ············</oval-def:concat>
5200 ··········</oval-def:unique>5200 ··········</oval-def:unique>
5201 ········</oval-def:local_variable>5201 ········</oval-def:local_variable>
5202 ······</oval-def:variables>5202 ······</oval-def:variables>
5203 ····</oval-def:oval_definitions>5203 ····</oval-def:oval_definitions>
5204 ··</ds:component>5204 ··</ds:component>
5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-02-28T20:08:00">5205 ··<ds:component·id="scap_org.open-scap_comp_ssg-firefox-ocil.xml"·timestamp="2025-03-01T22:08:00">
5206 ····<ocil:ocil>5206 ····<ocil:ocil>
5207 ······<ocil:generator>5207 ······<ocil:generator>
5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>5208 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>5209 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
5210 ········<ocil:schema_version>2.0</ocil:schema_version>5210 ········<ocil:schema_version>2.0</ocil:schema_version>
5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>5211 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
5212 ······</ocil:generator>5212 ······</ocil:generator>
5213 ······<ocil:questionnaires>5213 ······<ocil:questionnaires>
5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">5214 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
5215 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>5215 ··········<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
5216 ··········<ocil:actions>5216 ··········<ocil:actions>
5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>5217 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
5218 ··········</ocil:actions>5218 ··········</ocil:actions>
5219 ········</ocil:questionnaire>5219 ········</ocil:questionnaire>
5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">5220 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">
5221 ··········<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>5221 ··········<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>
5222 ··········<ocil:actions>5222 ··········<ocil:actions>
5223 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>5223 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>
5224 ··········</ocil:actions>5224 ··········</ocil:actions>
5225 ········</ocil:questionnaire>5225 ········</ocil:questionnaire>
5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">5226 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
 5227 ··········<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>
5227 ··········<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title> 
5228 ··········<ocil:actions> 
5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref> 
5230 ··········</ocil:actions> 
5231 ········</ocil:questionnaire> 
5232 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"> 
5233 ··········<ocil:title>Enable·Shared·System·Certificates</ocil:title> 
5234 ··········<ocil:actions>5228 ··········<ocil:actions>
5235 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>5229 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>
5236 ··········</ocil:actions>5230 ··········</ocil:actions>
5237 ········</ocil:questionnaire>5231 ········</ocil:questionnaire>
5238 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">5232 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">
5239 ··········<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>5233 ··········<ocil:title>Disable·Firefox·Studies</ocil:title>
5240 ··········<ocil:actions>5234 ··········<ocil:actions>
5241 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>5235 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>
5242 ··········</ocil:actions>5236 ··········</ocil:actions>
5243 ········</ocil:questionnaire>5237 ········</ocil:questionnaire>
5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">5238 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
5245 ··········<ocil:title>Enable·Certificate·Verification</ocil:title>5239 ··········<ocil:title>Disable·Firefox·Telemetry</ocil:title>
5246 ··········<ocil:actions>5240 ··········<ocil:actions>
5247 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>5241 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
5248 ··········</ocil:actions>5242 ··········</ocil:actions>
5249 ········</ocil:questionnaire>5243 ········</ocil:questionnaire>
5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">5244 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
5251 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>5245 ··········<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
5252 ··········<ocil:actions>5246 ··········<ocil:actions>
5253 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>5247 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
5254 ··········</ocil:actions>5248 ··········</ocil:actions>
5255 ········</ocil:questionnaire>5249 ········</ocil:questionnaire>
5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">5250 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
5257 ··········<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>5251 ··········<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
5258 ··········<ocil:actions>5252 ··········<ocil:actions>
5259 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>5253 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
5260 ··········</ocil:actions>5254 ··········</ocil:actions>
5261 ········</ocil:questionnaire>5255 ········</ocil:questionnaire>
5262 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">5256 ········<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">
5263 ··········<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>5257 ··········<ocil:title>Enable·Shared·System·Certificates</ocil:title>
5264 ··········<ocil:actions>5258 ··········<ocil:actions>
5265 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>5259 ············<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>
5266 ··········</ocil:actions>5260 ··········</ocil:actions>
5267 ········</ocil:questionnaire>5261 ········</ocil:questionnaire>
5268 ········<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">5262 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">
5269 ··········<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>5263 ··········<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>
5270 ··········<ocil:actions>5264 ··········<ocil:actions>
5271 ············<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>5265 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>
5272 ··········</ocil:actions>5266 ··········</ocil:actions>
5273 ········</ocil:questionnaire>5267 ········</ocil:questionnaire>
5274 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">5268 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
5275 ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>5269 ··········<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
5276 ··········<ocil:actions>5270 ··········<ocil:actions>
5277 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>5271 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
5278 ··········</ocil:actions>5272 ··········</ocil:actions>
5279 ········</ocil:questionnaire>5273 ········</ocil:questionnaire>
5280 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">5274 ········<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
5281 ··········<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>5275 ··········<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>
5282 ··········<ocil:actions>5276 ··········<ocil:actions>
5283 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>5277 ············<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 44411/55885 bytes (79.47%) of diff not shown.
47.7 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
47.6 KB
./usr/share/xml/scap/ssg/content/ssg-firefox-ocil.xml
Ordering differences only
    
Offset 3, 167 lines modifiedOffset 3, 167 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">
11 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>11 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>
12 ······<ocil:actions>12 ······<ocil:actions>
13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>
14 ······</ocil:actions>14 ······</ocil:actions>
15 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-private_browsing_ocil:questionnaire:1">
17 ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>17 ······<ocil:title>Firefox·private·browsing·must·be·disabled.</ocil:title>
18 ······<ocil:actions>18 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-private_browsing_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>20 ······</ocil:actions>
21 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_suggestion_ocil:questionnaire:1">22 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">
 23 ······<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>
23 ······<ocil:title>Firefox·search·suggestions·must·be·disabled.</ocil:title> 
24 ······<ocil:actions> 
25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_suggestion_action:testaction:1</ocil:test_action_ref> 
26 ······</ocil:actions> 
27 ····</ocil:questionnaire> 
28 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1"> 
29 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title> 
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_recommendation_ocil:questionnaire:1">28 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_studies_ocil:questionnaire:1">
35 ······<ocil:title>Disabled·Firefox·Extension·Recommendations</ocil:title>29 ······<ocil:title>Disable·Firefox·Studies</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_recommendation_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_studies_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-verification_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-telemetry_ocil:questionnaire:1">
41 ······<ocil:title>Enable·Certificate·Verification</ocil:title>35 ······<ocil:title>Disable·Firefox·Telemetry</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-verification_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-telemetry_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-auto-download_actions_ocil:questionnaire:1">
47 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>41 ······<ocil:title>Disable·auto-download·for·proscribed·MIME·types.</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-auto-download_actions_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1">
53 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>47 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-forget_button_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-enable_ca_trust_ocil:questionnaire:1">
59 ······<ocil:title>Firefox·must·prevent·the·user·from·quickly·deleting·data.</ocil:title>53 ······<ocil:title>Enable·Shared·System·Certificates</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-forget_button_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-enable_ca_trust_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">58 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-content_blocker_ocil:questionnaire:1">
65 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>59 ······<ocil:title>Ensure·the·Content·Blocker·uBlock·Origin·is·Installed</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-content_blocker_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">
71 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>65 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-fingerprinting_protection_ocil:questionnaire:1">
77 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>71 ······<ocil:title>Enabled·Firefox·Fingerprinting·Protection</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-fingerprinting_protection_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-extension_update_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-installed_firefox_version_supported_ocil:questionnaire:1">
83 ······<ocil:title>Firefox·must·be·configured·to·not·automatically·update·installed·add-ons·and·plugins.</ocil:title>77 ······<ocil:title>Supported·Version·of·Firefox·Installed</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-extension_update_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-installed_firefox_version_supported_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_resizing_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">
89 ······<ocil:title>Disable·JavaScript's·Moving·Or·Resizing·Windows·Capability</ocil:title>83 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_resizing_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-development_tools_ocil:questionnaire:1"> 
95 ······<ocil:title>Disable·Firefox·Development·Tools</ocil:title>88 ····<ocil:questionnaire·id="ocil:ssg-firefox_preferences-dod_root_certificate_installed_ocil:questionnaire:1">
 89 ······<ocil:title>The·DoD·Root·Certificate·Exists</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-development_tools_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-firefox_preferences-dod_root_certificate_installed_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-autoplay_video_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-cryptomining_ocil:questionnaire:1">
101 ······<ocil:title>Firefox·autoplay·must·be·disabled.</ocil:title>95 ······<ocil:title>Enabled·Firefox·Cryptomining·protection</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-autoplay_video_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-cryptomining_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_deprecated_ciphers_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-network_prediction_ocil:questionnaire:1">
107 ······<ocil:title>Disable·Firefox·deprecated·ciphers</ocil:title>101 ······<ocil:title>Disable·Firefox·network·prediction</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_deprecated_ciphers_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-network_prediction_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-enhanced_tracking_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-javascript_window_changes_ocil:questionnaire:1">
113 ······<ocil:title>Enabled·Firefox·Enhanced·Tracking·Protection</ocil:title>107 ······<ocil:title>Disable·JavaScript's·Raise·Or·Lower·Windows·Capability</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-enhanced_tracking_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-javascript_window_changes_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-pop-up_windows_ocil:questionnaire:1">112 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-search_update_ocil:questionnaire:1">
119 ······<ocil:title>Enable·Firefox·Pop-up·Blocker</ocil:title>113 ······<ocil:title>Disable·Installed·Search·Plugins·Update·Checking</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-pop-up_windows_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-search_update_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-firefox_policy-disable_pocket_ocil:questionnaire:1">
125 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>119 ······<ocil:title>Disable·Firefox·Pocket</ocil:title>
126 ······<ocil:actions>120 ······<ocil:actions>
127 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>121 ········<ocil:test_action_ref>ocil:ssg-firefox_policy-disable_pocket_action:testaction:1</ocil:test_action_ref>
Max diff block lines reached; 36572/48645 bytes (75.18%) of diff not shown.
24.6 MB
ssg-debderived_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····3044·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····3044·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··3721628·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··3720572·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
24.6 MB
data.tar.xz
24.6 MB
data.tar
19.8 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_average.html
    
Offset 29938, 141 lines modifiedOffset 29938, 141 lines modified
00074f10:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm100074f10:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
00074f20:·3033·3431·2220·7461·6269·6e64·6578·3d22··0341"·tabindex="00074f20:·3033·3431·2220·7461·6269·6e64·6578·3d22··0341"·tabindex="
00074f30:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00074f30:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00074f40:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00074f40:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00074f50:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00074f50:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00074f60:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00074f60:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00074f70:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00074f70:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00074f80:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·00074f80:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
00074f90:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
00074fa0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00074fb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00074fc0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00074fd0:·2220·6964·3d22·6964·6d31·3033·3431·223e··"·id="idm10341"> 
00074fe0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
00074ff0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
00075000:·226e·7470·220a·7665·7273·696f·6e20·3d20··"ntp".version·=· 
00075010:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
00075020:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00075030:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00075040:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00075050:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00075060:·7267·6574·3d22·2369·646d·3130·3334·3222··rget="#idm10342" 
00075070:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
00075080:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
00075090:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
000750a0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
000750b0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
000750c0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
000750d0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
000750e0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
000750f0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00075100:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00075110:·6964·3d22·6964·6d31·3033·3432·223e·3c74··id="idm10342"><t 
00075120:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
00075130:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
00075140:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
00075150:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
00075160:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
00075170:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
00075180:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00075190:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
000751a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
000751b0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
000751c0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
000751d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
000751e0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
000751f0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
00075200:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
00075210:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
00075220:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
00075230:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
00075240:·6e20·706c·6174·666f·726d·730a·6966·2064··n·platforms.if·d 
00075250:·706b·672d·7175·6572·7920·2d2d·7368·6f77··pkg-query·--show 
00075260:·202d·2d73·686f·7766·6f72·6d61·743d·2724···--showformat='$ 
00075270:·7b64·623a·5374·6174·7573·2d53·7461·7475··{db:Status-Statu 
00075280:·737d·0a27·2027·6c69·6e75·782d·6261·7365··s}.'·'linux-base 
00075290:·2720·3226·6774·3b2f·6465·762f·6e75·6c6c··'·2&gt;/dev/null 
000752a0:·207c·2067·7265·7020·2d71·205e·696e·7374···|·grep·-q·^inst 
000752b0:·616c·6c65·643b·2074·6865·6e0a·0a44·4542··alled;·then..DEB 
000752c0:·4941·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e··IAN_FRONTEND=non 
000752d0:·696e·7465·7261·6374·6976·6520·6170·742d··interactive·apt- 
000752e0:·6765·7420·696e·7374·616c·6c20·2d79·2022··get·install·-y·" 
000752f0:·6e74·7022·0a0a·656c·7365·0a20·2020·2026··ntp"..else.····& 
00075300:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
00075310:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
00075320:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
00075330:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
00075340:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
00075350:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00075360:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00075370:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00075380:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00075390:·7267·6574·3d22·2369·646d·3130·3334·3322··rget="#idm10343" 
000753a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
000753b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
000753c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
000753d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
000753e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
000753f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
00075400:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
00075410:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d00074f90:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
00075420:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-00074fa0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00075430:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00074fb0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00075440:·6522·2069·643d·2269·646d·3130·3334·3322··e"·id="idm10343"00074fc0:·7073·6522·2069·643d·2269·646d·3130·3334··pse"·id="idm1034
00075450:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t00074fd0:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=
00075460:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip00074fe0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
00075470:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere00074ff0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
00075480:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense00075000:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
00075490:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl00075010:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
000754a0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l00075020:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
000754b0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>00075030:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
000754c0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<00075040:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
000754d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00075050:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
000754e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb00075060:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
000754f0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal00075070:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
00075500:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>00075080:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
00075510:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t00075090:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
00075520:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td000750a0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
00075530:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p000750b0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
00075540:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name:000750c0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
00075550:·2047·6174·6865·7220·7468·6520·7061·636b···Gather·the·pack 
00075560:·6167·6520·6661·6374·730a·2020·7061·636b··age·facts.··pack 
00075570:·6167·655f·6661·6374·733a·0a20·2020·206d··age_facts:.····m 
00075580:·616e·6167·6572·3a20·6175·746f·0a20·2074··anager:·auto.··t 
00075590:·6167·733a·0a20·202d·204e·4953·542d·3830··ags:.··-·NIST-80 
000755a0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
000755b0:·2050·4349·2d44·5353·2d52·6571·2d31·302e···PCI-DSS-Req-10. 
000755c0:·340a·2020·2d20·656e·6162·6c65·5f73·7472··4.··-·enable_str 
000755d0:·6174·6567·790a·2020·2d20·6869·6768·5f73··ategy.··-·high_s 
000755e0:·6576·6572·6974·790a·2020·2d20·6c6f·775f··everity.··-·low_ 
000755f0:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l 
00075600:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.·· 
00075610:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need000750d0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 000750e0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 000750f0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 00075100:·0a69·6620·6470·6b67·2d71·7565·7279·202d··.if·dpkg-query·-
 00075110:·2d73·686f·7720·2d2d·7368·6f77·666f·726d··-show·--showform
 00075120:·6174·3d27·247b·6462·3a53·7461·7475·732d··at='${db:Status-
 00075130:·5374·6174·7573·7d0a·2720·276c·696e·7578··Status}.'·'linux
 00075140:·2d62·6173·6527·2032·2667·743b·2f64·6576··-base'·2&gt;/dev
 00075150:·2f6e·756c·6c20·7c20·6772·6570·202d·7120··/null·|·grep·-q·
 00075160:·5e69·6e73·7461·6c6c·6564·3b20·7468·656e··^installed;·then
 00075170:·0a0a·4445·4249·414e·5f46·524f·4e54·454e··..DEBIAN_FRONTEN
 00075180:·443d·6e6f·6e69·6e74·6572·6163·7469·7665··D=noninteractive
 00075190:·2061·7074·2d67·6574·2069·6e73·7461·6c6c···apt-get·install
 000751a0:·202d·7920·226e·7470·220a·0a65·6c73·650a···-y·"ntp"..else.
 000751b0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
Max diff block lines reached; 414/18520 bytes (2.24%) of diff not shown.
1.6 KB
html2text {}
    
Offset 3950, 19 lines modifiedOffset 3950, 14 lines modified
3950 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,3950 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
3951 References:················4.4.2.43951 References:················4.4.2.4
3952 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.93952 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
3953 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.13953 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
3954 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3954 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3955 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-13955 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
3956 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.43956 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
3957 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3958 [[packages]] 
3959 name·=·"ntp" 
3960 version·=·"*" 
3961 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83957 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3962 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3958 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3963 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3959 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3964 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3960 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3965 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3961 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3966 #·Remediation·is·applicable·only·in·certain·platforms3962 #·Remediation·is·applicable·only·in·certain·platforms
3967 if·dpkg-query·--show·--showformat='${db:Status-Status}3963 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 4001, 14 lines modifiedOffset 3996, 19 lines modified
4001 ··-·PCI-DSS-Req-10.43996 ··-·PCI-DSS-Req-10.4
4002 ··-·enable_strategy3997 ··-·enable_strategy
4003 ··-·high_severity3998 ··-·high_severity
4004 ··-·low_complexity3999 ··-·low_complexity
4005 ··-·low_disruption4000 ··-·low_disruption
4006 ··-·no_reboot_needed4001 ··-·no_reboot_needed
4007 ··-·package_ntp_installed4002 ··-·package_ntp_installed
 4003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4004 [[packages]]
 4005 name·=·"ntp"
 4006 version·=·"*"
4008 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84007 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4009 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4008 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4010 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4009 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4011 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4010 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4012 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4011 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4013 include·install_ntp4012 include·install_ntp
  
167 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_high.html
    
Offset 16792, 137 lines modifiedOffset 16792, 137 lines modified
00041970:·6172·6765·743d·2223·6964·6d33·3838·3622··arget="#idm3886"00041970:·6172·6765·743d·2223·6964·6d33·3838·3622··arget="#idm3886"
00041980:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00041980:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00041990:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00041990:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
000419a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false000419a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
000419b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat000419b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
000419c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre000419c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
000419d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati000419d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 000419e0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 000419f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00041a00:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 00041a10:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
000419e0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
000419f0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
00041a00:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00041a10:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00041a20:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00041a30:·2269·646d·3338·3836·223e·3c70·7265·3e3c··"idm3886"><pre>< 
00041a40:·636f·6465·3e5b·6375·7374·6f6d·697a·6174··code>[customizat 
00041a50:·696f·6e73·2e6b·6572·6e65·6c5d·0a61·7070··ions.kernel].app 
00041a60:·656e·6420·3d20·2269·6f6d·6d75·3d66·6f72··end·=·"iommu=for 
00041a70:·6365·220a·3c2f·636f·6465·3e3c·2f70·7265··ce".</code></pre 
00041a80:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00041a90:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00041aa0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00041ab0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00041ac0:·7267·6574·3d22·2369·646d·3338·3837·2220··rget="#idm3887"· 
00041ad0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00041ae0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00041af0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00041b00:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00041b10:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
00041b20:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
00041b30:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
00041b40:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00041b50:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00041b60:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00041b70:·643d·2269·646d·3338·3837·223e·3c70·7265··d="idm3887"><pre00041a20:·6964·3d22·6964·6d33·3838·3622·3e3c·7072··id="idm3886"><pr
 00041a30:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 00041a40:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 00041a50:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 00041a60:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 00041a70:·2028·2064·706b·672d·7175·6572·7920·2d2d···(·dpkg-query·--
 00041a80:·7368·6f77·202d·2d73·686f·7766·6f72·6d61··show·--showforma
 00041a90:·743d·2724·7b64·623a·5374·6174·7573·2d53··t='${db:Status-S
 00041aa0:·7461·7475·737d·5c6e·2720·2767·7275·6232··tatus}\n'·'grub2
 00041ab0:·2d63·6f6d·6d6f·6e27·2032·2667·743b·2f64··-common'·2&gt;/d
 00041ac0:·6576·2f6e·756c·6c20·7c20·6772·6570·202d··ev/null·|·grep·-
00041b80:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
00041b90:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
00041ba0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
00041bb0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
00041bc0:·2820·6470·6b67·2d71·7565·7279·202d·2d73··(·dpkg-query·--s 
00041bd0:·686f·7720·2d2d·7368·6f77·666f·726d·6174··how·--showformat 
00041be0:·3d27·247b·6462·3a53·7461·7475·732d·5374··='${db:Status-St 
00041bf0:·6174·7573·7d5c·6e27·2027·6772·7562·322d··atus}\n'·'grub2- 
00041c00:·636f·6d6d·6f6e·2720·3226·6774·3b2f·6465··common'·2&gt;/de 
00041c10:·762f·6e75·6c6c·207c·2067·7265·7020·2d71··v/null·|·grep·-q 
00041c20:·2027·5e69·6e73·7461·6c6c·6564·2720·2661···'^installed'·&a 
00041c30:·6d70·3b26·616d·703b·2064·706b·672d·7175··mp;&amp;·dpkg-qu 
00041c40:·6572·7920·2d2d·7368·6f77·202d·2d73·686f··ery·--show·--sho 
00041c50:·7766·6f72·6d61·743d·2724·7b64·623a·5374··wformat='${db:St 
00041c60:·6174·7573·2d53·7461·7475·737d·0a27·2027··atus-Status}.'·' 
00041c70:·6c69·6e75·782d·6261·7365·2720·3226·6774··linux-base'·2&gt 
00041c80:·3b2f·6465·762f·6e75·6c6c·207c·2067·7265··;/dev/null·|·gre 
00041c90:·7020·2d71·205e·696e·7374·616c·6c65·6420··p·-q·^installed·00041ad0:·7120·275e·696e·7374·616c·6c65·6427·2026··q·'^installed'·&
00041ca0:·293b·2074·6865·6e0a·0a65·7870·6563·7465··);·then..expecte 
00041cb0:·645f·7661·6c75·653d·2266·6f72·6365·220a··d_value="force". 
00041cc0:·0a0a·6966·205b·5b20·2224·4f53·4341·505f··..if·[[·"$OSCAP_ 
00041cd0:·424f·4f54·435f·4255·494c·4422·203d·3d20··BOOTC_BUILD"·==· 
00041ce0:·2259·4553·2220·5d5d·203b·2074·6865·6e0a··"YES"·]]·;·then. 
00041cf0:·2020·2020·4b41·5247·535f·4449·523d·222f······KARGS_DIR="/ 
00041d00:·7573·722f·6c69·622f·626f·6f74·632f·6b61··usr/lib/bootc/ka00041ae0:·616d·703b·2661·6d70·3b20·6470·6b67·2d71··amp;&amp;·dpkg-q
 00041af0:·7565·7279·202d·2d73·686f·7720·2d2d·7368··uery·--show·--sh
 00041b00:·6f77·666f·726d·6174·3d27·247b·6462·3a53··owformat='${db:S
 00041b10:·7461·7475·732d·5374·6174·7573·7d0a·2720··tatus-Status}.'·
 00041b20:·276c·696e·7578·2d62·6173·6527·2032·2667··'linux-base'·2&g
 00041b30:·743b·2f64·6576·2f6e·756c·6c20·7c20·6772··t;/dev/null·|·gr
 00041b40:·6570·202d·7120·5e69·6e73·7461·6c6c·6564··ep·-q·^installed
 00041b50:·2029·3b20·7468·656e·0a0a·6578·7065·6374···);·then..expect
 00041b60:·6564·5f76·616c·7565·3d22·666f·7263·6522··ed_value="force"
 00041b70:·0a0a·0a69·6620·5b5b·2022·244f·5343·4150··...if·[[·"$OSCAP
 00041b80:·5f42·4f4f·5443·5f42·5549·4c44·2220·3d3d··_BOOTC_BUILD"·==
 00041b90:·2022·5945·5322·205d·5d20·3b20·7468·656e···"YES"·]]·;·then
 00041ba0:·0a20·2020·204b·4152·4753·5f44·4952·3d22··.····KARGS_DIR="
 00041bb0:·2f75·7372·2f6c·6962·2f62·6f6f·7463·2f6b··/usr/lib/bootc/k
00041d10:·7267·732e·642f·220a·2020·2020·6966·2067··rgs.d/".····if·g00041bc0:·6172·6773·2e64·2f22·0a20·2020·2069·6620··args.d/".····if·
00041d20:·7265·7020·2d71·202d·4520·2269·6f6d·6d75··rep·-q·-E·"iommu00041bd0:·6772·6570·202d·7120·2d45·2022·696f·6d6d··grep·-q·-E·"iomm
 00041be0:·7522·2022·244b·4152·4753·5f44·4952·2f2a··u"·"$KARGS_DIR/*
 00041bf0:·2e74·6f6d·6c22·203b·2074·6865·6e0a·2020··.toml"·;·then.··
 00041c00:·2020·2020·2020·7365·6420·2d69·202d·4520········sed·-i·-E·
 00041c10:·2273·2f5e·285c·732a·6b61·7267·735c·732a··"s/^(\s*kargs\s*
 00041c20:·3d5c·732a·5c5b·2e2a·295c·2269·6f6d·6d75··=\s*\[.*)\"iommu
 00041c30:·3d5b·5e5c·225d·2a5c·2228·2e2a·5d5c·732a··=[^\"]*\"(.*]\s*
 00041c40:·292f·5c31·5c22·696f·6d6d·753d·2465·7870··)/\1\"iommu=$exp
 00041c50:·6563·7465·645f·7661·6c75·655c·225c·322f··ected_value\"\2/
00041d30:·2220·2224·4b41·5247·535f·4449·522f·2a2e··"·"$KARGS_DIR/*.00041c60:·2220·2224·4b41·5247·535f·4449·522f·2a2e··"·"$KARGS_DIR/*.
00041d40:·746f·6d6c·2220·3b20·7468·656e·0a20·2020··toml"·;·then.··· 
00041d50:·2020·2020·2073·6564·202d·6920·2d45·2022·······sed·-i·-E·" 
00041d60:·732f·5e28·5c73·2a6b·6172·6773·5c73·2a3d··s/^(\s*kargs\s*= 
00041d70:·5c73·2a5c·5b2e·2a29·5c22·696f·6d6d·753d··\s*\[.*)\"iommu= 
00041d80:·5b5e·5c22·5d2a·5c22·282e·2a5d·5c73·2a29··[^\"]*\"(.*]\s*) 
00041d90:·2f5c·315c·2269·6f6d·6d75·3d24·6578·7065··/\1\"iommu=$expe 
00041da0:·6374·6564·5f76·616c·7565·5c22·5c32·2f22··cted_value\"\2/" 
00041db0:·2022·244b·4152·4753·5f44·4952·2f2a·2e74···"$KARGS_DIR/*.t 
00041dc0:·6f6d·6c22·0a20·2020·2065·6c73·650a·2020··oml".····else.··00041c70:·746f·6d6c·220a·2020·2020·656c·7365·0a20··toml".····else.·
00041dd0:·2020·2020·2020·6563·686f·2022·6b61·7267········echo·"karg00041c80:·2020·2020·2020·2065·6368·6f20·226b·6172·········echo·"kar
00041de0:·7320·3d20·5b5c·2269·6f6d·6d75·3d24·6578··s·=·[\"iommu=$ex00041c90:·6773·203d·205b·5c22·696f·6d6d·753d·2465··gs·=·[\"iommu=$e
00041df0:·7065·6374·6564·5f76·616c·7565·5c22·5d22··pected_value\"]" 
00041e00:·2026·6774·3b26·6774·3b20·2224·4b41·5247···&gt;&gt;·"$KARG00041ca0:·7870·6563·7465·645f·7661·6c75·655c·225d··xpected_value\"]
 00041cb0:·2220·2667·743b·2667·743b·2022·244b·4152··"·&gt;&gt;·"$KAR
00041e10:·535f·4449·522f·3130·2d69·6f6d·6d75·2e74··S_DIR/10-iommu.t00041cc0:·4753·5f44·4952·2f31·302d·696f·6d6d·752e··GS_DIR/10-iommu.
00041e20:·6f6d·6c22·0a20·2020·2066·690a·656c·7365··oml".····fi.else00041cd0:·746f·6d6c·220a·2020·2020·6669·0a65·6c73··toml".····fi.els
00041e30:·0a0a·0a20·2020·2023·2043·6f72·7265·6374··...····#·Correct00041ce0:·650a·0a0a·2020·2020·2320·436f·7272·6563··e...····#·Correc
 00041cf0:·7420·7468·6520·666f·726d·206f·6620·6465··t·the·form·of·de
 00041d00:·6661·756c·7420·6b65·726e·656c·2063·6f6d··fault·kernel·com
 00041d10:·6d61·6e64·206c·696e·6520·696e·2047·5255··mand·line·in·GRU
 00041d20:·420a·2020·2020·6966·2067·7265·7020·2d71··B.····if·grep·-q
00041e40:·2074·6865·2066·6f72·6d20·6f66·2064·6566···the·form·of·def 
00041e50:·6175·6c74·206b·6572·6e65·6c20·636f·6d6d··ault·kernel·comm 
00041e60:·616e·6420·6c69·6e65·2069·6e20·4752·5542··and·line·in·GRUB 
00041e70:·0a20·2020·2069·6620·6772·6570·202d·7120··.····if·grep·-q· 
00041e80:·275e·5c73·2a47·5255·425f·434d·444c·494e··'^\s*GRUB_CMDLIN 
00041e90:·455f·4c49·4e55·583d·2e2a·696f·6d6d·753d··E_LINUX=.*iommu= 
00041ea0:·2e2a·2227·2020·272f·6574·632f·6465·6661··.*"'··'/etc/defa 
00041eb0:·756c·742f·6772·7562·2720·3b20·7468·656e··ult/grub'·;·then 
00041ec0:·0a20·2020·2020·2020·2020·2020·2320·6d6f··.···········#·mo 
00041ed0:·6469·6679·2074·6865·2047·5255·4220·636f··dify·the·GRUB·co 
Max diff block lines reached; 141618/159172 bytes (88.97%) of diff not shown.
11.1 KB
html2text {}
    
Offset 406, 17 lines modifiedOffset 406, 14 lines modified
406 enabling·IOMMU·can·cause·hardware·instabilities.·Proper·function·and·stability406 enabling·IOMMU·can·cause·hardware·instabilities.·Proper·function·and·stability
407 should·be·assessed·before·applying·remediation·to·production·systems.407 should·be·assessed·before·applying·remediation·to·production·systems.
408 Rationale:··On·x86·architectures,·activating·the·I/OMMU·prevents·the·system408 Rationale:··On·x86·architectures,·activating·the·I/OMMU·prevents·the·system
409 ············from·arbitrary·accesses·potentially·made·by·hardware·devices.409 ············from·arbitrary·accesses·potentially·made·by·hardware·devices.
410 Severity: ··unknown410 Severity: ··unknown
411 Rule·ID:····xccdf_org.ssgproject.content_rule_grub2_enable_iommu_force411 Rule·ID:····xccdf_org.ssgproject.content_rule_grub2_enable_iommu_force
412 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R7412 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R7
413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
414 [customizations.kernel] 
415 append·=·"iommu=force" 
416 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
417 #·Remediation·is·applicable·only·in·certain·platforms414 #·Remediation·is·applicable·only·in·certain·platforms
418 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/415 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/
419 dev/null·|·grep·-q·'^installed'·&&·dpkg-query·--show·--showformat='${db:416 dev/null·|·grep·-q·'^installed'·&&·dpkg-query·--show·--showformat='${db:
420 Status-Status}417 Status-Status}
421 '·'linux-base'·2>/dev/null·|·grep·-q·^installed·);·then418 '·'linux-base'·2>/dev/null·|·grep·-q·^installed·);·then
  
Offset 453, 14 lines modifiedOffset 450, 17 lines modified
453 ····update-grub450 ····update-grub
  
454 fi451 fi
  
455 else452 else
456 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'453 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
457 fi454 fi
 455 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 456 [customizations.kernel]
 457 append·=·"iommu=force"
458 Group  ·Configure·Syslog·  Group·contains·2·groups·and·4·rules458 Group  ·Configure·Syslog·  Group·contains·2·groups·and·4·rules
459 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·syslog·service·has·been·the·default·Unix·logging·mechanism·for·many459 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·syslog·service·has·been·the·default·Unix·logging·mechanism·for·many
460 years.·It·has·a·number·of·downsides,·including·inconsistent·log·format,·lack·of460 years.·It·has·a·number·of·downsides,·including·inconsistent·log·format,·lack·of
461 authentication·for·received·messages,·and·lack·of·authentication,·encryption,461 authentication·for·received·messages,·and·lack·of·authentication,·encryption,
462 or·reliable·transport·for·messages·sent·over·a·network.·However,·due·to·its462 or·reliable·transport·for·messages·sent·over·a·network.·However,·due·to·its
463 long·history,·syslog·is·a·de·facto·standard·which·is·supported·by·almost·all463 long·history,·syslog·is·a·de·facto·standard·which·is·supported·by·almost·all
464 Unix·applications.464 Unix·applications.
Offset 3685, 19 lines modifiedOffset 3685, 14 lines modified
3685 ···························SR·2.7,·SR·7.63685 ···························SR·2.7,·SR·7.6
3686 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3686 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3687 ···························A.14.2.4,·A.9.1.23687 ···························A.14.2.4,·A.9.1.2
3688 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3688 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3689 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33689 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3690 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002273690 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
3691 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.23691 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
3692 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3693 [[packages]] 
3694 name·=·"cron" 
3695 version·=·"*" 
3696 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83692 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3697 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3693 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3698 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3694 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3699 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3695 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3700 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3696 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3701 #·Remediation·is·applicable·only·in·certain·platforms3697 #·Remediation·is·applicable·only·in·certain·platforms
3702 if·dpkg-query·--show·--showformat='${db:Status-Status}3698 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 3738, 14 lines modifiedOffset 3733, 19 lines modified
3738 ··-·PCI-DSSv4-2.2.63733 ··-·PCI-DSSv4-2.2.6
3739 ··-·enable_strategy3734 ··-·enable_strategy
3740 ··-·low_complexity3735 ··-·low_complexity
3741 ··-·low_disruption3736 ··-·low_disruption
3742 ··-·medium_severity3737 ··-·medium_severity
3743 ··-·no_reboot_needed3738 ··-·no_reboot_needed
3744 ··-·package_cron_installed3739 ··-·package_cron_installed
 3740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3741 [[packages]]
 3742 name·=·"cron"
 3743 version·=·"*"
3745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3746 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3745 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3747 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3746 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3748 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3747 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3749 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3748 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3750 include·install_cron3749 include·install_cron
  
Offset 4130, 19 lines modifiedOffset 4130, 14 lines modified
4130 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,4130 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
4131 References:················4.4.2.44131 References:················4.4.2.4
4132 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94132 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4133 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14133 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4134 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)4134 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
4135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4138 [[packages]] 
4139 name·=·"ntp" 
4140 version·=·"*" 
4141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4146 #·Remediation·is·applicable·only·in·certain·platforms4142 #·Remediation·is·applicable·only·in·certain·platforms
4147 if·dpkg-query·--show·--showformat='${db:Status-Status}4143 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 4181, 14 lines modifiedOffset 4176, 19 lines modified
4181 ··-·PCI-DSS-Req-10.44176 ··-·PCI-DSS-Req-10.4
4182 ··-·enable_strategy4177 ··-·enable_strategy
4183 ··-·high_severity4178 ··-·high_severity
4184 ··-·low_complexity4179 ··-·low_complexity
4185 ··-·low_disruption4180 ··-·low_disruption
4186 ··-·no_reboot_needed4181 ··-·no_reboot_needed
4187 ··-·package_ntp_installed4182 ··-·package_ntp_installed
 4183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4184 [[packages]]
 4185 name·=·"ntp"
 4186 version·=·"*"
4188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4193 include·install_ntp4192 include·install_ntp
  
Offset 4220, 18 lines modifiedOffset 4220, 14 lines modified
4220 ···························4.4.2.44220 ···························4.4.2.4
4221 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94221 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4222 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14222 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4223 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)4223 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)
4224 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14224 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4225 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44225 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4226 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.64226 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.6
4227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4228 [customizations.services] 
4229 enabled·=·["ntp"] 
Max diff block lines reached; 5694/11335 bytes (50.23%) of diff not shown.
147 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-anssi_np_nt28_restrictive.html
    
Offset 28244, 143 lines modifiedOffset 28244, 143 lines modified
0006e530:·6172·6765·743d·2223·6964·6d39·3434·3322··arget="#idm9443"0006e530:·6172·6765·743d·2223·6964·6d39·3434·3322··arget="#idm9443"
0006e540:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0006e540:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0006e550:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0006e550:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0006e560:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0006e560:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0006e570:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0006e570:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0006e580:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0006e580:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0006e590:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0006e590:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0006e5a0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0006e5b0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0006e5c0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0006e5d0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0006e5e0:·6964·3d22·6964·6d39·3434·3322·3e3c·7461··id="idm9443"><ta
 0006e5f0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0006e600:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0006e610:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0006e620:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0006e630:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0006e640:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0006e650:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0006e660:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0006e670:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0006e680:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0006e690:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0006e6a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0006e6b0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0006e5a0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0006e5b0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0006e5c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0006e5d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0006e5e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0006e5f0:·2269·646d·3934·3433·223e·3c70·7265·3e3c··"idm9443"><pre>< 
0006e600:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0006e610:·5d5d·0a6e·616d·6520·3d20·2263·726f·6e22··]].name·=·"cron" 
0006e620:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0006e630:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0006e640:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0006e650:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0006e660:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0006e670:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0006e680:·2223·6964·6d39·3434·3422·2074·6162·696e··"#idm9444"·tabin 
0006e690:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0006e6a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0006e6b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0006e6c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0006e6d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0006e6e0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0006e6f0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0006e700:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0006e710:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0006e720:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0006e730:·6d39·3434·3422·3e3c·7461·626c·6520·636c··m9444"><table·cl 
0006e740:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0006e750:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0006e760:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0006e770:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0006e780:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0006e790:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0006e7a0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0006e7b0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0006e7c0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0006e7d0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0006e7e0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0006e6c0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0006e6d0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0006e6e0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0006e6f0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0006e700:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0006e710:·2070·6c61·7466·6f72·6d73·0a69·6620·6470···platforms.if·dp
 0006e720:·6b67·2d71·7565·7279·202d·2d73·686f·7720··kg-query·--show·
 0006e730:·2d2d·7368·6f77·666f·726d·6174·3d27·247b··--showformat='${
 0006e740:·6462·3a53·7461·7475·732d·5374·6174·7573··db:Status-Status
 0006e750:·7d0a·2720·276c·696e·7578·2d62·6173·6527··}.'·'linux-base'
 0006e760:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null·
 0006e770:·7c20·6772·6570·202d·7120·5e69·6e73·7461··|·grep·-q·^insta
 0006e780:·6c6c·6564·3b20·7468·656e·0a0a·4445·4249··lled;·then..DEBI
 0006e790:·414e·5f46·524f·4e54·454e·443d·6e6f·6e69··AN_FRONTEND=noni
 0006e7a0:·6e74·6572·6163·7469·7665·2061·7074·2d67··nteractive·apt-g
 0006e7b0:·6574·2069·6e73·7461·6c6c·202d·7920·2263··et·install·-y·"c
 0006e7c0:·726f·6e22·0a0a·656c·7365·0a20·2020·2026··ron"..else.····&
 0006e7d0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
0006e7f0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0006e800:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0006e810:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0006e820:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0006e830:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0006e840:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0006e850:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0006e860:·6f72·6d73·0a69·6620·6470·6b67·2d71·7565··orms.if·dpkg-que 
0006e870:·7279·202d·2d73·686f·7720·2d2d·7368·6f77··ry·--show·--show 
0006e880:·666f·726d·6174·3d27·247b·6462·3a53·7461··format='${db:Sta 
0006e890:·7475·732d·5374·6174·7573·7d0a·2720·276c··tus-Status}.'·'l 
0006e8a0:·696e·7578·2d62·6173·6527·2032·2667·743b··inux-base'·2&gt; 
0006e8b0:·2f64·6576·2f6e·756c·6c20·7c20·6772·6570··/dev/null·|·grep 
0006e8c0:·202d·7120·5e69·6e73·7461·6c6c·6564·3b20···-q·^installed;· 
0006e8d0:·7468·656e·0a0a·4445·4249·414e·5f46·524f··then..DEBIAN_FRO 
0006e8e0:·4e54·454e·443d·6e6f·6e69·6e74·6572·6163··NTEND=noninterac 
0006e8f0:·7469·7665·2061·7074·2d67·6574·2069·6e73··tive·apt-get·ins 
0006e900:·7461·6c6c·202d·7920·2263·726f·6e22·0a0a··tall·-y·"cron".. 
0006e910:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0006e920:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0006e930:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0006e940:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0006e950:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0006e960:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0006e970:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0006e980:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0006e990:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0006e9a0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0006e9b0:·2369·646d·3934·3435·2220·7461·6269·6e64··#idm9445"·tabind 
0006e9c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0006e9d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0006e9e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0006e9f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0006ea00:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0006ea10:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0006e7e0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
0006ea20:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0006ea30:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0006ea40:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0006ea50:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0006ea60:·6964·6d39·3434·3522·3e3c·7461·626c·6520··idm9445"><table· 
0006ea70:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0006ea80:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0006ea90:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0006eaa0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0006eab0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0006eac0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0006ead0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0006eae0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
Max diff block lines reached; 122684/141066 bytes (86.97%) of diff not shown.
9.37 KB
html2text {}
    
Offset 3607, 19 lines modifiedOffset 3607, 14 lines modified
3607 ···························SR·2.7,·SR·7.63607 ···························SR·2.7,·SR·7.6
3608 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3608 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3609 ···························A.14.2.4,·A.9.1.23609 ···························A.14.2.4,·A.9.1.2
3610 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3610 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3611 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33611 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3612 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002273612 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
3613 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.23613 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
3614 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3615 [[packages]] 
3616 name·=·"cron" 
3617 version·=·"*" 
3618 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83614 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3619 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3615 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3620 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3616 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3621 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3617 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3622 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3618 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3623 #·Remediation·is·applicable·only·in·certain·platforms3619 #·Remediation·is·applicable·only·in·certain·platforms
3624 if·dpkg-query·--show·--showformat='${db:Status-Status}3620 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 3660, 14 lines modifiedOffset 3655, 19 lines modified
3660 ··-·PCI-DSSv4-2.2.63655 ··-·PCI-DSSv4-2.2.6
3661 ··-·enable_strategy3656 ··-·enable_strategy
3662 ··-·low_complexity3657 ··-·low_complexity
3663 ··-·low_disruption3658 ··-·low_disruption
3664 ··-·medium_severity3659 ··-·medium_severity
3665 ··-·no_reboot_needed3660 ··-·no_reboot_needed
3666 ··-·package_cron_installed3661 ··-·package_cron_installed
 3662 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3663 [[packages]]
 3664 name·=·"cron"
 3665 version·=·"*"
3667 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83666 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3668 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3667 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3669 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3668 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3670 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3669 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3671 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3670 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3672 include·install_cron3671 include·install_cron
  
Offset 4052, 19 lines modifiedOffset 4052, 14 lines modified
4052 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,4052 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
4053 References:················4.4.2.44053 References:················4.4.2.4
4054 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94054 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4055 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14055 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4056 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)4056 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
4057 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14057 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4058 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44058 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4059 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4060 [[packages]] 
4061 name·=·"ntp" 
4062 version·=·"*" 
4063 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84059 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4064 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4060 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4065 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4061 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4066 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4062 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4067 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4063 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4068 #·Remediation·is·applicable·only·in·certain·platforms4064 #·Remediation·is·applicable·only·in·certain·platforms
4069 if·dpkg-query·--show·--showformat='${db:Status-Status}4065 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 4103, 14 lines modifiedOffset 4098, 19 lines modified
4103 ··-·PCI-DSS-Req-10.44098 ··-·PCI-DSS-Req-10.4
4104 ··-·enable_strategy4099 ··-·enable_strategy
4105 ··-·high_severity4100 ··-·high_severity
4106 ··-·low_complexity4101 ··-·low_complexity
4107 ··-·low_disruption4102 ··-·low_disruption
4108 ··-·no_reboot_needed4103 ··-·no_reboot_needed
4109 ··-·package_ntp_installed4104 ··-·package_ntp_installed
 4105 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4106 [[packages]]
 4107 name·=·"ntp"
 4108 version·=·"*"
4110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84109 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4110 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4111 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4112 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4113 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4115 include·install_ntp4114 include·install_ntp
  
Offset 4142, 18 lines modifiedOffset 4142, 14 lines modified
4142 ···························4.4.2.44142 ···························4.4.2.4
4143 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94143 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4144 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14144 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4145 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)4145 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)
4146 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14146 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4147 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44147 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4148 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.64148 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.6
4149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4150 [customizations.services] 
4151 enabled·=·["ntp"] 
4152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4157 #·Remediation·is·applicable·only·in·certain·platforms4154 #·Remediation·is·applicable·only·in·certain·platforms
4158 if·dpkg-query·--show·--showformat='${db:Status-Status}4155 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 4218, 14 lines modifiedOffset 4214, 18 lines modified
4218 ··-·PCI-DSSv4-10.6.14214 ··-·PCI-DSSv4-10.6.1
4219 ··-·enable_strategy4215 ··-·enable_strategy
4220 ··-·high_severity4216 ··-·high_severity
4221 ··-·low_complexity4217 ··-·low_complexity
4222 ··-·low_disruption4218 ··-·low_disruption
4223 ··-·no_reboot_needed4219 ··-·no_reboot_needed
4224 ··-·service_ntp_enabled4220 ··-·service_ntp_enabled
 4221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4222 [customizations.services]
 4223 enabled·=·["ntp"]
4225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4227 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4228 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4230 include·enable_ntp4229 include·enable_ntp
  
Offset 4255, 18 lines modifiedOffset 4255, 14 lines modified
4255 ···························4.4.2.44255 ···························4.4.2.4
4256 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94256 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4257 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14257 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4258 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)4258 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)
4259 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14259 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4260 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44260 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4261 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.64261 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.6
4262 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 4103/9574 bytes (42.86%) of diff not shown.
214 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1604-guide-standard.html
    
Offset 19807, 140 lines modifiedOffset 19807, 140 lines modified
0004d5e0:·6172·6765·743d·2223·6964·6d34·3733·3522··arget="#idm4735"0004d5e0:·6172·6765·743d·2223·6964·6d34·3733·3522··arget="#idm4735"
0004d5f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0004d5f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0004d600:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0004d600:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0004d610:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0004d610:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0004d620:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0004d620:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0004d630:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0004d630:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0004d640:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0004d640:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0004d650:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
0004d650:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0004d660:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0004d670:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0004d680:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0004d690:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0004d6a0:·2269·646d·3437·3335·223e·3c70·7265·3e3c··"idm4735"><pre>< 
0004d6b0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0004d6c0:·5d5d·0a6e·616d·6520·3d20·2272·7379·736c··]].name·=·"rsysl 
0004d6d0:·6f67·220a·7665·7273·696f·6e20·3d20·222a··og".version·=·"* 
0004d6e0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0004d6f0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0004d700:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0004d710:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0004d720:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0004d730:·6574·3d22·2369·646d·3437·3336·2220·7461··et="#idm4736"·ta 
0004d740:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0004d750:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0004d760:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0004d770:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0004d780:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0004d790:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0004d7a0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0004d7b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0004d7c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0004d7d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0004d7e0:·2269·646d·3437·3336·223e·3c74·6162·6c65··"idm4736"><table 
0004d7f0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0004d800:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0004d810:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0004d820:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0004d830:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0004d840:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0004d850:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0004d860:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0004d870:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0004d880:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0004d890:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0004d8a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0004d8b0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0004d8c0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0004d8d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0004d8e0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0004d8f0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0004d900:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0004d910:·6174·666f·726d·730a·6966·2064·706b·672d··atforms.if·dpkg- 
0004d920:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s 
0004d930:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db: 
0004d940:·5374·6174·7573·2d53·7461·7475·737d·0a27··Status-Status}.' 
0004d950:·2027·6c69·6e75·782d·6261·7365·2720·3226···'linux-base'·2& 
0004d960:·6774·3b2f·6465·762f·6e75·6c6c·207c·2067··gt;/dev/null·|·g 
0004d970:·7265·7020·2d71·205e·696e·7374·616c·6c65··rep·-q·^installe 
0004d980:·643b·2074·6865·6e0a·0a44·4542·4941·4e5f··d;·then..DEBIAN_ 
0004d990:·4652·4f4e·5445·4e44·3d6e·6f6e·696e·7465··FRONTEND=noninte 
0004d9a0:·7261·6374·6976·6520·6170·742d·6765·7420··ractive·apt-get· 
0004d9b0:·696e·7374·616c·6c20·2d79·2022·7273·7973··install·-y·"rsys 
0004d9c0:·6c6f·6722·0a0a·656c·7365·0a20·2020·2026··log"..else.····& 
0004d9d0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0004d9e0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0004d9f0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0004da00:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0004da10:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0004da20:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0004da30:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0004da40:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0004da50:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0004da60:·7267·6574·3d22·2369·646d·3437·3337·2220··rget="#idm4737"· 
0004da70:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0004da80:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0004da90:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0004daa0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0004dab0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0004dac0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0004dad0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0004dae0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0004d660:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0004daf0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0004d670:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0004db00:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0004d680:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0004db10:·2220·6964·3d22·6964·6d34·3733·3722·3e3c··"·id="idm4737"><0004d690:·6964·3d22·6964·6d34·3733·3522·3e3c·7461··id="idm4735"><ta
0004db20:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0004d6a0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0004db30:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0004d6b0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0004db40:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0004d6c0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0004db50:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0004d6d0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0004db60:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0004d6e0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0004db70:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0004d6f0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0004db80:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0004d700:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0004db90:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0004d710:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0004dba0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0004d720:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0004dbb0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0004d730:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0004dbc0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0004d740:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0004dbd0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0004d750:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0004dbe0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0004d760:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0004dbf0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0004d770:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0004dc00:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0004d780:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0004dc10:·3e3c·636f·6465·3e2d·206e·616d·653a·2047··><code>-·name:·G 
0004dc20:·6174·6865·7220·7468·6520·7061·636b·6167··ather·the·packag 
0004dc30:·6520·6661·6374·730a·2020·7061·636b·6167··e·facts.··packag 
0004dc40:·655f·6661·6374·733a·0a20·2020·206d·616e··e_facts:.····man 
0004dc50:·6167·6572·3a20·6175·746f·0a20·2074·6167··ager:·auto.··tag 
0004dc60:·733a·0a20·202d·204e·4953·542d·3830·302d··s:.··-·NIST-800- 
0004dc70:·3533·2d43·4d2d·3628·6129·0a20·202d·2065··53-CM-6(a).··-·e 
0004dc80:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
0004dc90:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
0004dca0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
0004dcb0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
0004dcc0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
0004dcd0:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
0004dce0:·2d20·7061·636b·6167·655f·7273·7973·6c6f··-·package_rsyslo 
0004dcf0:·675f·696e·7374·616c·6c65·640a·0a2d·206e··g_installed..-·n 
0004dd00:·616d·653a·2045·6e73·7572·6520·7273·7973··ame:·Ensure·rsys 
0004dd10:·6c6f·6720·6973·2069·6e73·7461·6c6c·6564··log·is·installed 
0004dd20:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.···· 
0004dd30:·6e61·6d65·3a20·7273·7973·6c6f·670a·2020··name:·rsyslog.·· 
0004dd40:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present 
0004dd50:·0a20·2077·6865·6e3a·2027·226c·696e·7578··.··when:·'"linux 
0004dd60:·2d62·6173·6522·2069·6e20·616e·7369·626c··-base"·in·ansibl 
0004dd70:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages0004d790:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0004d7a0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0004d7b0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0004d7c0:·2070·6c61·7466·6f72·6d73·0a69·6620·6470···platforms.if·dp
 0004d7d0:·6b67·2d71·7565·7279·202d·2d73·686f·7720··kg-query·--show·
Max diff block lines reached; 186110/204078 bytes (91.20%) of diff not shown.
14.2 KB
html2text {}
    
Offset 1644, 19 lines modifiedOffset 1644, 14 lines modified
1644 References:················4.4.2.41644 References:················4.4.2.4
1645 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91645 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1646 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11646 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1647 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1647 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1648 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11648 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1649 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1649 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1650 ···························SRG-OS-000480-GPOS-002271650 ···························SRG-OS-000480-GPOS-00227
1651 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1652 [[packages]] 
1653 name·=·"rsyslog" 
1654 version·=·"*" 
1655 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81651 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1656 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1652 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1657 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1653 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1658 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1654 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1659 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1655 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1660 #·Remediation·is·applicable·only·in·certain·platforms1656 #·Remediation·is·applicable·only·in·certain·platforms
1661 if·dpkg-query·--show·--showformat='${db:Status-Status}1657 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1693, 14 lines modifiedOffset 1688, 19 lines modified
1693 ··-·NIST-800-53-CM-6(a)1688 ··-·NIST-800-53-CM-6(a)
1694 ··-·enable_strategy1689 ··-·enable_strategy
1695 ··-·low_complexity1690 ··-·low_complexity
1696 ··-·low_disruption1691 ··-·low_disruption
1697 ··-·medium_severity1692 ··-·medium_severity
1698 ··-·no_reboot_needed1693 ··-·no_reboot_needed
1699 ··-·package_rsyslog_installed1694 ··-·package_rsyslog_installed
 1695 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1696 [[packages]]
 1697 name·=·"rsyslog"
 1698 version·=·"*"
1700 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81699 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1701 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1700 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1702 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1701 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1703 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1702 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1704 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1703 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1705 include·install_rsyslog1704 include·install_rsyslog
  
Offset 1729, 18 lines modifiedOffset 1729, 14 lines modified
1729 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,1729 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
1730 ···························SR·6.2,·SR·7.1,·SR·7.21730 ···························SR·6.2,·SR·7.1,·SR·7.2
1731 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,1731 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
1732 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11732 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1733 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1733 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1734 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11734 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1735 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002271735 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
1736 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1737 [customizations.services] 
1738 enabled·=·["rsyslog"] 
1739 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81736 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1740 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1737 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1741 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1738 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1742 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1739 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1743 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1740 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1744 #·Remediation·is·applicable·only·in·certain·platforms1741 #·Remediation·is·applicable·only·in·certain·platforms
1745 if·dpkg-query·--show·--showformat='${db:Status-Status}1742 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1795, 14 lines modifiedOffset 1791, 18 lines modified
1795 ··-·NIST-800-53-CM-6(a)1791 ··-·NIST-800-53-CM-6(a)
1796 ··-·enable_strategy1792 ··-·enable_strategy
1797 ··-·low_complexity1793 ··-·low_complexity
1798 ··-·low_disruption1794 ··-·low_disruption
1799 ··-·medium_severity1795 ··-·medium_severity
1800 ··-·no_reboot_needed1796 ··-·no_reboot_needed
1801 ··-·service_rsyslog_enabled1797 ··-·service_rsyslog_enabled
 1798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1799 [customizations.services]
 1800 enabled·=·["rsyslog"]
1802 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1803 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1802 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1804 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1803 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1805 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1804 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1806 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1805 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1807 include·enable_rsyslog1806 include·enable_rsyslog
  
Offset 3593, 19 lines modifiedOffset 3593, 14 lines modified
3593 ···························SR·2.7,·SR·7.63593 ···························SR·2.7,·SR·7.6
3594 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3594 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3595 ···························A.14.2.4,·A.9.1.23595 ···························A.14.2.4,·A.9.1.2
3596 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3596 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3597 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33597 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3598 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002273598 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
3599 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.23599 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
3600 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3601 [[packages]] 
3602 name·=·"cron" 
3603 version·=·"*" 
3604 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83600 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3605 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3601 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3606 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3602 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3607 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3603 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3608 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3604 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3609 #·Remediation·is·applicable·only·in·certain·platforms3605 #·Remediation·is·applicable·only·in·certain·platforms
3610 if·dpkg-query·--show·--showformat='${db:Status-Status}3606 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 3646, 14 lines modifiedOffset 3641, 19 lines modified
3646 ··-·PCI-DSSv4-2.2.63641 ··-·PCI-DSSv4-2.2.6
3647 ··-·enable_strategy3642 ··-·enable_strategy
3648 ··-·low_complexity3643 ··-·low_complexity
3649 ··-·low_disruption3644 ··-·low_disruption
3650 ··-·medium_severity3645 ··-·medium_severity
3651 ··-·no_reboot_needed3646 ··-·no_reboot_needed
3652 ··-·package_cron_installed3647 ··-·package_cron_installed
 3648 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3649 [[packages]]
 3650 name·=·"cron"
 3651 version·=·"*"
3653 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83652 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3654 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3653 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3655 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3654 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3656 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3655 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3657 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3656 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3658 include·install_cron3657 include·install_cron
  
Offset 3687, 18 lines modifiedOffset 3687, 14 lines modified
3687 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR3687 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR
3688 ···························1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,3688 ···························1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,
3689 ···························SR·2.7,·SR·7.63689 ···························SR·2.7,·SR·7.6
3690 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3690 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3691 ···························A.14.2.4,·A.9.1.23691 ···························A.14.2.4,·A.9.1.2
3692 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3692 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3693 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33693 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3694 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 8893/14524 bytes (61.23%) of diff not shown.
19.8 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_average.html
    
Offset 29972, 141 lines modifiedOffset 29972, 141 lines modified
00075130:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00075130:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00075140:·6964·6d31·3139·3930·2220·7461·6269·6e64··idm11990"·tabind00075140:·6964·6d31·3139·3930·2220·7461·6269·6e64··idm11990"·tabind
00075150:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00075150:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
00075160:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00075160:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
00075170:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00075170:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00075180:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00075180:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00075190:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00075190:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
000751a0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu000751a0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 000751b0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
000751b0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
000751c0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
000751d0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
000751e0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
000751f0:·6170·7365·2220·6964·3d22·6964·6d31·3139··apse"·id="idm119 
00075200:·3930·223e·3c70·7265·3e3c·636f·6465·3e0a··90"><pre><code>. 
00075210:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
00075220:·6520·3d20·226e·7470·220a·7665·7273·696f··e·=·"ntp".versio 
00075230:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
00075240:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
00075250:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00075260:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00075270:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
00075280:·612d·7461·7267·6574·3d22·2369·646d·3131··a-target="#idm11 
00075290:·3939·3122·2074·6162·696e·6465·783d·2230··991"·tabindex="0 
000752a0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
000752b0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
000752c0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
000752d0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
000752e0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
000752f0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
00075300:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
00075310:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00075320:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00075330:·7365·2220·6964·3d22·6964·6d31·3139·3931··se"·id="idm11991 
00075340:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
00075350:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
00075360:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
00075370:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
00075380:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00075390:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
000753a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
000753b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
000753c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
000753d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
000753e0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
000753f0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
00075400:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
00075410:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
00075420:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
00075430:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
00075440:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
00075450:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
00075460:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
00075470:·6966·2064·706b·672d·7175·6572·7920·2d2d··if·dpkg-query·-- 
00075480:·7368·6f77·202d·2d73·686f·7766·6f72·6d61··show·--showforma 
00075490:·743d·2724·7b64·623a·5374·6174·7573·2d53··t='${db:Status-S 
000754a0:·7461·7475·737d·0a27·2027·6c69·6e75·782d··tatus}.'·'linux- 
000754b0:·6261·7365·2720·3226·6774·3b2f·6465·762f··base'·2&gt;/dev/ 
000754c0:·6e75·6c6c·207c·2067·7265·7020·2d71·205e··null·|·grep·-q·^ 
000754d0:·696e·7374·616c·6c65·643b·2074·6865·6e0a··installed;·then. 
000754e0:·0a44·4542·4941·4e5f·4652·4f4e·5445·4e44··.DEBIAN_FRONTEND 
000754f0:·3d6e·6f6e·696e·7465·7261·6374·6976·6520··=noninteractive· 
00075500:·6170·742d·6765·7420·696e·7374·616c·6c20··apt-get·install· 
00075510:·2d79·2022·6e74·7022·0a0a·656c·7365·0a20··-y·"ntp"..else.· 
00075520:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
00075530:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
00075540:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
00075550:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
00075560:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
00075570:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
00075580:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00075590:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
000755a0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
000755b0:·612d·7461·7267·6574·3d22·2369·646d·3131··a-target="#idm11 
000755c0:·3939·3222·2074·6162·696e·6465·783d·2230··992"·tabindex="0 
000755d0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
000755e0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
000755f0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
00075600:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
00075610:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
00075620:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
00075630:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00075640:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa000751c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
00075650:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col000751d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
00075660:·6c61·7073·6522·2069·643d·2269·646d·3131··lapse"·id="idm11000751e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
00075670:·3939·3222·3e3c·7461·626c·6520·636c·6173··992"><table·clas000751f0:·3131·3939·3022·3e3c·7461·626c·6520·636c··11990"><table·cl
00075680:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s00075200:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
00075690:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor00075210:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
000756a0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond00075220:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
000756b0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C00075230:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
000756c0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><00075240:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
000756d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00075250:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
000756e0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti00075260:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
000756f0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<00075270:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
00075700:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00075280:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
00075710:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td00075290:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
00075720:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>000752a0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
00075730:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy000752b0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
00075740:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable000752c0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
00075750:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl000752d0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
00075760:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n000752e0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
00075770:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
00075780:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
00075790:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
000757a0:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto 
000757b0:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS 
000757c0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
000757d0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
000757e0:·2d31·302e·340a·2020·2d20·656e·6162·6c65··-10.4.··-·enable 
000757f0:·5f73·7472·6174·6567·790a·2020·2d20·6869··_strategy.··-·hi 
00075800:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-· 
00075810:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.· 
00075820:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio 
00075830:·6e0a·2020·2d20·6e6f·5f72·6562·6f6f·745f··n.··-·no_reboot_ 
00075840:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa 
00075850:·6765·5f6e·7470·5f69·6e73·7461·6c6c·6564··ge_ntp_installed 
00075860:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure 
00075870:·206e·7470·2069·7320·696e·7374·616c·6c65···ntp·is·installe 
00075880:·640a·2020·7061·636b·6167·653a·0a20·2020··d.··package:.··· 
00075890:·206e·616d·653a·206e·7470·0a20·2020·2073···name:·ntp.····s 
000758a0:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.·· 
000758b0:·7768·656e·3a20·2722·6c69·6e75·782d·6261··when:·'"linux-ba 
000758c0:·7365·2220·696e·2061·6e73·6962·6c65·5f66··se"·in·ansible_f 
000758d0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
000758e0:·2074·6167·733a·0a20·202d·204e·4953·542d···tags:.··-·NIST- 
000758f0:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
00075900:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
Max diff block lines reached; 414/18520 bytes (2.24%) of diff not shown.
1.6 KB
html2text {}
    
Offset 3955, 19 lines modifiedOffset 3955, 14 lines modified
3955 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,3955 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
3956 References:················4.4.2.43956 References:················4.4.2.4
3957 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.93957 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
3958 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.13958 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
3959 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3959 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3960 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-13960 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
3961 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.43961 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
3962 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3963 [[packages]] 
3964 name·=·"ntp" 
3965 version·=·"*" 
3966 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83962 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3967 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3963 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3968 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3964 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3969 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3965 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3970 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3966 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3971 #·Remediation·is·applicable·only·in·certain·platforms3967 #·Remediation·is·applicable·only·in·certain·platforms
3972 if·dpkg-query·--show·--showformat='${db:Status-Status}3968 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 4006, 14 lines modifiedOffset 4001, 19 lines modified
4006 ··-·PCI-DSS-Req-10.44001 ··-·PCI-DSS-Req-10.4
4007 ··-·enable_strategy4002 ··-·enable_strategy
4008 ··-·high_severity4003 ··-·high_severity
4009 ··-·low_complexity4004 ··-·low_complexity
4010 ··-·low_disruption4005 ··-·low_disruption
4011 ··-·no_reboot_needed4006 ··-·no_reboot_needed
4012 ··-·package_ntp_installed4007 ··-·package_ntp_installed
 4008 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4009 [[packages]]
 4010 name·=·"ntp"
 4011 version·=·"*"
4013 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84012 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4014 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4013 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4015 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4014 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4016 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4015 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4017 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4016 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4018 include·install_ntp4017 include·install_ntp
  
167 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_high.html
    
Offset 16823, 137 lines modifiedOffset 16823, 137 lines modified
00041b60:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i00041b60:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
00041b70:·646d·3431·3039·2220·7461·6269·6e64·6578··dm4109"·tabindex00041b70:·646d·3431·3039·2220·7461·6269·6e64·6578··dm4109"·tabindex
00041b80:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00041b80:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00041b90:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00041b90:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00041ba0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00041ba0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00041bb0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00041bb0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00041bc0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00041bc0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
00041bd0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil00041bd0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 00041be0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 00041bf0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00041c00:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00041c10:·6c61·7073·6522·2069·643d·2269·646d·3431··lapse"·id="idm41
 00041c20:·3039·223e·3c70·7265·3e3c·636f·6465·3e23··09"><pre><code>#
 00041c30:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 00041c40:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 00041c50:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 00041c60:·6f72·6d73·0a69·6620·2820·6470·6b67·2d71··orms.if·(·dpkg-q
 00041c70:·7565·7279·202d·2d73·686f·7720·2d2d·7368··uery·--show·--sh
 00041c80:·6f77·666f·726d·6174·3d27·247b·6462·3a53··owformat='${db:S
 00041c90:·7461·7475·732d·5374·6174·7573·7d5c·6e27··tatus-Status}\n'
 00041ca0:·2027·6772·7562·322d·636f·6d6d·6f6e·2720···'grub2-common'·
 00041cb0:·3226·6774·3b2f·6465·762f·6e75·6c6c·207c··2&gt;/dev/null·|
 00041cc0:·2067·7265·7020·2d71·2027·5e69·6e73·7461···grep·-q·'^insta
 00041cd0:·6c6c·6564·2720·2661·6d70·3b26·616d·703b··lled'·&amp;&amp;
 00041ce0:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh
 00041cf0:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat=
 00041d00:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta
 00041d10:·7475·737d·0a27·2027·6c69·6e75·782d·6261··tus}.'·'linux-ba
 00041d20:·7365·2720·3226·6774·3b2f·6465·762f·6e75··se'·2&gt;/dev/nu
 00041d30:·6c6c·207c·2067·7265·7020·2d71·205e·696e··ll·|·grep·-q·^in
 00041d40:·7374·616c·6c65·6420·293b·2074·6865·6e0a··stalled·);·then.
 00041d50:·0a65·7870·6563·7465·645f·7661·6c75·653d··.expected_value=
 00041d60:·2266·6f72·6365·220a·0a0a·6966·205b·5b20··"force"...if·[[·
 00041d70:·2224·4f53·4341·505f·424f·4f54·435f·4255··"$OSCAP_BOOTC_BU
 00041d80:·494c·4422·203d·3d20·2259·4553·2220·5d5d··ILD"·==·"YES"·]]
00041be0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
00041bf0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
00041c00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00041c10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00041c20:·7365·2220·6964·3d22·6964·6d34·3130·3922··se"·id="idm4109" 
00041c30:·3e3c·7072·653e·3c63·6f64·653e·5b63·7573··><pre><code>[cus 
00041c40:·746f·6d69·7a61·7469·6f6e·732e·6b65·726e··tomizations.kern 
00041c50:·656c·5d0a·6170·7065·6e64·203d·2022·696f··el].append·=·"io 
00041c60:·6d6d·753d·666f·7263·6522·0a3c·2f63·6f64··mmu=force".</cod 
00041c70:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
00041c80:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
00041c90:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
00041ca0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
00041cb0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
00041cc0:·6d34·3131·3022·2074·6162·696e·6465·783d··m4110"·tabindex= 
00041cd0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
00041ce0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
00041cf0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
00041d00:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
00041d10:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
00041d20:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
00041d30:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
00041d40:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00041d50:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00041d60:·6170·7365·2220·6964·3d22·6964·6d34·3131··apse"·id="idm411 
00041d70:·3022·3e3c·7072·653e·3c63·6f64·653e·2320··0"><pre><code>#· 
00041d80:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
00041d90:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
00041da0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
00041db0:·726d·730a·6966·2028·2064·706b·672d·7175··rms.if·(·dpkg-qu 
00041dc0:·6572·7920·2d2d·7368·6f77·202d·2d73·686f··ery·--show·--sho 
00041dd0:·7766·6f72·6d61·743d·2724·7b64·623a·5374··wformat='${db:St 
00041de0:·6174·7573·2d53·7461·7475·737d·5c6e·2720··atus-Status}\n'· 
00041df0:·2767·7275·6232·2d63·6f6d·6d6f·6e27·2032··'grub2-common'·2 
00041e00:·2667·743b·2f64·6576·2f6e·756c·6c20·7c20··&gt;/dev/null·|· 
00041e10:·6772·6570·202d·7120·275e·696e·7374·616c··grep·-q·'^instal 
00041e20:·6c65·6427·2026·616d·703b·2661·6d70·3b20··led'·&amp;&amp;· 
00041e30:·6470·6b67·2d71·7565·7279·202d·2d73·686f··dpkg-query·--sho 
00041e40:·7720·2d2d·7368·6f77·666f·726d·6174·3d27··w·--showformat=' 
00041e50:·247b·6462·3a53·7461·7475·732d·5374·6174··${db:Status-Stat 
00041e60:·7573·7d0a·2720·276c·696e·7578·2d62·6173··us}.'·'linux-bas 
00041e70:·6527·2032·2667·743b·2f64·6576·2f6e·756c··e'·2&gt;/dev/nul 
00041e80:·6c20·7c20·6772·6570·202d·7120·5e69·6e73··l·|·grep·-q·^ins 
00041e90:·7461·6c6c·6564·2029·3b20·7468·656e·0a0a··talled·);·then.. 
00041ea0:·6578·7065·6374·6564·5f76·616c·7565·3d22··expected_value=" 
00041eb0:·666f·7263·6522·0a0a·0a69·6620·5b5b·2022··force"...if·[[·" 
00041ec0:·244f·5343·4150·5f42·4f4f·5443·5f42·5549··$OSCAP_BOOTC_BUI 
00041ed0:·4c44·2220·3d3d·2022·5945·5322·205d·5d20··LD"·==·"YES"·]]· 
00041ee0:·3b20·7468·656e·0a20·2020·204b·4152·4753··;·then.····KARGS00041d90:·203b·2074·6865·6e0a·2020·2020·4b41·5247···;·then.····KARG
00041ef0:·5f44·4952·3d22·2f75·7372·2f6c·6962·2f62··_DIR="/usr/lib/b00041da0:·535f·4449·523d·222f·7573·722f·6c69·622f··S_DIR="/usr/lib/
00041f00:·6f6f·7463·2f6b·6172·6773·2e64·2f22·0a20··ootc/kargs.d/".· 
00041f10:·2020·2069·6620·6772·6570·202d·7120·2d45·····if·grep·-q·-E 
00041f20:·2022·696f·6d6d·7522·2022·244b·4152·4753···"iommu"·"$KARGS00041db0:·626f·6f74·632f·6b61·7267·732e·642f·220a··bootc/kargs.d/".
 00041dc0:·2020·2020·6966·2067·7265·7020·2d71·202d······if·grep·-q·-
 00041dd0:·4520·2269·6f6d·6d75·2220·2224·4b41·5247··E·"iommu"·"$KARG
 00041de0:·535f·4449·522f·2a2e·746f·6d6c·2220·3b20··S_DIR/*.toml"·;·
 00041df0:·7468·656e·0a20·2020·2020·2020·2073·6564··then.········sed
 00041e00:·202d·6920·2d45·2022·732f·5e28·5c73·2a6b···-i·-E·"s/^(\s*k
 00041e10:·6172·6773·5c73·2a3d·5c73·2a5c·5b2e·2a29··args\s*=\s*\[.*)
 00041e20:·5c22·696f·6d6d·753d·5b5e·5c22·5d2a·5c22··\"iommu=[^\"]*\"
 00041e30:·282e·2a5d·5c73·2a29·2f5c·315c·2269·6f6d··(.*]\s*)/\1\"iom
 00041e40:·6d75·3d24·6578·7065·6374·6564·5f76·616c··mu=$expected_val
 00041e50:·7565·5c22·5c32·2f22·2022·244b·4152·4753··ue\"\2/"·"$KARGS
00041f30:·5f44·4952·2f2a·2e74·6f6d·6c22·203b·2074··_DIR/*.toml"·;·t00041e60:·5f44·4952·2f2a·2e74·6f6d·6c22·0a20·2020··_DIR/*.toml".···
00041f40:·6865·6e0a·2020·2020·2020·2020·7365·6420··hen.········sed· 
00041f50:·2d69·202d·4520·2273·2f5e·285c·732a·6b61··-i·-E·"s/^(\s*ka 
00041f60:·7267·735c·732a·3d5c·732a·5c5b·2e2a·295c··rgs\s*=\s*\[.*)\ 
00041f70:·2269·6f6d·6d75·3d5b·5e5c·225d·2a5c·2228··"iommu=[^\"]*\"( 
00041f80:·2e2a·5d5c·732a·292f·5c31·5c22·696f·6d6d··.*]\s*)/\1\"iomm 
00041f90:·753d·2465·7870·6563·7465·645f·7661·6c75··u=$expected_valu 
00041fa0:·655c·225c·322f·2220·2224·4b41·5247·535f··e\"\2/"·"$KARGS_ 
00041fb0:·4449·522f·2a2e·746f·6d6c·220a·2020·2020··DIR/*.toml".···· 
00041fc0:·656c·7365·0a20·2020·2020·2020·2065·6368··else.········ech00041e70:·2065·6c73·650a·2020·2020·2020·2020·6563···else.········ec
 00041e80:·686f·2022·6b61·7267·7320·3d20·5b5c·2269··ho·"kargs·=·[\"i
 00041e90:·6f6d·6d75·3d24·6578·7065·6374·6564·5f76··ommu=$expected_v
 00041ea0:·616c·7565·5c22·5d22·2026·6774·3b26·6774··alue\"]"·&gt;&gt
 00041eb0:·3b20·2224·4b41·5247·535f·4449·522f·3130··;·"$KARGS_DIR/10
 00041ec0:·2d69·6f6d·6d75·2e74·6f6d·6c22·0a20·2020··-iommu.toml".···
 00041ed0:·2066·690a·656c·7365·0a0a·0a20·2020·2023···fi.else...····#
 00041ee0:·2043·6f72·7265·6374·2074·6865·2066·6f72···Correct·the·for
 00041ef0:·6d20·6f66·2064·6566·6175·6c74·206b·6572··m·of·default·ker
 00041f00:·6e65·6c20·636f·6d6d·616e·6420·6c69·6e65··nel·command·line
 00041f10:·2069·6e20·4752·5542·0a20·2020·2069·6620···in·GRUB.····if·
 00041f20:·6772·6570·202d·7120·275e·5c73·2a47·5255··grep·-q·'^\s*GRU
00041fd0:·6f20·226b·6172·6773·203d·205b·5c22·696f··o·"kargs·=·[\"io 
00041fe0:·6d6d·753d·2465·7870·6563·7465·645f·7661··mmu=$expected_va 
00041ff0:·6c75·655c·225d·2220·2667·743b·2667·743b··lue\"]"·&gt;&gt; 
00042000:·2022·244b·4152·4753·5f44·4952·2f31·302d···"$KARGS_DIR/10- 
00042010:·696f·6d6d·752e·746f·6d6c·220a·2020·2020··iommu.toml".···· 
00042020:·6669·0a65·6c73·650a·0a0a·2020·2020·2320··fi.else...····#· 
00042030:·436f·7272·6563·7420·7468·6520·666f·726d··Correct·the·form 
00042040:·206f·6620·6465·6661·756c·7420·6b65·726e···of·default·kern 
Max diff block lines reached; 141618/159172 bytes (88.97%) of diff not shown.
11.1 KB
html2text {}
    
Offset 411, 17 lines modifiedOffset 411, 14 lines modified
411 enabling·IOMMU·can·cause·hardware·instabilities.·Proper·function·and·stability411 enabling·IOMMU·can·cause·hardware·instabilities.·Proper·function·and·stability
412 should·be·assessed·before·applying·remediation·to·production·systems.412 should·be·assessed·before·applying·remediation·to·production·systems.
413 Rationale:··On·x86·architectures,·activating·the·I/OMMU·prevents·the·system413 Rationale:··On·x86·architectures,·activating·the·I/OMMU·prevents·the·system
414 ············from·arbitrary·accesses·potentially·made·by·hardware·devices.414 ············from·arbitrary·accesses·potentially·made·by·hardware·devices.
415 Severity: ··unknown415 Severity: ··unknown
416 Rule·ID:····xccdf_org.ssgproject.content_rule_grub2_enable_iommu_force416 Rule·ID:····xccdf_org.ssgproject.content_rule_grub2_enable_iommu_force
417 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R7417 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R7
418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
419 [customizations.kernel] 
420 append·=·"iommu=force" 
421 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
422 #·Remediation·is·applicable·only·in·certain·platforms419 #·Remediation·is·applicable·only·in·certain·platforms
423 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/420 if·(·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'grub2-common'·2>/
424 dev/null·|·grep·-q·'^installed'·&&·dpkg-query·--show·--showformat='${db:421 dev/null·|·grep·-q·'^installed'·&&·dpkg-query·--show·--showformat='${db:
425 Status-Status}422 Status-Status}
426 '·'linux-base'·2>/dev/null·|·grep·-q·^installed·);·then423 '·'linux-base'·2>/dev/null·|·grep·-q·^installed·);·then
  
Offset 458, 14 lines modifiedOffset 455, 17 lines modified
458 ····update-grub455 ····update-grub
  
459 fi456 fi
  
460 else457 else
461 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'458 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
462 fi459 fi
 460 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 461 [customizations.kernel]
 462 append·=·"iommu=force"
463 Group  ·Configure·Syslog·  Group·contains·2·groups·and·4·rules463 Group  ·Configure·Syslog·  Group·contains·2·groups·and·4·rules
464 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·syslog·service·has·been·the·default·Unix·logging·mechanism·for·many464 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·syslog·service·has·been·the·default·Unix·logging·mechanism·for·many
465 years.·It·has·a·number·of·downsides,·including·inconsistent·log·format,·lack·of465 years.·It·has·a·number·of·downsides,·including·inconsistent·log·format,·lack·of
466 authentication·for·received·messages,·and·lack·of·authentication,·encryption,466 authentication·for·received·messages,·and·lack·of·authentication,·encryption,
467 or·reliable·transport·for·messages·sent·over·a·network.·However,·due·to·its467 or·reliable·transport·for·messages·sent·over·a·network.·However,·due·to·its
468 long·history,·syslog·is·a·de·facto·standard·which·is·supported·by·almost·all468 long·history,·syslog·is·a·de·facto·standard·which·is·supported·by·almost·all
469 Unix·applications.469 Unix·applications.
Offset 3690, 19 lines modifiedOffset 3690, 14 lines modified
3690 ···························SR·2.7,·SR·7.63690 ···························SR·2.7,·SR·7.6
3691 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3691 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3692 ···························A.14.2.4,·A.9.1.23692 ···························A.14.2.4,·A.9.1.2
3693 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3693 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3694 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33694 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3695 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002273695 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
3696 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.23696 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
3697 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3698 [[packages]] 
3699 name·=·"cron" 
3700 version·=·"*" 
3701 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83697 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3702 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3698 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3703 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3699 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3704 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3700 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3705 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3701 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3706 #·Remediation·is·applicable·only·in·certain·platforms3702 #·Remediation·is·applicable·only·in·certain·platforms
3707 if·dpkg-query·--show·--showformat='${db:Status-Status}3703 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 3743, 14 lines modifiedOffset 3738, 19 lines modified
3743 ··-·PCI-DSSv4-2.2.63738 ··-·PCI-DSSv4-2.2.6
3744 ··-·enable_strategy3739 ··-·enable_strategy
3745 ··-·low_complexity3740 ··-·low_complexity
3746 ··-·low_disruption3741 ··-·low_disruption
3747 ··-·medium_severity3742 ··-·medium_severity
3748 ··-·no_reboot_needed3743 ··-·no_reboot_needed
3749 ··-·package_cron_installed3744 ··-·package_cron_installed
 3745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3746 [[packages]]
 3747 name·=·"cron"
 3748 version·=·"*"
3750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3751 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3750 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3752 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3751 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3753 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3752 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3754 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3753 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3755 include·install_cron3754 include·install_cron
  
Offset 4135, 19 lines modifiedOffset 4135, 14 lines modified
4135 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,4135 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
4136 References:················4.4.2.44136 References:················4.4.2.4
4137 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94137 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4138 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14138 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4139 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)4139 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
4140 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14140 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4141 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44141 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4143 [[packages]] 
4144 name·=·"ntp" 
4145 version·=·"*" 
4146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4151 #·Remediation·is·applicable·only·in·certain·platforms4147 #·Remediation·is·applicable·only·in·certain·platforms
4152 if·dpkg-query·--show·--showformat='${db:Status-Status}4148 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 4186, 14 lines modifiedOffset 4181, 19 lines modified
4186 ··-·PCI-DSS-Req-10.44181 ··-·PCI-DSS-Req-10.4
4187 ··-·enable_strategy4182 ··-·enable_strategy
4188 ··-·high_severity4183 ··-·high_severity
4189 ··-·low_complexity4184 ··-·low_complexity
4190 ··-·low_disruption4185 ··-·low_disruption
4191 ··-·no_reboot_needed4186 ··-·no_reboot_needed
4192 ··-·package_ntp_installed4187 ··-·package_ntp_installed
 4188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4189 [[packages]]
 4190 name·=·"ntp"
 4191 version·=·"*"
4193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4198 include·install_ntp4197 include·install_ntp
  
Offset 4225, 18 lines modifiedOffset 4225, 14 lines modified
4225 ···························4.4.2.44225 ···························4.4.2.4
4226 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94226 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4227 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14227 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4228 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)4228 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)
4229 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14229 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4230 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44230 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4231 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.64231 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.6
4232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4233 [customizations.services] 
4234 enabled·=·["ntp"] 
Max diff block lines reached; 5694/11335 bytes (50.23%) of diff not shown.
147 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-anssi_np_nt28_restrictive.html
    
Offset 28276, 144 lines modifiedOffset 28276, 144 lines modified
0006e730:·2d74·6172·6765·743d·2223·6964·6d31·3130··-target="#idm1100006e730:·2d74·6172·6765·743d·2223·6964·6d31·3130··-target="#idm110
0006e740:·3932·2220·7461·6269·6e64·6578·3d22·3022··92"·tabindex="0"0006e740:·3932·2220·7461·6269·6e64·6578·3d22·3022··92"·tabindex="0"
0006e750:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0006e750:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0006e760:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0006e760:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0006e770:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0006e770:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0006e780:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0006e780:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0006e790:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0006e790:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0006e7a0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0006e7b0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0006e7c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0006e7d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0006e7e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0006e7f0:·6964·3d22·6964·6d31·3130·3932·223e·3c70··id="idm11092"><p 
0006e800:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
0006e810:·6167·6573·5d5d·0a6e·616d·6520·3d20·2263··ages]].name·=·"c 
0006e820:·726f·6e22·0a76·6572·7369·6f6e·203d·2022··ron".version·=·" 
0006e830:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
0006e840:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0006e850:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0006e860:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0006e870:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0006e880:·6765·743d·2223·6964·6d31·3130·3933·2220··get="#idm11093"· 
0006e890:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0006e8a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0006e8b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0006e8c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0006e8d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0006e8e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0006e8f0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.0006e7a0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
0006e900:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0006e910:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0006e920:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0006e930:·643d·2269·646d·3131·3039·3322·3e3c·7461··d="idm11093"><ta 
0006e940:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0006e950:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0006e960:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0006e970:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0006e980:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0006e990:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0006e9a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0006e9b0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0006e9c0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0006e9d0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0006e9e0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0006e9f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0006ea00:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0006ea10:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0006ea20:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0006ea30:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0006ea40:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0006ea50:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0006ea60:·2070·6c61·7466·6f72·6d73·0a69·6620·6470···platforms.if·dp 
0006ea70:·6b67·2d71·7565·7279·202d·2d73·686f·7720··kg-query·--show· 
0006ea80:·2d2d·7368·6f77·666f·726d·6174·3d27·247b··--showformat='${ 
0006ea90:·6462·3a53·7461·7475·732d·5374·6174·7573··db:Status-Status 
0006eaa0:·7d0a·2720·276c·696e·7578·2d62·6173·6527··}.'·'linux-base' 
0006eab0:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null· 
0006eac0:·7c20·6772·6570·202d·7120·5e69·6e73·7461··|·grep·-q·^insta 
0006ead0:·6c6c·6564·3b20·7468·656e·0a0a·4445·4249··lled;·then..DEBI 
0006eae0:·414e·5f46·524f·4e54·454e·443d·6e6f·6e69··AN_FRONTEND=noni 
0006eaf0:·6e74·6572·6163·7469·7665·2061·7074·2d67··nteractive·apt-g 
0006eb00:·6574·2069·6e73·7461·6c6c·202d·7920·2263··et·install·-y·"c 
0006eb10:·726f·6e22·0a0a·656c·7365·0a20·2020·2026··ron"..else.····& 
0006eb20:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0006eb30:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0006eb40:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0006eb50:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0006eb60:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0006eb70:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0006eb80:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0006eb90:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0006eba0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0006ebb0:·7267·6574·3d22·2369·646d·3131·3039·3422··rget="#idm11094" 
0006ebc0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0006ebd0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0006ebe0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0006ebf0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0006ec00:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0006ec10:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0006ec20:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0006ec30:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0006e7b0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0006ec40:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0006e7c0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0006ec50:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0006e7d0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0006ec60:·6522·2069·643d·2269·646d·3131·3039·3422··e"·id="idm11094"0006e7e0:·6522·2069·643d·2269·646d·3131·3039·3222··e"·id="idm11092"
0006ec70:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0006e7f0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0006ec80:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0006e800:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0006ec90:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0006e810:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0006eca0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0006e820:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0006ecb0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0006e830:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0006ecc0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0006e840:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0006ecd0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0006e850:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0006ece0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0006e860:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0006ecf0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0006e870:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0006ed00:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0006e880:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0006ed10:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0006e890:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0006ed20:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0006e8a0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0006ed30:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0006e8b0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0006ed40:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0006e8c0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0006ed50:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0006e8d0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0006ed60:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name:0006e8e0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 0006e8f0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 0006e900:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 0006e910:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 0006e920:·6620·6470·6b67·2d71·7565·7279·202d·2d73··f·dpkg-query·--s
 0006e930:·686f·7720·2d2d·7368·6f77·666f·726d·6174··how·--showformat
 0006e940:·3d27·247b·6462·3a53·7461·7475·732d·5374··='${db:Status-St
 0006e950:·6174·7573·7d0a·2720·276c·696e·7578·2d62··atus}.'·'linux-b
 0006e960:·6173·6527·2032·2667·743b·2f64·6576·2f6e··ase'·2&gt;/dev/n
 0006e970:·756c·6c20·7c20·6772·6570·202d·7120·5e69··ull·|·grep·-q·^i
 0006e980:·6e73·7461·6c6c·6564·3b20·7468·656e·0a0a··nstalled;·then..
 0006e990:·4445·4249·414e·5f46·524f·4e54·454e·443d··DEBIAN_FRONTEND=
 0006e9a0:·6e6f·6e69·6e74·6572·6163·7469·7665·2061··noninteractive·a
 0006e9b0:·7074·2d67·6574·2069·6e73·7461·6c6c·202d··pt-get·install·-
 0006e9c0:·7920·2263·726f·6e22·0a0a·656c·7365·0a20··y·"cron"..else.·
 0006e9d0:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0006e9e0:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0006e9f0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 0006ea00:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 0006ea10:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
 0006ea20:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0006ea30:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0006ea40:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0006ea50:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0006ea60:·612d·7461·7267·6574·3d22·2369·646d·3131··a-target="#idm11
 0006ea70:·3039·3322·2074·6162·696e·6465·783d·2230··093"·tabindex="0
 0006ea80:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0006ea90:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
Max diff block lines reached; 122684/141204 bytes (86.88%) of diff not shown.
9.37 KB
html2text {}
    
Offset 3612, 19 lines modifiedOffset 3612, 14 lines modified
3612 ···························SR·2.7,·SR·7.63612 ···························SR·2.7,·SR·7.6
3613 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3613 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3614 ···························A.14.2.4,·A.9.1.23614 ···························A.14.2.4,·A.9.1.2
3615 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3615 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3616 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33616 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3617 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002273617 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
3618 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.23618 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
3619 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3620 [[packages]] 
3621 name·=·"cron" 
3622 version·=·"*" 
3623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83619 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3624 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3620 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3625 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3621 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3626 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3622 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3627 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3623 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3628 #·Remediation·is·applicable·only·in·certain·platforms3624 #·Remediation·is·applicable·only·in·certain·platforms
3629 if·dpkg-query·--show·--showformat='${db:Status-Status}3625 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 3665, 14 lines modifiedOffset 3660, 19 lines modified
3665 ··-·PCI-DSSv4-2.2.63660 ··-·PCI-DSSv4-2.2.6
3666 ··-·enable_strategy3661 ··-·enable_strategy
3667 ··-·low_complexity3662 ··-·low_complexity
3668 ··-·low_disruption3663 ··-·low_disruption
3669 ··-·medium_severity3664 ··-·medium_severity
3670 ··-·no_reboot_needed3665 ··-·no_reboot_needed
3671 ··-·package_cron_installed3666 ··-·package_cron_installed
 3667 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3668 [[packages]]
 3669 name·=·"cron"
 3670 version·=·"*"
3672 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83671 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3673 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3672 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3674 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3673 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3675 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3674 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3676 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3675 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3677 include·install_cron3676 include·install_cron
  
Offset 4057, 19 lines modifiedOffset 4057, 14 lines modified
4057 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,4057 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
4058 References:················4.4.2.44058 References:················4.4.2.4
4059 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94059 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4060 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14060 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4061 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)4061 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
4062 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14062 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4063 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44063 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4064 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4065 [[packages]] 
4066 name·=·"ntp" 
4067 version·=·"*" 
4068 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84064 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4069 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4065 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4070 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4066 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4071 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4067 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4072 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4068 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4073 #·Remediation·is·applicable·only·in·certain·platforms4069 #·Remediation·is·applicable·only·in·certain·platforms
4074 if·dpkg-query·--show·--showformat='${db:Status-Status}4070 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 4108, 14 lines modifiedOffset 4103, 19 lines modified
4108 ··-·PCI-DSS-Req-10.44103 ··-·PCI-DSS-Req-10.4
4109 ··-·enable_strategy4104 ··-·enable_strategy
4110 ··-·high_severity4105 ··-·high_severity
4111 ··-·low_complexity4106 ··-·low_complexity
4112 ··-·low_disruption4107 ··-·low_disruption
4113 ··-·no_reboot_needed4108 ··-·no_reboot_needed
4114 ··-·package_ntp_installed4109 ··-·package_ntp_installed
 4110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4111 [[packages]]
 4112 name·=·"ntp"
 4113 version·=·"*"
4115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4120 include·install_ntp4119 include·install_ntp
  
Offset 4147, 18 lines modifiedOffset 4147, 14 lines modified
4147 ···························4.4.2.44147 ···························4.4.2.4
4148 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94148 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4149 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14149 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4150 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)4150 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)
4151 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14151 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4152 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44152 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4153 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.64153 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.6
4154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4155 [customizations.services] 
4156 enabled·=·["ntp"] 
4157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4162 #·Remediation·is·applicable·only·in·certain·platforms4159 #·Remediation·is·applicable·only·in·certain·platforms
4163 if·dpkg-query·--show·--showformat='${db:Status-Status}4160 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 4223, 14 lines modifiedOffset 4219, 18 lines modified
4223 ··-·PCI-DSSv4-10.6.14219 ··-·PCI-DSSv4-10.6.1
4224 ··-·enable_strategy4220 ··-·enable_strategy
4225 ··-·high_severity4221 ··-·high_severity
4226 ··-·low_complexity4222 ··-·low_complexity
4227 ··-·low_disruption4223 ··-·low_disruption
4228 ··-·no_reboot_needed4224 ··-·no_reboot_needed
4229 ··-·service_ntp_enabled4225 ··-·service_ntp_enabled
 4226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4227 [customizations.services]
 4228 enabled·=·["ntp"]
4230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4231 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4232 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4233 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4234 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4235 include·enable_ntp4234 include·enable_ntp
  
Offset 4260, 18 lines modifiedOffset 4260, 14 lines modified
4260 ···························4.4.2.44260 ···························4.4.2.4
4261 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94261 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4262 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14262 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4263 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)4263 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-8(1)(a)
4264 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14264 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4265 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.44265 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.4
4266 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.64266 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.6.1,·10.6
4267 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 4103/9574 bytes (42.86%) of diff not shown.
30.5 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-cis.html
    
Offset 52981, 220 lines modifiedOffset 52981, 220 lines modified
000cef40:·6574·3d22·2369·646d·3135·3139·3822·2074··et="#idm15198"·t000cef40:·6574·3d22·2369·646d·3135·3139·3822·2074··et="#idm15198"·t
000cef50:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role000cef50:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
000cef60:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e000cef60:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
000cef70:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·000cef70:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
000cef80:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·000cef80:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
000cef90:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=000cef90:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
000cefa0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation000cefa0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
000cefb0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
000cefc0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
000cefd0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
000cefe0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
000ceff0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
000cf000:·646d·3135·3139·3822·3e3c·7072·653e·3c63··dm15198"><pre><c 
000cf010:·6f64·653e·0a5b·6375·7374·6f6d·697a·6174··ode>.[customizat 
000cf020:·696f·6e73·2e73·6572·7669·6365·735d·0a65··ions.services].e 
000cf030:·6e61·626c·6564·203d·205b·2261·7564·6974··nabled·=·["audit 
000cf040:·6422·5d0a·3c2f·636f·6465·3e3c·2f70·7265··d"].</code></pre 
000cf050:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
000cf060:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
000cf070:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
000cf080:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
000cf090:·7267·6574·3d22·2369·646d·3135·3139·3922··rget="#idm15199" 
000cf0a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
000cf0b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
000cf0c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
000cf0d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
000cf0e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
000cf0f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
000cf100:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·000cefb0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
000cf110:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·000cefc0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
000cf120:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col000cefd0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
000cf130:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·000cefe0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
000cf140:·6964·3d22·6964·6d31·3531·3939·223e·3c74··id="idm15199"><t000ceff0:·3d22·6964·6d31·3531·3938·223e·3c74·6162··="idm15198"><tab
000cf150:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl000cf000:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
000cf160:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·000cf010:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
000cf170:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t000cf020:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
000cf180:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">000cf030:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
000cf190:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi000cf040:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
000cf1a0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<000cf050:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
000cf1b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
000cf1c0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
000cf1d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
000cf1e0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
000cf1f0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
000cf200:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th000cf060:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 000cf070:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 000cf080:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000cf090:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 000cf0a0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 000cf0b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
000cf210:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><000cf0c0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
000cf220:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></000cf0d0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
000cf230:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>000cf0e0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
000cf240:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat000cf0f0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
000cf250:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl000cf100:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
000cf260:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai000cf110:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
000cf270:·6e20·706c·6174·666f·726d·730a·6966·2064··n·platforms.if·d000cf120:·706c·6174·666f·726d·730a·6966·2064·706b··platforms.if·dpk
000cf280:·706b·672d·7175·6572·7920·2d2d·7368·6f77··pkg-query·--show000cf130:·672d·7175·6572·7920·2d2d·7368·6f77·202d··g-query·--show·-
000cf290:·202d·2d73·686f·7766·6f72·6d61·743d·2724···--showformat='$000cf140:·2d73·686f·7766·6f72·6d61·743d·2724·7b64··-showformat='${d
000cf2a0:·7b64·623a·5374·6174·7573·2d53·7461·7475··{db:Status-Statu000cf150:·623a·5374·6174·7573·2d53·7461·7475·737d··b:Status-Status}
000cf2b0:·737d·0a27·2027·6c69·6e75·782d·6261·7365··s}.'·'linux-base000cf160:·0a27·2027·6c69·6e75·782d·6261·7365·2720··.'·'linux-base'·
000cf2c0:·2720·3226·6774·3b2f·6465·762f·6e75·6c6c··'·2&gt;/dev/null000cf170:·3226·6774·3b2f·6465·762f·6e75·6c6c·207c··2&gt;/dev/null·|
000cf2d0:·207c·2067·7265·7020·2d71·205e·696e·7374···|·grep·-q·^inst000cf180:·2067·7265·7020·2d71·205e·696e·7374·616c···grep·-q·^instal
000cf2e0:·616c·6c65·6420·2661·6d70·3b26·616d·703b··alled·&amp;&amp;000cf190:·6c65·6420·2661·6d70·3b26·616d·703b·207b··led·&amp;&amp;·{
000cf2f0:·207b·2064·706b·672d·7175·6572·7920·2d2d···{·dpkg-query·--000cf1a0:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh
000cf300:·7368·6f77·202d·2d73·686f·7766·6f72·6d61··show·--showforma000cf1b0:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat=
000cf310:·743d·2724·7b64·623a·5374·6174·7573·2d53··t='${db:Status-S000cf1c0:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta
000cf320:·7461·7475·737d·5c6e·2720·2761·7564·6974··tatus}\n'·'audit000cf1d0:·7475·737d·5c6e·2720·2761·7564·6974·6427··tus}\n'·'auditd'
000cf330:·6427·2032·2667·743b·2f64·6576·2f6e·756c··d'·2&gt;/dev/nul000cf1e0:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null·
000cf340:·6c20·7c20·6772·6570·202d·7120·275e·696e··l·|·grep·-q·'^in000cf1f0:·7c20·6772·6570·202d·7120·275e·696e·7374··|·grep·-q·'^inst
000cf350:·7374·616c·6c65·6427·3b20·7d3b·2074·6865··stalled';·};·the000cf200:·616c·6c65·6427·3b20·7d3b·2074·6865·6e0a··alled';·};·then.
000cf360:·6e0a·0a53·5953·5445·4d43·544c·5f45·5845··n..SYSTEMCTL_EXE000cf210:·0a53·5953·5445·4d43·544c·5f45·5845·433d··.SYSTEMCTL_EXEC=
000cf370:·433d·272f·7573·722f·6269·6e2f·7379·7374··C='/usr/bin/syst000cf220:·272f·7573·722f·6269·6e2f·7379·7374·656d··'/usr/bin/system
000cf380:·656d·6374·6c27·0a22·2453·5953·5445·4d43··emctl'."$SYSTEMC000cf230:·6374·6c27·0a22·2453·5953·5445·4d43·544c··ctl'."$SYSTEMCTL
000cf390:·544c·5f45·5845·4322·2075·6e6d·6173·6b20··TL_EXEC"·unmask·000cf240:·5f45·5845·4322·2075·6e6d·6173·6b20·2761··_EXEC"·unmask·'a
000cf3a0:·2761·7564·6974·642e·7365·7276·6963·6527··'auditd.service' 
000cf3b0:·0a69·6620·5b5b·2024·2822·2453·5953·5445··.if·[[·$("$SYSTE 
000cf3c0:·4d43·544c·5f45·5845·4322·2069·732d·7379··MCTL_EXEC"·is-sy 
000cf3d0:·7374·656d·2d72·756e·6e69·6e67·2920·213d··stem-running)·!= 
000cf3e0:·2022·6f66·666c·696e·6522·205d·5d3b·2074···"offline"·]];·t 
000cf3f0:·6865·6e0a·2020·2224·5359·5354·454d·4354··hen.··"$SYSTEMCT 
000cf400:·4c5f·4558·4543·2220·7374·6172·7420·2761··L_EXEC"·start·'a 
000cf410:·7564·6974·642e·7365·7276·6963·6527·0a66··uditd.service'.f000cf250:·7564·6974·642e·7365·7276·6963·6527·0a69··uditd.service'.i
 000cf260:·6620·5b5b·2024·2822·2453·5953·5445·4d43··f·[[·$("$SYSTEMC
 000cf270:·544c·5f45·5845·4322·2069·732d·7379·7374··TL_EXEC"·is-syst
 000cf280:·656d·2d72·756e·6e69·6e67·2920·213d·2022··em-running)·!=·"
 000cf290:·6f66·666c·696e·6522·205d·5d3b·2074·6865··offline"·]];·the
 000cf2a0:·6e0a·2020·2224·5359·5354·454d·4354·4c5f··n.··"$SYSTEMCTL_
 000cf2b0:·4558·4543·2220·7374·6172·7420·2761·7564··EXEC"·start·'aud
 000cf2c0:·6974·642e·7365·7276·6963·6527·0a66·690a··itd.service'.fi.
000cf420:·690a·2224·5359·5354·454d·4354·4c5f·4558··i."$SYSTEMCTL_EX000cf2d0:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC
000cf430:·4543·2220·656e·6162·6c65·2027·6175·6469··EC"·enable·'audi000cf2e0:·2220·656e·6162·6c65·2027·6175·6469·7464··"·enable·'auditd
000cf440:·7464·2e73·6572·7669·6365·270a·0a65·6c73··td.service'..els000cf2f0:·2e73·6572·7669·6365·270a·0a65·6c73·650a··.service'..else.
000cf450:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2000cf300:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
000cf460:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati000cf310:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
000cf470:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic000cf320:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
000cf480:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa000cf330:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
000cf490:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod000cf340:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
000cf4a0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a000cf350:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
000cf4b0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-000cf360:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
000cf4c0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to000cf370:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
000cf4d0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·000cf380:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
000cf4e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id000cf390:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
000cf4f0:·6d31·3532·3030·2220·7461·6269·6e64·6578··m15200"·tabindex000cf3a0:·3531·3939·2220·7461·6269·6e64·6578·3d22··5199"·tabindex="
000cf500:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto000cf3b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
000cf510:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded000cf3c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
000cf520:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="000cf3d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
000cf530:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve000cf3e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
000cf540:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re000cf3f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
000cf550:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl000cf400:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
000cf560:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a000cf410:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
000cf570:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=000cf420:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
000cf580:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·000cf430:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
000cf590:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id000cf440:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
000cf5a0:·6d31·3532·3030·223e·3c74·6162·6c65·2063··m15200"><table·c000cf450:·3531·3939·223e·3c74·6162·6c65·2063·6c61··5199"><table·cla
000cf5b0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl000cf460:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
000cf5c0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-000cf470:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
000cf5d0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c000cf480:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
000cf5e0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t000cf490:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
000cf5f0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t000cf4a0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
000cf600:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></000cf4b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
000cf610:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru000cf4c0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
000cf620:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l000cf4d0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
000cf630:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>000cf4e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
000cf640:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>000cf4f0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
000cf650:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></000cf500:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
000cf660:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat000cf510:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
Max diff block lines reached; 414/29422 bytes (1.41%) of diff not shown.
1.69 KB
html2text {}
    
Offset 10028, 18 lines modifiedOffset 10028, 14 lines modified
10028 ···························00139,·SRG-OS-000352-GPOS-00140,·SRG-OS-000353-GPOS-00141,·SRG-10028 ···························00139,·SRG-OS-000352-GPOS-00140,·SRG-OS-000353-GPOS-00141,·SRG-
10029 ···························OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,·SRG-OS-000365-10029 ···························OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,·SRG-OS-000365-
10030 ···························GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-0022010030 ···························GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-00220
10031 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000095-CTR-000170,·SRG-APP-000409-CTR-000990,·SRG-APP-10031 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000095-CTR-000170,·SRG-APP-000409-CTR-000990,·SRG-APP-
10032 ···························000508-CTR-001300,·SRG-APP-000510-CTR-00131010032 ···························000508-CTR-001300,·SRG-APP-000510-CTR-001310
10033 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R33,·R7310033 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R33,·R73
10034 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.2.1,·10.210034 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.2.1,·10.2
10035 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
10036 [customizations.services] 
10037 enabled·=·["auditd"] 
10038 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810035 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10039 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10036 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10040 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10037 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10041 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10038 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10042 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable10039 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
10043 #·Remediation·is·applicable·only·in·certain·platforms10040 #·Remediation·is·applicable·only·in·certain·platforms
10044 if·dpkg-query·--show·--showformat='${db:Status-Status}10041 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 10125, 14 lines modifiedOffset 10121, 18 lines modified
10125 ··-·PCI-DSSv4-10.2.110121 ··-·PCI-DSSv4-10.2.1
10126 ··-·enable_strategy10122 ··-·enable_strategy
10127 ··-·low_complexity10123 ··-·low_complexity
10128 ··-·low_disruption10124 ··-·low_disruption
10129 ··-·medium_severity10125 ··-·medium_severity
10130 ··-·no_reboot_needed10126 ··-·no_reboot_needed
10131 ··-·service_auditd_enabled10127 ··-·service_auditd_enabled
 10128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 10129 [customizations.services]
 10130 enabled·=·["auditd"]
10132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable10135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
10137 include·enable_auditd10136 include·enable_auditd
  
214 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu1804-guide-standard.html
    
Offset 19838, 140 lines modifiedOffset 19838, 140 lines modified
0004d7d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0004d7d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0004d7e0:·6d34·3935·3822·2074·6162·696e·6465·783d··m4958"·tabindex=0004d7e0:·6d34·3935·3822·2074·6162·696e·6465·783d··m4958"·tabindex=
0004d7f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0004d7f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0004d800:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0004d800:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0004d810:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0004d810:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0004d820:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0004d820:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0004d830:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0004d830:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0004d840:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild0004d840:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
0004d850:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0004d860:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0004d870:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0004d880:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0004d890:·6522·2069·643d·2269·646d·3439·3538·223e··e"·id="idm4958"> 
0004d8a0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0004d8b0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0004d8c0:·2272·7379·736c·6f67·220a·7665·7273·696f··"rsyslog".versio 
0004d8d0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
0004d8e0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0004d8f0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0004d900:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0004d910:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0004d920:·612d·7461·7267·6574·3d22·2369·646d·3439··a-target="#idm49 
0004d930:·3539·2220·7461·6269·6e64·6578·3d22·3022··59"·tabindex="0" 
0004d940:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0004d950:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0004d960:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0004d970:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0004d980:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0004d990:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0004d9a0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0004d9b0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0004d9c0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0004d9d0:·6522·2069·643d·2269·646d·3439·3539·223e··e"·id="idm4959"> 
0004d9e0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0004d9f0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0004da00:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0004da10:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0004da20:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0004da30:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0004da40:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0004da50:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0004da60:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0004da70:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0004da80:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0004da90:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0004daa0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0004dab0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0004dac0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0004dad0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0004dae0:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0004daf0:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0004db00:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0004db10:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh 
0004db20:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat= 
0004db30:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta 
0004db40:·7475·737d·0a27·2027·6c69·6e75·782d·6261··tus}.'·'linux-ba 
0004db50:·7365·2720·3226·6774·3b2f·6465·762f·6e75··se'·2&gt;/dev/nu 
0004db60:·6c6c·207c·2067·7265·7020·2d71·205e·696e··ll·|·grep·-q·^in 
0004db70:·7374·616c·6c65·643b·2074·6865·6e0a·0a44··stalled;·then..D 
0004db80:·4542·4941·4e5f·4652·4f4e·5445·4e44·3d6e··EBIAN_FRONTEND=n 
0004db90:·6f6e·696e·7465·7261·6374·6976·6520·6170··oninteractive·ap 
0004dba0:·742d·6765·7420·696e·7374·616c·6c20·2d79··t-get·install·-y 
0004dbb0:·2022·7273·7973·6c6f·6722·0a0a·656c·7365···"rsyslog"..else 
0004dbc0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0004dbd0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0004dbe0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0004dbf0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0004dc00:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0004dc10:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0004dc20:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0004dc30:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0004dc40:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0004dc50:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0004dc60:·3439·3630·2220·7461·6269·6e64·6578·3d22··4960"·tabindex=" 
0004dc70:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0004dc80:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0004dc90:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0004dca0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0004dcb0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0004dcc0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0004dcd0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0004d850:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
0004dce0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0004d860:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0004dcf0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0004d870:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0004dd00:·6c6c·6170·7365·2220·6964·3d22·6964·6d34··llapse"·id="idm40004d880:·6170·7365·2220·6964·3d22·6964·6d34·3935··apse"·id="idm495
0004dd10:·3936·3022·3e3c·7461·626c·6520·636c·6173··960"><table·clas0004d890:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=
0004dd20:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0004d8a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0004dd30:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0004d8b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0004dd40:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0004d8c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0004dd50:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0004d8d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0004dd60:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0004d8e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0004dd70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0004d8f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0004dd80:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0004d900:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0004dd90:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0004d910:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0004dda0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0004d920:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0004ddb0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0004d930:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0004ddc0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0004d940:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0004ddd0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0004d950:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0004dde0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0004d960:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0004ddf0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0004d970:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0004de00:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0004d980:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
0004de10:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
0004de20:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
0004de30:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
0004de40:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto 
0004de50:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS 
0004de60:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0004de70:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0004de80:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0004de90:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
0004dea0:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m 
0004deb0:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.· 
0004dec0:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
0004ded0:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_ 
0004dee0:·7273·7973·6c6f·675f·696e·7374·616c·6c65··rsyslog_installe 
0004def0:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur 
0004df00:·6520·7273·7973·6c6f·6720·6973·2069·6e73··e·rsyslog·is·ins 
0004df10:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package 
0004df20:·3a0a·2020·2020·6e61·6d65·3a20·7273·7973··:.····name:·rsys 
0004df30:·6c6f·670a·2020·2020·7374·6174·653a·2070··log.····state:·p 
0004df40:·7265·7365·6e74·0a20·2077·6865·6e3a·2027··resent.··when:·' 
0004df50:·226c·696e·7578·2d62·6173·6522·2069·6e20··"linux-base"·in· 
0004df60:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
0004df70:·636b·6167·6573·270a·2020·7461·6773·3a0a··ckages'.··tags:.0004d990:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0004d9a0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0004d9b0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0004d9c0:·0a69·6620·6470·6b67·2d71·7565·7279·202d··.if·dpkg-query·-
 0004d9d0:·2d73·686f·7720·2d2d·7368·6f77·666f·726d··-show·--showform
Max diff block lines reached; 186248/204216 bytes (91.20%) of diff not shown.
14.2 KB
html2text {}
    
Offset 1649, 19 lines modifiedOffset 1649, 14 lines modified
1649 References:················4.4.2.41649 References:················4.4.2.4
1650 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91650 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1651 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11651 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1652 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1652 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1653 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11653 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1654 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1654 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1655 ···························SRG-OS-000480-GPOS-002271655 ···························SRG-OS-000480-GPOS-00227
1656 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1657 [[packages]] 
1658 name·=·"rsyslog" 
1659 version·=·"*" 
1660 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81656 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1661 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1657 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1662 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1658 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1663 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1659 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1664 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1660 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1665 #·Remediation·is·applicable·only·in·certain·platforms1661 #·Remediation·is·applicable·only·in·certain·platforms
1666 if·dpkg-query·--show·--showformat='${db:Status-Status}1662 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1698, 14 lines modifiedOffset 1693, 19 lines modified
1698 ··-·NIST-800-53-CM-6(a)1693 ··-·NIST-800-53-CM-6(a)
1699 ··-·enable_strategy1694 ··-·enable_strategy
1700 ··-·low_complexity1695 ··-·low_complexity
1701 ··-·low_disruption1696 ··-·low_disruption
1702 ··-·medium_severity1697 ··-·medium_severity
1703 ··-·no_reboot_needed1698 ··-·no_reboot_needed
1704 ··-·package_rsyslog_installed1699 ··-·package_rsyslog_installed
 1700 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1701 [[packages]]
 1702 name·=·"rsyslog"
 1703 version·=·"*"
1705 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1706 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1705 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1707 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1706 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1708 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1707 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1709 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1708 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1710 include·install_rsyslog1709 include·install_rsyslog
  
Offset 1734, 18 lines modifiedOffset 1734, 14 lines modified
1734 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,1734 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
1735 ···························SR·6.2,·SR·7.1,·SR·7.21735 ···························SR·6.2,·SR·7.1,·SR·7.2
1736 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,1736 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
1737 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11737 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1738 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1738 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1739 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11739 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1740 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002271740 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
1741 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1742 [customizations.services] 
1743 enabled·=·["rsyslog"] 
1744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81741 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1745 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1742 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1746 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1743 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1747 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1744 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1748 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1745 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1749 #·Remediation·is·applicable·only·in·certain·platforms1746 #·Remediation·is·applicable·only·in·certain·platforms
1750 if·dpkg-query·--show·--showformat='${db:Status-Status}1747 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1800, 14 lines modifiedOffset 1796, 18 lines modified
1800 ··-·NIST-800-53-CM-6(a)1796 ··-·NIST-800-53-CM-6(a)
1801 ··-·enable_strategy1797 ··-·enable_strategy
1802 ··-·low_complexity1798 ··-·low_complexity
1803 ··-·low_disruption1799 ··-·low_disruption
1804 ··-·medium_severity1800 ··-·medium_severity
1805 ··-·no_reboot_needed1801 ··-·no_reboot_needed
1806 ··-·service_rsyslog_enabled1802 ··-·service_rsyslog_enabled
 1803 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1804 [customizations.services]
 1805 enabled·=·["rsyslog"]
1807 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81806 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1808 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1807 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1809 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1808 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1810 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1809 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1811 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1810 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1812 include·enable_rsyslog1811 include·enable_rsyslog
  
Offset 3598, 19 lines modifiedOffset 3598, 14 lines modified
3598 ···························SR·2.7,·SR·7.63598 ···························SR·2.7,·SR·7.6
3599 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3599 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3600 ···························A.14.2.4,·A.9.1.23600 ···························A.14.2.4,·A.9.1.2
3601 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3601 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3602 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33602 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3603 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002273603 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
3604 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.23604 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
3605 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3606 [[packages]] 
3607 name·=·"cron" 
3608 version·=·"*" 
3609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83605 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3606 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3607 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3608 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3609 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3614 #·Remediation·is·applicable·only·in·certain·platforms3610 #·Remediation·is·applicable·only·in·certain·platforms
3615 if·dpkg-query·--show·--showformat='${db:Status-Status}3611 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 3651, 14 lines modifiedOffset 3646, 19 lines modified
3651 ··-·PCI-DSSv4-2.2.63646 ··-·PCI-DSSv4-2.2.6
3652 ··-·enable_strategy3647 ··-·enable_strategy
3653 ··-·low_complexity3648 ··-·low_complexity
3654 ··-·low_disruption3649 ··-·low_disruption
3655 ··-·medium_severity3650 ··-·medium_severity
3656 ··-·no_reboot_needed3651 ··-·no_reboot_needed
3657 ··-·package_cron_installed3652 ··-·package_cron_installed
 3653 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3654 [[packages]]
 3655 name·=·"cron"
 3656 version·=·"*"
3658 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83657 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3659 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3658 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3660 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3659 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3661 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3660 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3662 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3661 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3663 include·install_cron3662 include·install_cron
  
Offset 3692, 18 lines modifiedOffset 3692, 14 lines modified
3692 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR3692 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR
3693 ···························1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,3693 ···························1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,
3694 ···························SR·2.7,·SR·7.63694 ···························SR·2.7,·SR·7.6
3695 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3695 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3696 ···························A.14.2.4,·A.9.1.23696 ···························A.14.2.4,·A.9.1.2
3697 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3697 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3698 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33698 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3699 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 8893/14524 bytes (61.23%) of diff not shown.
608 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_server.html
    
Offset 15095, 149 lines modifiedOffset 15095, 149 lines modified
0003af60:·6765·743d·2223·6964·6d32·3736·3322·2074··get="#idm2763"·t0003af60:·6765·743d·2223·6964·6d32·3736·3322·2074··get="#idm2763"·t
0003af70:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003af70:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003af80:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003af80:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003af90:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003af90:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003afa0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003afa0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003afb0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003afb0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003afc0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003afc0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003afd0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003afe0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003aff0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b000:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b010:·3d22·6964·6d32·3736·3322·3e3c·7461·626c··="idm2763"><tabl
 0003b020:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b030:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b040:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b050:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b060:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b070:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b080:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b090:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b0a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b0b0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b0c0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b0d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b0e0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003afd0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003afe0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003aff0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b000:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b010:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b020:·646d·3237·3633·223e·3c70·7265·3e3c·636f··dm2763"><pre><co 
0003b030:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003b040:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003b050:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003b060:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b070:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b080:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b090:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b0a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b0b0:·6964·6d32·3736·3422·2074·6162·696e·6465··idm2764"·tabinde 
0003b0c0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b0d0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b0e0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b0f0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b100:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b110:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b120:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b130:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b140:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b150:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
0003b160:·3736·3422·3e3c·7461·626c·6520·636c·6173··764"><table·clas 
0003b170:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b180:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b190:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b1a0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b1b0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b1c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b1d0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b1e0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b1f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b200:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b210:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b0f0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003b220:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b230:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b240:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b250:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b260:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b270:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b280:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b290:·6d73·0a69·6620·6470·6b67·2d71·7565·7279··ms.if·dpkg-query 
0003b2a0:·202d·2d73·686f·7720·2d2d·7368·6f77·666f···--show·--showfo 
0003b2b0:·726d·6174·3d27·247b·6462·3a53·7461·7475··rmat='${db:Statu 
0003b2c0:·732d·5374·6174·7573·7d0a·2720·276c·696e··s-Status}.'·'lin 
0003b2d0:·7578·2d62·6173·6527·2032·2667·743b·2f64··ux-base'·2&gt;/d 
0003b2e0:·6576·2f6e·756c·6c20·7c20·6772·6570·202d··ev/null·|·grep·- 
0003b2f0:·7120·5e69·6e73·7461·6c6c·6564·3b20·7468··q·^installed;·th 
0003b300:·656e·0a0a·4445·4249·414e·5f46·524f·4e54··en..DEBIAN_FRONT 
0003b310:·454e·443d·6e6f·6e69·6e74·6572·6163·7469··END=noninteracti 
0003b320:·7665·2061·7074·2d67·6574·2069·6e73·7461··ve·apt-get·insta 
0003b330:·6c6c·202d·7920·2261·6964·6522·0a0a·656c··ll·-y·"aide"..el 
0003b340:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003b350:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003b360:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003b370:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003b380:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003b390:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b3a0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b3b0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b3c0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b3d0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b3e0:·646d·3237·3635·2220·7461·6269·6e64·6578··dm2765"·tabindex 
0003b3f0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b400:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b410:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b420:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b430:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b440:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl 
0003b450:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a 
0003b460:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b470:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b480:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b490:·6d32·3736·3522·3e3c·7461·626c·6520·636c··m2765"><table·cl 
0003b4a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b4b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b4c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b4d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b4e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b4f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b500:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b510:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b520:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b530:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b100:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b110:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003b120:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003b130:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003b140:·6c61·7466·6f72·6d73·0a69·6620·6470·6b67··latforms.if·dpkg
 0003b150:·2d71·7565·7279·202d·2d73·686f·7720·2d2d··-query·--show·--
 0003b160:·7368·6f77·666f·726d·6174·3d27·247b·6462··showformat='${db
 0003b170:·3a53·7461·7475·732d·5374·6174·7573·7d0a··:Status-Status}.
 0003b180:·2720·276c·696e·7578·2d62·6173·6527·2032··'·'linux-base'·2
 0003b190:·2667·743b·2f64·6576·2f6e·756c·6c20·7c20··&gt;/dev/null·|·
 0003b1a0:·6772·6570·202d·7120·5e69·6e73·7461·6c6c··grep·-q·^install
 0003b1b0:·6564·3b20·7468·656e·0a0a·4445·4249·414e··ed;·then..DEBIAN
 0003b1c0:·5f46·524f·4e54·454e·443d·6e6f·6e69·6e74··_FRONTEND=nonint
 0003b1d0:·6572·6163·7469·7665·2061·7074·2d67·6574··eractive·apt-get
 0003b1e0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003b1f0:·6522·0a0a·656c·7365·0a20·2020·2026·6774··e"..else.····&gt
Max diff block lines reached; 560712/579922 bytes (96.69%) of diff not shown.
41.7 KB
html2text {}
    
Offset 121, 19 lines modifiedOffset 121, 14 lines modified
121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
123 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450123 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
124 ············_\x8c_\x8i_\x8s············1.4.1124 ············_\x8c_\x8i_\x8s············1.4.1
125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
127 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule127 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
129 [[packages]] 
130 name·=·"aide" 
131 version·=·"*" 
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
137 #·Remediation·is·applicable·only·in·certain·platforms133 #·Remediation·is·applicable·only·in·certain·platforms
138 if·dpkg-query·--show·--showformat='${db:Status-Status}134 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 178, 14 lines modifiedOffset 173, 19 lines modified
178 ··-·PCI-DSSv4-11.5.2173 ··-·PCI-DSSv4-11.5.2
179 ··-·enable_strategy174 ··-·enable_strategy
180 ··-·low_complexity175 ··-·low_complexity
181 ··-·low_disruption176 ··-·low_disruption
182 ··-·medium_severity177 ··-·medium_severity
183 ··-·no_reboot_needed178 ··-·no_reboot_needed
184 ··-·package_aide_installed179 ··-·package_aide_installed
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 181 [[packages]]
 182 name·=·"aide"
 183 version·=·"*"
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
190 include·install_aide189 include·install_aide
  
Offset 847, 19 lines modifiedOffset 847, 14 lines modified
847 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386847 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
848 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)848 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
849 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1849 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
850 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125850 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
851 ············_\x8c_\x8i_\x8s·····1.3.1851 ············_\x8c_\x8i_\x8s·····1.3.1
852 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33852 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
853 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2853 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
854 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
855 [[packages]] 
856 name·=·"sudo" 
857 version·=·"*" 
858 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8854 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
859 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low855 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
860 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low856 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
861 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false857 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
862 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable858 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
863 #·Remediation·is·applicable·only·in·certain·platforms859 #·Remediation·is·applicable·only·in·certain·platforms
864 if·dpkg-query·--show·--showformat='${db:Status-Status}860 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 900, 14 lines modifiedOffset 895, 19 lines modified
900 ··-·PCI-DSSv4-2.2.6895 ··-·PCI-DSSv4-2.2.6
901 ··-·enable_strategy896 ··-·enable_strategy
902 ··-·low_complexity897 ··-·low_complexity
903 ··-·low_disruption898 ··-·low_disruption
904 ··-·medium_severity899 ··-·medium_severity
905 ··-·no_reboot_needed900 ··-·no_reboot_needed
906 ··-·package_sudo_installed901 ··-·package_sudo_installed
 902 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 903 [[packages]]
 904 name·=·"sudo"
 905 version·=·"*"
907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low907 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low908 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false909 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable910 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
912 include·install_sudo911 include·install_sudo
  
Offset 3895, 19 lines modifiedOffset 3895, 14 lines modified
3895 Severity: ··medium3895 Severity: ··medium
3896 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed3896 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
3897 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003663897 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
3898 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002253898 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
3899 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0100573899 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010057
3900 ············_\x8c_\x8i_\x8s·····5.3.13900 ············_\x8c_\x8i_\x8s·····5.3.1
3901 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule3901 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule
3902 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3903 [[packages]] 
3904 name·=·"libpam-pwquality" 
3905 version·=·"*" 
3906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83902 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3907 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3903 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3908 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3904 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3909 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3905 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3910 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3906 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3911 #·Remediation·is·applicable·only·in·certain·platforms3907 #·Remediation·is·applicable·only·in·certain·platforms
3912 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-3908 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 3944, 14 lines modifiedOffset 3939, 19 lines modified
3944 ··-·DISA-STIG-UBTU-20-0100573939 ··-·DISA-STIG-UBTU-20-010057
3945 ··-·enable_strategy3940 ··-·enable_strategy
3946 ··-·low_complexity3941 ··-·low_complexity
3947 ··-·low_disruption3942 ··-·low_disruption
3948 ··-·medium_severity3943 ··-·medium_severity
3949 ··-·no_reboot_needed3944 ··-·no_reboot_needed
3950 ··-·package_pam_pwquality_installed3945 ··-·package_pam_pwquality_installed
 3946 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3947 [[packages]]
 3948 name·=·"libpam-pwquality"
 3949 version·=·"*"
3951 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3952 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3951 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3953 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3952 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3954 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3953 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3955 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3954 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3956 include·install_libpam-pwquality3955 include·install_libpam-pwquality
  
Offset 6274, 19 lines modifiedOffset 6274, 14 lines modified
6274 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022356274 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
6275 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,6275 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,
6276 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001556276 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
6277 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0104396277 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010439
6278 ············_\x8c_\x8i_\x8s·····1.7.1.16278 ············_\x8c_\x8i_\x8s·····1.7.1.1
6279 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R456279 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
6280 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238360r853435_rule6280 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238360r853435_rule
Max diff block lines reached; 37426/42637 bytes (87.78%) of diff not shown.
495 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level1_workstation.html
    
Offset 15090, 150 lines modifiedOffset 15090, 150 lines modified
0003af10:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003af10:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003af20:·3d22·2369·646d·3237·3633·2220·7461·6269··="#idm2763"·tabi0003af20:·3d22·2369·646d·3237·3633·2220·7461·6269··="#idm2763"·tabi
0003af30:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003af30:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003af40:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003af40:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003af50:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003af50:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003af60:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003af60:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003af70:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003af70:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003af80:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003af80:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003af90:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003afa0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003afb0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003afc0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003afd0:·646d·3237·3633·223e·3c74·6162·6c65·2063··dm2763"><table·c
 0003afe0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003aff0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b000:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b010:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b020:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b030:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b040:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b050:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b060:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b070:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b080:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b090:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b0a0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003af90:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003afa0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003afb0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003afc0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003afd0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
0003afe0:·3736·3322·3e3c·7072·653e·3c63·6f64·653e··763"><pre><code> 
0003aff0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003b000:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003b010:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003b020:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b030:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b040:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b050:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b060:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b070:·3237·3634·2220·7461·6269·6e64·6578·3d22··2764"·tabindex=" 
0003b080:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b090:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b0a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b0b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b0c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b0d0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b0e0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003b0f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b100:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b110:·7073·6522·2069·643d·2269·646d·3237·3634··pse"·id="idm2764 
0003b120:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b130:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b140:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b150:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b160:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b170:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003b180:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b190:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b1a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b1b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b1c0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003b1d0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b0b0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003b0c0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b0d0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003b0e0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003b0f0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003b100:·666f·726d·730a·6966·2064·706b·672d·7175··forms.if·dpkg-qu
 0003b110:·6572·7920·2d2d·7368·6f77·202d·2d73·686f··ery·--show·--sho
 0003b120:·7766·6f72·6d61·743d·2724·7b64·623a·5374··wformat='${db:St
 0003b130:·6174·7573·2d53·7461·7475·737d·0a27·2027··atus-Status}.'·'
 0003b140:·6c69·6e75·782d·6261·7365·2720·3226·6774··linux-base'·2&gt
 0003b150:·3b2f·6465·762f·6e75·6c6c·207c·2067·7265··;/dev/null·|·gre
 0003b160:·7020·2d71·205e·696e·7374·616c·6c65·643b··p·-q·^installed;
 0003b170:·2074·6865·6e0a·0a44·4542·4941·4e5f·4652···then..DEBIAN_FR
 0003b180:·4f4e·5445·4e44·3d6e·6f6e·696e·7465·7261··ONTEND=nonintera
 0003b190:·6374·6976·6520·6170·742d·6765·7420·696e··ctive·apt-get·in
 0003b1a0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003b1b0:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 0003b1c0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 0003b1d0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 0003b1e0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 0003b1f0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
 0003b200:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003b1e0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003b1f0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003b200:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b210:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003b220:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b230:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b240:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b250:·6966·2064·706b·672d·7175·6572·7920·2d2d··if·dpkg-query·-- 
0003b260:·7368·6f77·202d·2d73·686f·7766·6f72·6d61··show·--showforma 
0003b270:·743d·2724·7b64·623a·5374·6174·7573·2d53··t='${db:Status-S 
0003b280:·7461·7475·737d·0a27·2027·6c69·6e75·782d··tatus}.'·'linux- 
0003b290:·6261·7365·2720·3226·6774·3b2f·6465·762f··base'·2&gt;/dev/ 
0003b2a0:·6e75·6c6c·207c·2067·7265·7020·2d71·205e··null·|·grep·-q·^ 
0003b2b0:·696e·7374·616c·6c65·643b·2074·6865·6e0a··installed;·then. 
0003b2c0:·0a44·4542·4941·4e5f·4652·4f4e·5445·4e44··.DEBIAN_FRONTEND 
0003b2d0:·3d6e·6f6e·696e·7465·7261·6374·6976·6520··=noninteractive· 
0003b2e0:·6170·742d·6765·7420·696e·7374·616c·6c20··apt-get·install· 
0003b2f0:·2d79·2022·6169·6465·220a·0a65·6c73·650a··-y·"aide"..else. 
0003b300:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
0003b310:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
0003b320:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
0003b330:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
0003b340:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
0003b350:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003b360:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003b370:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003b380:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003b390:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2 
0003b3a0:·3736·3522·2074·6162·696e·6465·783d·2230··765"·tabindex="0 
0003b3b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003b3c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003b3d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003b3e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003b3f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003b400:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
0003b410:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b420:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003b210:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003b430:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b440:·6c61·7073·6522·2069·643d·2269·646d·3237··lapse"·id="idm27 
0003b450:·3635·223e·3c74·6162·6c65·2063·6c61·7373··65"><table·class 
0003b460:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b470:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b480:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
Max diff block lines reached; 452324/471672 bytes (95.90%) of diff not shown.
33.8 KB
html2text {}
    
Offset 120, 19 lines modifiedOffset 120, 14 lines modified
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450122 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
123 ············_\x8c_\x8i_\x8s············1.4.1123 ············_\x8c_\x8i_\x8s············1.4.1
124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
126 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule126 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
128 [[packages]] 
129 name·=·"aide" 
130 version·=·"*" 
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
136 #·Remediation·is·applicable·only·in·certain·platforms132 #·Remediation·is·applicable·only·in·certain·platforms
137 if·dpkg-query·--show·--showformat='${db:Status-Status}133 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 177, 14 lines modifiedOffset 172, 19 lines modified
177 ··-·PCI-DSSv4-11.5.2172 ··-·PCI-DSSv4-11.5.2
178 ··-·enable_strategy173 ··-·enable_strategy
179 ··-·low_complexity174 ··-·low_complexity
180 ··-·low_disruption175 ··-·low_disruption
181 ··-·medium_severity176 ··-·medium_severity
182 ··-·no_reboot_needed177 ··-·no_reboot_needed
183 ··-·package_aide_installed178 ··-·package_aide_installed
 179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 180 [[packages]]
 181 name·=·"aide"
 182 version·=·"*"
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
189 include·install_aide188 include·install_aide
  
Offset 960, 19 lines modifiedOffset 960, 14 lines modified
960 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386960 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
961 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)961 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
962 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1962 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
963 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125963 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
964 ············_\x8c_\x8i_\x8s·····1.3.1964 ············_\x8c_\x8i_\x8s·····1.3.1
965 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33965 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
966 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2966 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
967 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
968 [[packages]] 
969 name·=·"sudo" 
970 version·=·"*" 
971 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8967 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
972 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low968 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
973 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low969 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
974 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false970 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
975 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable971 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
976 #·Remediation·is·applicable·only·in·certain·platforms972 #·Remediation·is·applicable·only·in·certain·platforms
977 if·dpkg-query·--show·--showformat='${db:Status-Status}973 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1013, 14 lines modifiedOffset 1008, 19 lines modified
1013 ··-·PCI-DSSv4-2.2.61008 ··-·PCI-DSSv4-2.2.6
1014 ··-·enable_strategy1009 ··-·enable_strategy
1015 ··-·low_complexity1010 ··-·low_complexity
1016 ··-·low_disruption1011 ··-·low_disruption
1017 ··-·medium_severity1012 ··-·medium_severity
1018 ··-·no_reboot_needed1013 ··-·no_reboot_needed
1019 ··-·package_sudo_installed1014 ··-·package_sudo_installed
 1015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1016 [[packages]]
 1017 name·=·"sudo"
 1018 version·=·"*"
1020 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81019 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1021 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1020 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1022 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1021 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1023 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1022 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1024 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1023 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1025 include·install_sudo1024 include·install_sudo
  
Offset 4341, 19 lines modifiedOffset 4341, 14 lines modified
4341 Severity: ··medium4341 Severity: ··medium
4342 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed4342 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
4343 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003664343 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
4344 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002254344 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
4345 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0100574345 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010057
4346 ············_\x8c_\x8i_\x8s·····5.3.14346 ············_\x8c_\x8i_\x8s·····5.3.1
4347 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule4347 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule
4348 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4349 [[packages]] 
4350 name·=·"libpam-pwquality" 
4351 version·=·"*" 
4352 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84348 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4353 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4349 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4354 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4350 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4355 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4351 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4356 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4352 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4357 #·Remediation·is·applicable·only·in·certain·platforms4353 #·Remediation·is·applicable·only·in·certain·platforms
4358 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-4354 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 4390, 14 lines modifiedOffset 4385, 19 lines modified
4390 ··-·DISA-STIG-UBTU-20-0100574385 ··-·DISA-STIG-UBTU-20-010057
4391 ··-·enable_strategy4386 ··-·enable_strategy
4392 ··-·low_complexity4387 ··-·low_complexity
4393 ··-·low_disruption4388 ··-·low_disruption
4394 ··-·medium_severity4389 ··-·medium_severity
4395 ··-·no_reboot_needed4390 ··-·no_reboot_needed
4396 ··-·package_pam_pwquality_installed4391 ··-·package_pam_pwquality_installed
 4392 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4393 [[packages]]
 4394 name·=·"libpam-pwquality"
 4395 version·=·"*"
4397 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84396 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4398 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4397 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4399 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4398 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4400 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4399 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4401 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4400 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4402 include·install_libpam-pwquality4401 include·install_libpam-pwquality
  
Offset 6720, 19 lines modifiedOffset 6720, 14 lines modified
6720 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022356720 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
6721 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,6721 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,
6722 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001556722 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
6723 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0104396723 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010439
6724 ············_\x8c_\x8i_\x8s·····1.7.1.16724 ············_\x8c_\x8i_\x8s·····1.7.1.1
6725 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R456725 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
6726 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238360r853435_rule6726 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238360r853435_rule
Max diff block lines reached; 29339/34552 bytes (84.91%) of diff not shown.
703 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_server.html
    
Offset 15117, 150 lines modifiedOffset 15117, 150 lines modified
0003b0c0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b0c0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b0d0:·646d·3237·3633·2220·7461·6269·6e64·6578··dm2763"·tabindex0003b0d0:·646d·3237·3633·2220·7461·6269·6e64·6578··dm2763"·tabindex
0003b0e0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b0e0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b0f0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b0f0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b100:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b100:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b110:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b110:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b120:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b120:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b130:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b130:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003b140:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b150:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b160:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b170:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b180:·7365·2220·6964·3d22·6964·6d32·3736·3322··se"·id="idm2763"0003b140:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003b150:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b160:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b170:·6c61·7073·6522·2069·643d·2269·646d·3237··lapse"·id="idm27
 0003b180:·3633·223e·3c74·6162·6c65·2063·6c61·7373··63"><table·class
 0003b190:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b1a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b1b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b1c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b1d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b1e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b1f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b200:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b210:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b220:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b230:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b240:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b250:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b260:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b190:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p0003b270:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
0003b1a0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b1b0:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b1c0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003b1d0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b1e0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b1f0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b200:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b210:·7461·7267·6574·3d22·2369·646d·3237·3634··target="#idm2764 
0003b220:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b230:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b240:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b250:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b260:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b270:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b280:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b290:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b2a0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b2b0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b2c0:·2069·643d·2269·646d·3237·3634·223e·3c74···id="idm2764"><t 
0003b2d0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b2e0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b2f0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b300:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b310:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b320:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b330:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b340:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b350:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b360:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b370:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b380:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b390:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b280:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003b290:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003b2a0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003b2b0:·730a·6966·2064·706b·672d·7175·6572·7920··s.if·dpkg-query·
 0003b2c0:·2d2d·7368·6f77·202d·2d73·686f·7766·6f72··--show·--showfor
 0003b2d0:·6d61·743d·2724·7b64·623a·5374·6174·7573··mat='${db:Status
 0003b2e0:·2d53·7461·7475·737d·0a27·2027·6c69·6e75··-Status}.'·'linu
 0003b2f0:·782d·6261·7365·2720·3226·6774·3b2f·6465··x-base'·2&gt;/de
 0003b300:·762f·6e75·6c6c·207c·2067·7265·7020·2d71··v/null·|·grep·-q
 0003b310:·205e·696e·7374·616c·6c65·643b·2074·6865···^installed;·the
 0003b320:·6e0a·0a44·4542·4941·4e5f·4652·4f4e·5445··n..DEBIAN_FRONTE
 0003b330:·4e44·3d6e·6f6e·696e·7465·7261·6374·6976··ND=noninteractiv
 0003b340:·6520·6170·742d·6765·7420·696e·7374·616c··e·apt-get·instal
 0003b350:·6c20·2d79·2022·6169·6465·220a·0a65·6c73··l·-y·"aide"..els
 0003b360:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003b370:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003b380:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003b390:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003b3a0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 0003b3b0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b3c0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b3d0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b3e0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b3f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b400:·6d32·3736·3422·2074·6162·696e·6465·783d··m2764"·tabindex=
 0003b410:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b420:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b430:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b440:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b450:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b460:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
 0003b470:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b480:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b490:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b4a0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b4b0:·3237·3634·223e·3c74·6162·6c65·2063·6c61··2764"><table·cla
 0003b4c0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b4d0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b4e0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b4f0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b500:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b510:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b520:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b530:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b540:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b550:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003b3a0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b560:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b570:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b580:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003b3b0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b3c0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b3d0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b3e0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b3f0:·6e20·706c·6174·666f·726d·730a·6966·2064··n·platforms.if·d 
0003b400:·706b·672d·7175·6572·7920·2d2d·7368·6f77··pkg-query·--show 
0003b410:·202d·2d73·686f·7766·6f72·6d61·743d·2724···--showformat='$ 
0003b420:·7b64·623a·5374·6174·7573·2d53·7461·7475··{db:Status-Statu 
0003b430:·737d·0a27·2027·6c69·6e75·782d·6261·7365··s}.'·'linux-base 
0003b440:·2720·3226·6774·3b2f·6465·762f·6e75·6c6c··'·2&gt;/dev/null 
0003b450:·207c·2067·7265·7020·2d71·205e·696e·7374···|·grep·-q·^inst 
0003b460:·616c·6c65·643b·2074·6865·6e0a·0a44·4542··alled;·then..DEB 
0003b470:·4941·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e··IAN_FRONTEND=non 
0003b480:·696e·7465·7261·6374·6976·6520·6170·742d··interactive·apt- 
0003b490:·6765·7420·696e·7374·616c·6c20·2d79·2022··get·install·-y·" 
Max diff block lines reached; 650948/670296 bytes (97.11%) of diff not shown.
48.4 KB
html2text {}
    
Offset 124, 19 lines modifiedOffset 124, 14 lines modified
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
126 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450126 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
127 ············_\x8c_\x8i_\x8s············1.4.1127 ············_\x8c_\x8i_\x8s············1.4.1
128 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79128 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
129 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2129 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
130 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule130 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
132 [[packages]] 
133 name·=·"aide" 
134 version·=·"*" 
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
140 #·Remediation·is·applicable·only·in·certain·platforms136 #·Remediation·is·applicable·only·in·certain·platforms
141 if·dpkg-query·--show·--showformat='${db:Status-Status}137 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 181, 14 lines modifiedOffset 176, 19 lines modified
181 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
182 ··-·enable_strategy177 ··-·enable_strategy
183 ··-·low_complexity178 ··-·low_complexity
184 ··-·low_disruption179 ··-·low_disruption
185 ··-·medium_severity180 ··-·medium_severity
186 ··-·no_reboot_needed181 ··-·no_reboot_needed
187 ··-·package_aide_installed182 ··-·package_aide_installed
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 184 [[packages]]
 185 name·=·"aide"
 186 version·=·"*"
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
193 include·install_aide192 include·install_aide
  
Offset 952, 19 lines modifiedOffset 952, 14 lines modified
952 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386952 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
953 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)953 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
954 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1954 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
955 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125955 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
956 ············_\x8c_\x8i_\x8s·····1.3.1956 ············_\x8c_\x8i_\x8s·····1.3.1
957 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33957 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
958 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2958 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
959 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
960 [[packages]] 
961 name·=·"sudo" 
962 version·=·"*" 
963 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8959 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
964 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low960 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
965 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low961 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
966 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false962 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
967 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable963 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
968 #·Remediation·is·applicable·only·in·certain·platforms964 #·Remediation·is·applicable·only·in·certain·platforms
969 if·dpkg-query·--show·--showformat='${db:Status-Status}965 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1005, 14 lines modifiedOffset 1000, 19 lines modified
1005 ··-·PCI-DSSv4-2.2.61000 ··-·PCI-DSSv4-2.2.6
1006 ··-·enable_strategy1001 ··-·enable_strategy
1007 ··-·low_complexity1002 ··-·low_complexity
1008 ··-·low_disruption1003 ··-·low_disruption
1009 ··-·medium_severity1004 ··-·medium_severity
1010 ··-·no_reboot_needed1005 ··-·no_reboot_needed
1011 ··-·package_sudo_installed1006 ··-·package_sudo_installed
 1007 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1008 [[packages]]
 1009 name·=·"sudo"
 1010 version·=·"*"
1012 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81011 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1013 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1012 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1014 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1013 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1015 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1014 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1016 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1015 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1017 include·install_sudo1016 include·install_sudo
  
Offset 4000, 19 lines modifiedOffset 4000, 14 lines modified
4000 Severity: ··medium4000 Severity: ··medium
4001 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed4001 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
4002 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003664002 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
4003 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002254003 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
4004 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0100574004 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010057
4005 ············_\x8c_\x8i_\x8s·····5.3.14005 ············_\x8c_\x8i_\x8s·····5.3.1
4006 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule4006 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule
4007 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4008 [[packages]] 
4009 name·=·"libpam-pwquality" 
4010 version·=·"*" 
4011 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84007 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4012 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4008 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4013 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4009 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4014 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4010 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4015 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4011 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4016 #·Remediation·is·applicable·only·in·certain·platforms4012 #·Remediation·is·applicable·only·in·certain·platforms
4017 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-4013 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 4049, 14 lines modifiedOffset 4044, 19 lines modified
4049 ··-·DISA-STIG-UBTU-20-0100574044 ··-·DISA-STIG-UBTU-20-010057
4050 ··-·enable_strategy4045 ··-·enable_strategy
4051 ··-·low_complexity4046 ··-·low_complexity
4052 ··-·low_disruption4047 ··-·low_disruption
4053 ··-·medium_severity4048 ··-·medium_severity
4054 ··-·no_reboot_needed4049 ··-·no_reboot_needed
4055 ··-·package_pam_pwquality_installed4050 ··-·package_pam_pwquality_installed
 4051 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4052 [[packages]]
 4053 name·=·"libpam-pwquality"
 4054 version·=·"*"
4056 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84055 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4057 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4056 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4058 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4057 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4059 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4058 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4060 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4059 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4061 include·install_libpam-pwquality4060 include·install_libpam-pwquality
  
Offset 6379, 19 lines modifiedOffset 6379, 14 lines modified
6379 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022356379 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
6380 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,6380 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,
6381 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001556381 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
6382 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0104396382 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010439
6383 ············_\x8c_\x8i_\x8s·····1.7.1.16383 ············_\x8c_\x8i_\x8s·····1.7.1.1
6384 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R456384 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
6385 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238360r853435_rule6385 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238360r853435_rule
Max diff block lines reached; 44348/49561 bytes (89.48%) of diff not shown.
703 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-cis_level2_workstation.html
    
Offset 15113, 150 lines modifiedOffset 15113, 150 lines modified
0003b080:·612d·7461·7267·6574·3d22·2369·646d·3237··a-target="#idm270003b080:·612d·7461·7267·6574·3d22·2369·646d·3237··a-target="#idm27
0003b090:·3633·2220·7461·6269·6e64·6578·3d22·3022··63"·tabindex="0"0003b090:·3633·2220·7461·6269·6e64·6578·3d22·3022··63"·tabindex="0"
0003b0a0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b0a0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b0b0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b0b0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b0c0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b0c0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b0d0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b0d0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b0e0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b0e0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b0f0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003b100:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003b110:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b120:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b130:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b140:·6964·3d22·6964·6d32·3736·3322·3e3c·7072··id="idm2763"><pr 
0003b150:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003b160:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003b170:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003b180:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003b190:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b1a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b1b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b1c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b1d0:·6574·3d22·2369·646d·3237·3634·2220·7461··et="#idm2764"·ta 
0003b1e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b1f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b200:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b210:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b220:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b230:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b240:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b250:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b260:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b270:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b280:·2269·646d·3237·3634·223e·3c74·6162·6c65··"idm2764"><table 
0003b290:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b2a0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b2b0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b2c0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b2d0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b2e0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b2f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b300:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b310:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b320:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b330:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b340:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b350:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003b0f0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003b100:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003b110:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b120:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b130:·6522·2069·643d·2269·646d·3237·3633·223e··e"·id="idm2763">
 0003b140:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b150:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b160:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b170:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b180:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b190:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b1a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b1b0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b1c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b1d0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b1e0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b1f0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b200:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b210:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b220:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b230:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003b240:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003b250:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003b260:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003b270:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh
 0003b280:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat=
 0003b290:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta
 0003b2a0:·7475·737d·0a27·2027·6c69·6e75·782d·6261··tus}.'·'linux-ba
 0003b2b0:·7365·2720·3226·6774·3b2f·6465·762f·6e75··se'·2&gt;/dev/nu
 0003b2c0:·6c6c·207c·2067·7265·7020·2d71·205e·696e··ll·|·grep·-q·^in
 0003b2d0:·7374·616c·6c65·643b·2074·6865·6e0a·0a44··stalled;·then..D
 0003b2e0:·4542·4941·4e5f·4652·4f4e·5445·4e44·3d6e··EBIAN_FRONTEND=n
 0003b2f0:·6f6e·696e·7465·7261·6374·6976·6520·6170··oninteractive·ap
 0003b300:·742d·6765·7420·696e·7374·616c·6c20·2d79··t-get·install·-y
 0003b310:·2022·6169·6465·220a·0a65·6c73·650a·2020···"aide"..else.··
 0003b320:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003b330:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003b340:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003b350:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 0003b360:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 0003b370:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003b380:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003b390:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003b3a0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003b3b0:·2d74·6172·6765·743d·2223·6964·6d32·3736··-target="#idm276
 0003b3c0:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·
 0003b3d0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003b3e0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003b3f0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003b400:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003b410:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b420:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
 0003b430:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b440:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b450:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b460:·7073·6522·2069·643d·2269·646d·3237·3634··pse"·id="idm2764
 0003b470:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b480:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b490:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b4a0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b4b0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b4c0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b4d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b4e0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b4f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b500:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b510:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b360:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003b520:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b530:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b540:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b550:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b560:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
 0003b570:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac
 0003b580:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac
 0003b590:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.····
 0003b5a0:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.··
 0003b5b0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
 0003b5c0:·2e31·302e·312e·330a·2020·2d20·4449·5341··.10.1.3.··-·DISA
 0003b5d0:·2d53·5449·472d·5542·5455·2d32·302d·3031··-STIG-UBTU-20-01
 0003b5e0:·3034·3530·0a20·202d·204e·4953·542d·3830··0450.··-·NIST-80
 0003b5f0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
0003b370:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
Max diff block lines reached; 650398/669746 bytes (97.11%) of diff not shown.
48.4 KB
html2text {}
    
Offset 123, 19 lines modifiedOffset 123, 14 lines modified
123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450125 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
126 ············_\x8c_\x8i_\x8s············1.4.1126 ············_\x8c_\x8i_\x8s············1.4.1
127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule129 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
131 [[packages]] 
132 name·=·"aide" 
133 version·=·"*" 
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
139 #·Remediation·is·applicable·only·in·certain·platforms135 #·Remediation·is·applicable·only·in·certain·platforms
140 if·dpkg-query·--show·--showformat='${db:Status-Status}136 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 180, 14 lines modifiedOffset 175, 19 lines modified
180 ··-·PCI-DSSv4-11.5.2175 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy176 ··-·enable_strategy
182 ··-·low_complexity177 ··-·low_complexity
183 ··-·low_disruption178 ··-·low_disruption
184 ··-·medium_severity179 ··-·medium_severity
185 ··-·no_reboot_needed180 ··-·no_reboot_needed
186 ··-·package_aide_installed181 ··-·package_aide_installed
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide191 include·install_aide
  
Offset 1065, 19 lines modifiedOffset 1065, 14 lines modified
1065 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861065 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1066 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1066 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1067 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11067 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1068 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251068 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1069 ············_\x8c_\x8i_\x8s·····1.3.11069 ············_\x8c_\x8i_\x8s·····1.3.1
1070 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331070 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1071 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21071 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1072 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1073 [[packages]] 
1074 name·=·"sudo" 
1075 version·=·"*" 
1076 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81072 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1077 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1073 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1078 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1074 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1079 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1075 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1080 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1076 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1081 #·Remediation·is·applicable·only·in·certain·platforms1077 #·Remediation·is·applicable·only·in·certain·platforms
1082 if·dpkg-query·--show·--showformat='${db:Status-Status}1078 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1118, 14 lines modifiedOffset 1113, 19 lines modified
1118 ··-·PCI-DSSv4-2.2.61113 ··-·PCI-DSSv4-2.2.6
1119 ··-·enable_strategy1114 ··-·enable_strategy
1120 ··-·low_complexity1115 ··-·low_complexity
1121 ··-·low_disruption1116 ··-·low_disruption
1122 ··-·medium_severity1117 ··-·medium_severity
1123 ··-·no_reboot_needed1118 ··-·no_reboot_needed
1124 ··-·package_sudo_installed1119 ··-·package_sudo_installed
 1120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1121 [[packages]]
 1122 name·=·"sudo"
 1123 version·=·"*"
1125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1130 include·install_sudo1129 include·install_sudo
  
Offset 4446, 19 lines modifiedOffset 4446, 14 lines modified
4446 Severity: ··medium4446 Severity: ··medium
4447 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed4447 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
4448 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003664448 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
4449 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002254449 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
4450 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0100574450 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010057
4451 ············_\x8c_\x8i_\x8s·····5.3.14451 ············_\x8c_\x8i_\x8s·····5.3.1
4452 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule4452 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule
4453 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4454 [[packages]] 
4455 name·=·"libpam-pwquality" 
4456 version·=·"*" 
4457 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84453 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4458 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4454 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4459 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4455 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4460 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4456 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4461 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4457 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4462 #·Remediation·is·applicable·only·in·certain·platforms4458 #·Remediation·is·applicable·only·in·certain·platforms
4463 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-4459 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 4495, 14 lines modifiedOffset 4490, 19 lines modified
4495 ··-·DISA-STIG-UBTU-20-0100574490 ··-·DISA-STIG-UBTU-20-010057
4496 ··-·enable_strategy4491 ··-·enable_strategy
4497 ··-·low_complexity4492 ··-·low_complexity
4498 ··-·low_disruption4493 ··-·low_disruption
4499 ··-·medium_severity4494 ··-·medium_severity
4500 ··-·no_reboot_needed4495 ··-·no_reboot_needed
4501 ··-·package_pam_pwquality_installed4496 ··-·package_pam_pwquality_installed
 4497 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4498 [[packages]]
 4499 name·=·"libpam-pwquality"
 4500 version·=·"*"
4502 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84501 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4503 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4502 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4504 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4503 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4505 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4504 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4506 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4505 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4507 include·install_libpam-pwquality4506 include·install_libpam-pwquality
  
Offset 6825, 19 lines modifiedOffset 6825, 14 lines modified
6825 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022356825 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
6826 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,6826 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,
6827 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001556827 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
6828 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0104396828 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010439
6829 ············_\x8c_\x8i_\x8s·····1.7.1.16829 ············_\x8c_\x8i_\x8s·····1.7.1.1
6830 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R456830 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
6831 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238360r853435_rule6831 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238360r853435_rule
Max diff block lines reached; 44348/49563 bytes (89.48%) of diff not shown.
242 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-standard.html
    
Offset 20152, 140 lines modifiedOffset 20152, 140 lines modified
0004eb70:·6765·743d·2223·6964·6d31·3037·3636·2220··get="#idm10766"·0004eb70:·6765·743d·2223·6964·6d31·3037·3636·2220··get="#idm10766"·
0004eb80:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0004eb80:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0004eb90:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0004eb90:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0004eba0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0004eba0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0004ebb0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0004ebb0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0004ebc0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0004ebc0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0004ebd0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0004ebd0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0004ebe0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 0004ebf0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0004ec00:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0004ec10:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0004ebe0:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0004ebf0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
0004ec00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0004ec10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0004ec20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0004ec30:·6964·6d31·3037·3636·223e·3c70·7265·3e3c··idm10766"><pre>< 
0004ec40:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0004ec50:·5d5d·0a6e·616d·6520·3d20·2272·7379·736c··]].name·=·"rsysl 
0004ec60:·6f67·220a·7665·7273·696f·6e20·3d20·222a··og".version·=·"* 
0004ec70:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0004ec80:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0004ec90:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0004eca0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0004ecb0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0004ecc0:·6574·3d22·2369·646d·3130·3736·3722·2074··et="#idm10767"·t0004ec20:·643d·2269·646d·3130·3736·3622·3e3c·7461··d="idm10766"><ta
0004ecd0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0004ece0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0004ecf0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0004ed00:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0004ed10:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0004ec30:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0004ec40:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0004ec50:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0004ec60:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0004ec70:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0004ec80:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0004ec90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0004eca0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0004ecb0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0004ecc0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0004ecd0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0004ece0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0004ecf0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0004ed00:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0004ed10:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0004ed20:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0004ed30:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0004ed40:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0004ed50:·2070·6c61·7466·6f72·6d73·0a69·6620·6470···platforms.if·dp
 0004ed60:·6b67·2d71·7565·7279·202d·2d73·686f·7720··kg-query·--show·
 0004ed70:·2d2d·7368·6f77·666f·726d·6174·3d27·247b··--showformat='${
 0004ed80:·6462·3a53·7461·7475·732d·5374·6174·7573··db:Status-Status
 0004ed90:·7d0a·2720·276c·696e·7578·2d62·6173·6527··}.'·'linux-base'
 0004eda0:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null·
 0004edb0:·7c20·6772·6570·202d·7120·5e69·6e73·7461··|·grep·-q·^insta
 0004edc0:·6c6c·6564·3b20·7468·656e·0a0a·4445·4249··lled;·then..DEBI
 0004edd0:·414e·5f46·524f·4e54·454e·443d·6e6f·6e69··AN_FRONTEND=noni
 0004ede0:·6e74·6572·6163·7469·7665·2061·7074·2d67··nteractive·apt-g
 0004edf0:·6574·2069·6e73·7461·6c6c·202d·7920·2272··et·install·-y·"r
 0004ee00:·7379·736c·6f67·220a·0a65·6c73·650a·2020··syslog"..else.··
 0004ee10:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
0004ed20:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0004ee20:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
0004ed30:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0004ed40:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0004ed50:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0004ee30:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0004ee40:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 0004ee50:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 0004ee60:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0004ee70:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0004ee80:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0004ed60:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0004ee90:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0004ed70:·3d22·6964·6d31·3037·3637·223e·3c74·6162··="idm10767"><tab 
0004ed80:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0004ed90:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0004eda0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0004edb0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0004edc0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0004edd0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0004ede0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0004edf0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0004ee00:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0004ee10:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0004ee20:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0004ee30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0004ee40:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0004eea0:·2d74·6172·6765·743d·2223·6964·6d31·3037··-target="#idm107
 0004eeb0:·3637·2220·7461·6269·6e64·6578·3d22·3022··67"·tabindex="0"
 0004eec0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0004eed0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0004eee0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0004eef0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0004ef00:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0004ef10:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
 0004ef20:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0004ef30:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0004ef40:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0004ef50:·6170·7365·2220·6964·3d22·6964·6d31·3037··apse"·id="idm107
 0004ef60:·3637·223e·3c74·6162·6c65·2063·6c61·7373··67"><table·class
 0004ef70:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0004ef80:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0004ef90:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0004efa0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0004efb0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0004efc0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0004efd0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0004efe0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0004eff0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0004f000:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0004ee50:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0004f010:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0004ee60:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0004ee70:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0004ee80:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0004ee90:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0004eea0:·706c·6174·666f·726d·730a·6966·2064·706b··platforms.if·dpk 
0004eeb0:·672d·7175·6572·7920·2d2d·7368·6f77·202d··g-query·--show·- 
0004eec0:·2d73·686f·7766·6f72·6d61·743d·2724·7b64··-showformat='${d 
0004eed0:·623a·5374·6174·7573·2d53·7461·7475·737d··b:Status-Status} 
0004eee0:·0a27·2027·6c69·6e75·782d·6261·7365·2720··.'·'linux-base'· 
0004eef0:·3226·6774·3b2f·6465·762f·6e75·6c6c·207c··2&gt;/dev/null·| 
0004ef00:·2067·7265·7020·2d71·205e·696e·7374·616c···grep·-q·^instal 
0004ef10:·6c65·643b·2074·6865·6e0a·0a44·4542·4941··led;·then..DEBIA 
0004ef20:·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e·696e··N_FRONTEND=nonin 
0004ef30:·7465·7261·6374·6976·6520·6170·742d·6765··teractive·apt-ge 
0004ef40:·7420·696e·7374·616c·6c20·2d79·2022·7273··t·install·-y·"rs 
0004ef50:·7973·6c6f·6722·0a0a·656c·7365·0a20·2020··yslog"..else.··· 
0004ef60:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0004ef70:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0004ef80:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
Max diff block lines reached; 212744/230712 bytes (92.21%) of diff not shown.
16.2 KB
html2text {}
    
Offset 1657, 19 lines modifiedOffset 1657, 14 lines modified
1657 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91657 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1658 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11658 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1659 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1659 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1660 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11660 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1661 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1661 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1662 ···························SRG-OS-000480-GPOS-002271662 ···························SRG-OS-000480-GPOS-00227
1663 ············_\x8c_\x8i_\x8s············4.2.1.11663 ············_\x8c_\x8i_\x8s············4.2.1.1
1664 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1665 [[packages]] 
1666 name·=·"rsyslog" 
1667 version·=·"*" 
1668 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81664 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1669 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1665 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1670 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1666 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1671 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1667 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1672 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1668 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1673 #·Remediation·is·applicable·only·in·certain·platforms1669 #·Remediation·is·applicable·only·in·certain·platforms
1674 if·dpkg-query·--show·--showformat='${db:Status-Status}1670 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1706, 14 lines modifiedOffset 1701, 19 lines modified
1706 ··-·NIST-800-53-CM-6(a)1701 ··-·NIST-800-53-CM-6(a)
1707 ··-·enable_strategy1702 ··-·enable_strategy
1708 ··-·low_complexity1703 ··-·low_complexity
1709 ··-·low_disruption1704 ··-·low_disruption
1710 ··-·medium_severity1705 ··-·medium_severity
1711 ··-·no_reboot_needed1706 ··-·no_reboot_needed
1712 ··-·package_rsyslog_installed1707 ··-·package_rsyslog_installed
 1708 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1709 [[packages]]
 1710 name·=·"rsyslog"
 1711 version·=·"*"
1713 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1714 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1715 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1716 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1717 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1718 include·install_rsyslog1717 include·install_rsyslog
  
Offset 1745, 18 lines modifiedOffset 1745, 14 lines modified
1745 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11745 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1746 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1746 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1747 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11747 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1748 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002271748 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
1749 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-0104321749 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010432
1750 ············_\x8c_\x8i_\x8s············4.2.1.21750 ············_\x8c_\x8i_\x8s············4.2.1.2
1751 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238353r654234_rule1751 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238353r654234_rule
1752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1753 [customizations.services] 
1754 enabled·=·["rsyslog"] 
1755 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1756 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1757 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1754 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1758 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1755 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1759 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1756 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1760 #·Remediation·is·applicable·only·in·certain·platforms1757 #·Remediation·is·applicable·only·in·certain·platforms
1761 if·dpkg-query·--show·--showformat='${db:Status-Status}1758 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1813, 14 lines modifiedOffset 1809, 18 lines modified
1813 ··-·NIST-800-53-CM-6(a)1809 ··-·NIST-800-53-CM-6(a)
1814 ··-·enable_strategy1810 ··-·enable_strategy
1815 ··-·low_complexity1811 ··-·low_complexity
1816 ··-·low_disruption1812 ··-·low_disruption
1817 ··-·medium_severity1813 ··-·medium_severity
1818 ··-·no_reboot_needed1814 ··-·no_reboot_needed
1819 ··-·service_rsyslog_enabled1815 ··-·service_rsyslog_enabled
 1816 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1817 [customizations.services]
 1818 enabled·=·["rsyslog"]
1820 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81819 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1821 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1820 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1822 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1821 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1823 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1822 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1824 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1823 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1825 include·enable_rsyslog1824 include·enable_rsyslog
  
Offset 3603, 18 lines modifiedOffset 3603, 14 lines modified
3603 apport·service·can·be·disabled·with·the·following·command:3603 apport·service·can·be·disabled·with·the·following·command:
3604 $·sudo·systemctl·mask·--now·apport.service3604 $·sudo·systemctl·mask·--now·apport.service
3605 ···········The·Apport·service·modifies·the·kernel·fs.suid_dumpable·configuration3605 ···········The·Apport·service·modifies·the·kernel·fs.suid_dumpable·configuration
3606 Rationale:·at·runtime·which·prevents·other·hardening·from·being·persistent.3606 Rationale:·at·runtime·which·prevents·other·hardening·from·being·persistent.
3607 ···········Disabling·the·service·prevents·this·behavior.3607 ···········Disabling·the·service·prevents·this·behavior.
3608 Severity: ·unknown3608 Severity: ·unknown
3609 Rule·ID:···xccdf_org.ssgproject.content_rule_service_apport_disabled3609 Rule·ID:···xccdf_org.ssgproject.content_rule_service_apport_disabled
3610 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3611 [customizations.services] 
3612 masked·=·["apport"] 
3613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83610 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3611 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3612 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3613 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3614 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3618 #·Remediation·is·applicable·only·in·certain·platforms3615 #·Remediation·is·applicable·only·in·certain·platforms
3619 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|3616 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null·|
Offset 3637, 14 lines modifiedOffset 3633, 33 lines modified
3637 #·so·let's·reset·the·state·so·OVAL·checks·pass.3633 #·so·let's·reset·the·state·so·OVAL·checks·pass.
3638 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.3634 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
3639 "$SYSTEMCTL_EXEC"·reset-failed·'apport.service'·||·true3635 "$SYSTEMCTL_EXEC"·reset-failed·'apport.service'·||·true
  
3640 else3636 else
3641 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3637 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3642 fi3638 fi
 3639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3640 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3641 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 3642 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 3643 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
 3644 apiVersion:·machineconfiguration.openshift.io/v1
 3645 kind:·MachineConfig
 3646 spec:
 3647 ··config:
 3648 ····ignition:
 3649 ······version:·3.1.0
 3650 ····systemd:
 3651 ······units:
 3652 ······-·name:·apport.service
 3653 ········enabled:·false
 3654 ········mask:·true
 3655 ······-·name:·apport.socket
 3656 ········enabled:·false
 3657 ········mask:·true
3643 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83658 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3644 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3659 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3645 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3660 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3646 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3661 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 11258/16524 bytes (68.13%) of diff not shown.
422 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2004-guide-stig.html
    
Offset 15079, 150 lines modifiedOffset 15079, 150 lines modified
0003ae60:·7461·7267·6574·3d22·2369·646d·3237·3633··target="#idm27630003ae60:·7461·7267·6574·3d22·2369·646d·3237·3633··target="#idm2763
0003ae70:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003ae70:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003ae80:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003ae80:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003ae90:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003ae90:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003aea0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003aea0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003aeb0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003aeb0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003aec0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003aec0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003aed0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 0003aee0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003aef0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003af00:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003af10:·2069·643d·2269·646d·3237·3633·223e·3c74···id="idm2763"><t
 0003af20:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003af30:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003af40:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003af50:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003af60:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003af70:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003af80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003af90:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003afa0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003afb0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003afc0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003afd0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003afe0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003aed0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003aee0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003aef0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003af00:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003af10:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003af20:·3d22·6964·6d32·3736·3322·3e3c·7072·653e··="idm2763"><pre> 
0003af30:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003af40:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003af50:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003af60:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003af70:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003af80:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003af90:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003afa0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003afb0:·3d22·2369·646d·3237·3634·2220·7461·6269··="#idm2764"·tabi 
0003afc0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003afd0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003afe0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003aff0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b000:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b010:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003b020:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003b030:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b040:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b050:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b060:·646d·3237·3634·223e·3c74·6162·6c65·2063··dm2764"><table·c 
0003b070:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b080:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b090:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b0a0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b0b0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b0c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b0d0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b0e0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b0f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b100:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b110:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003aff0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003b000:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b010:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 0003b020:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 0003b030:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 0003b040:·6e20·706c·6174·666f·726d·730a·6966·2064··n·platforms.if·d
 0003b050:·706b·672d·7175·6572·7920·2d2d·7368·6f77··pkg-query·--show
 0003b060:·202d·2d73·686f·7766·6f72·6d61·743d·2724···--showformat='$
 0003b070:·7b64·623a·5374·6174·7573·2d53·7461·7475··{db:Status-Statu
 0003b080:·737d·0a27·2027·6c69·6e75·782d·6261·7365··s}.'·'linux-base
 0003b090:·2720·3226·6774·3b2f·6465·762f·6e75·6c6c··'·2&gt;/dev/null
 0003b0a0:·207c·2067·7265·7020·2d71·205e·696e·7374···|·grep·-q·^inst
 0003b0b0:·616c·6c65·643b·2074·6865·6e0a·0a44·4542··alled;·then..DEB
 0003b0c0:·4941·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e··IAN_FRONTEND=non
 0003b0d0:·696e·7465·7261·6374·6976·6520·6170·742d··interactive·apt-
 0003b0e0:·6765·7420·696e·7374·616c·6c20·2d79·2022··get·install·-y·"
 0003b0f0:·6169·6465·220a·0a65·6c73·650a·2020·2020··aide"..else.····
 0003b100:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
0003b120:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b130:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b140:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b150:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b160:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003b170:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003b180:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003b190:·666f·726d·730a·6966·2064·706b·672d·7175··forms.if·dpkg-qu 
0003b1a0:·6572·7920·2d2d·7368·6f77·202d·2d73·686f··ery·--show·--sho 
0003b1b0:·7766·6f72·6d61·743d·2724·7b64·623a·5374··wformat='${db:St 
0003b1c0:·6174·7573·2d53·7461·7475·737d·0a27·2027··atus-Status}.'·' 
0003b1d0:·6c69·6e75·782d·6261·7365·2720·3226·6774··linux-base'·2&gt 
0003b1e0:·3b2f·6465·762f·6e75·6c6c·207c·2067·7265··;/dev/null·|·gre 
0003b1f0:·7020·2d71·205e·696e·7374·616c·6c65·643b··p·-q·^installed; 
0003b200:·2074·6865·6e0a·0a44·4542·4941·4e5f·4652···then..DEBIAN_FR 
0003b210:·4f4e·5445·4e44·3d6e·6f6e·696e·7465·7261··ONTEND=nonintera 
0003b220:·6374·6976·6520·6170·742d·6765·7420·696e··ctive·apt-get·in 
0003b230:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003b240:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b250:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b260:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b270:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b280:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b290:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b2a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b2b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b2c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b2d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b2e0:·2223·6964·6d32·3736·3522·2074·6162·696e··"#idm2765"·tabin 
0003b2f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b300:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b310:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b320:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b330:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b340:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003b110:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
0003b350:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003b360:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b370:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b120:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003b130:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 0003b140:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
 0003b150:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003b160:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 0003b170:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 0003b180:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003b190:·6172·6765·743d·2223·6964·6d32·3736·3422··arget="#idm2764"
 0003b1a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003b1b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003b1c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
Max diff block lines reached; 381362/400710 bytes (95.17%) of diff not shown.
30.2 KB
html2text {}
    
Offset 115, 19 lines modifiedOffset 115, 14 lines modified
115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
117 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450117 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-20-010450
118 ············_\x8c_\x8i_\x8s············1.4.1118 ············_\x8c_\x8i_\x8s············1.4.1
119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
121 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule121 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-238371r880913_rule
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
123 [[packages]] 
124 name·=·"aide" 
125 version·=·"*" 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
131 #·Remediation·is·applicable·only·in·certain·platforms127 #·Remediation·is·applicable·only·in·certain·platforms
132 if·dpkg-query·--show·--showformat='${db:Status-Status}128 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 172, 14 lines modifiedOffset 167, 19 lines modified
172 ··-·PCI-DSSv4-11.5.2167 ··-·PCI-DSSv4-11.5.2
173 ··-·enable_strategy168 ··-·enable_strategy
174 ··-·low_complexity169 ··-·low_complexity
175 ··-·low_disruption170 ··-·low_disruption
176 ··-·medium_severity171 ··-·medium_severity
177 ··-·no_reboot_needed172 ··-·no_reboot_needed
178 ··-·package_aide_installed173 ··-·package_aide_installed
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 175 [[packages]]
 176 name·=·"aide"
 177 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
184 include·install_aide183 include·install_aide
  
Offset 5345, 19 lines modifiedOffset 5345, 14 lines modified
5345 Severity: ··medium5345 Severity: ··medium
5346 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed5346 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
5347 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003665347 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
5348 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002255348 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
5349 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0100575349 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010057
5350 ············_\x8c_\x8i_\x8s·····5.3.15350 ············_\x8c_\x8i_\x8s·····5.3.1
5351 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule5351 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238228r653859_rule
5352 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5353 [[packages]] 
5354 name·=·"libpam-pwquality" 
5355 version·=·"*" 
5356 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85352 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5357 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5353 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5358 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5354 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5359 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5355 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5360 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5356 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5361 #·Remediation·is·applicable·only·in·certain·platforms5357 #·Remediation·is·applicable·only·in·certain·platforms
5362 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-5358 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 5394, 14 lines modifiedOffset 5389, 19 lines modified
5394 ··-·DISA-STIG-UBTU-20-0100575389 ··-·DISA-STIG-UBTU-20-010057
5395 ··-·enable_strategy5390 ··-·enable_strategy
5396 ··-·low_complexity5391 ··-·low_complexity
5397 ··-·low_disruption5392 ··-·low_disruption
5398 ··-·medium_severity5393 ··-·medium_severity
5399 ··-·no_reboot_needed5394 ··-·no_reboot_needed
5400 ··-·package_pam_pwquality_installed5395 ··-·package_pam_pwquality_installed
 5396 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5397 [[packages]]
 5398 name·=·"libpam-pwquality"
 5399 version·=·"*"
5401 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85400 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5402 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5401 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5403 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5402 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5404 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5403 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5405 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5404 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5406 include·install_libpam-pwquality5405 include·install_libpam-pwquality
  
Offset 5794, 19 lines modifiedOffset 5794, 14 lines modified
5794 ············reauthenticates.·No·other·activity·aside·from·reauthentication·must·unlock·the·system.5794 ············reauthenticates.·No·other·activity·aside·from·reauthentication·must·unlock·the·system.
5795 Severity: ··medium5795 Severity: ··medium
5796 Rule·ID:····xccdf_org.ssgproject.content_rule_vlock_installed5796 Rule·ID:····xccdf_org.ssgproject.content_rule_vlock_installed
5797 ············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-0000605797 ············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-000060
5798 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-000115798 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-00011
5799 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0100055799 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010005
5800 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238200r653775_rule5800 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238200r653775_rule
5801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5802 [[packages]] 
5803 name·=·"vlock" 
5804 version·=·"*" 
5805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5806 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5802 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5807 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5803 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5808 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5804 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5809 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5805 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5810 #·Remediation·is·applicable·only·in·certain·platforms5806 #·Remediation·is·applicable·only·in·certain·platforms
5811 if·dpkg-query·--show·--showformat='${db:Status-Status}5807 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 5843, 14 lines modifiedOffset 5838, 19 lines modified
5843 ··-·DISA-STIG-UBTU-20-0100055838 ··-·DISA-STIG-UBTU-20-010005
5844 ··-·enable_strategy5839 ··-·enable_strategy
5845 ··-·low_complexity5840 ··-·low_complexity
5846 ··-·low_disruption5841 ··-·low_disruption
5847 ··-·medium_severity5842 ··-·medium_severity
5848 ··-·no_reboot_needed5843 ··-·no_reboot_needed
5849 ··-·vlock_installed5844 ··-·vlock_installed
 5845 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5846 [[packages]]
 5847 name·=·"vlock"
 5848 version·=·"*"
5850 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85849 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5851 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5850 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5852 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5851 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5853 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5852 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5854 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5853 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5855 include·install_vlock5854 include·install_vlock
  
Offset 5878, 19 lines modifiedOffset 5878, 14 lines modified
5878 Rule·ID:····xccdf_org.ssgproject.content_rule_package_opensc_installed5878 Rule·ID:····xccdf_org.ssgproject.content_rule_package_opensc_installed
5879 ············_\x8d_\x8i_\x8s_\x8a····CCI-001953,·CCI-0040465879 ············_\x8d_\x8i_\x8s_\x8a····CCI-001953,·CCI-004046
5880 ············_\x8i_\x8s_\x8m·····1382,·1384,·13865880 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
5881 References:·_\x8n_\x8i_\x8s_\x8t····CM-6(a)5881 References:·_\x8n_\x8i_\x8s_\x8t····CM-6(a)
5882 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-001615882 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161
5883 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-0100645883 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-20-010064
5884 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238231r853411_rule5884 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-238231r853411_rule
Max diff block lines reached; 25564/30875 bytes (82.80%) of diff not shown.
606 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_server.html
    
Offset 15122, 149 lines modifiedOffset 15122, 149 lines modified
0003b110:·6574·3d22·2369·646d·3239·3235·2220·7461··et="#idm2925"·ta0003b110:·6574·3d22·2369·646d·3239·3235·2220·7461··et="#idm2925"·ta
0003b120:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b120:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b130:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b130:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b140:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b140:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b150:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b150:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b160:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b160:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b170:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b170:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b180:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003b190:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b1a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b1b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b1c0:·2269·646d·3239·3235·223e·3c74·6162·6c65··"idm2925"><table
 0003b1d0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003b1e0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003b1f0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003b200:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b210:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003b220:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b230:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b240:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003b250:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b260:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003b270:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003b280:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003b290:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b180:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003b190:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003b1a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b1b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b1c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b1d0:·6d32·3932·3522·3e3c·7072·653e·3c63·6f64··m2925"><pre><cod 
0003b1e0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003b1f0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003b200:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003b210:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b220:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b230:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b240:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b250:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b260:·646d·3239·3236·2220·7461·6269·6e64·6578··dm2926"·tabindex 
0003b270:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b280:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b290:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b2a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b2b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b2c0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b2d0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b2e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b2f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b300:·6c61·7073·6522·2069·643d·2269·646d·3239··lapse"·id="idm29 
0003b310:·3236·223e·3c74·6162·6c65·2063·6c61·7373··26"><table·class 
0003b320:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b330:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b340:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b350:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b360:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b370:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b380:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b390:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b3a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b3b0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b3c0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b2a0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003b3d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b3e0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b3f0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b400:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
0003b410:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b420:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b430:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b440:·730a·6966·2064·706b·672d·7175·6572·7920··s.if·dpkg-query· 
0003b450:·2d2d·7368·6f77·202d·2d73·686f·7766·6f72··--show·--showfor 
0003b460:·6d61·743d·2724·7b64·623a·5374·6174·7573··mat='${db:Status 
0003b470:·2d53·7461·7475·737d·0a27·2027·6c69·6e75··-Status}.'·'linu 
0003b480:·782d·6261·7365·2720·3226·6774·3b2f·6465··x-base'·2&gt;/de 
0003b490:·762f·6e75·6c6c·207c·2067·7265·7020·2d71··v/null·|·grep·-q 
0003b4a0:·205e·696e·7374·616c·6c65·643b·2074·6865···^installed;·the 
0003b4b0:·6e0a·0a44·4542·4941·4e5f·4652·4f4e·5445··n..DEBIAN_FRONTE 
0003b4c0:·4e44·3d6e·6f6e·696e·7465·7261·6374·6976··ND=noninteractiv 
0003b4d0:·6520·6170·742d·6765·7420·696e·7374·616c··e·apt-get·instal 
0003b4e0:·6c20·2d79·2022·6169·6465·220a·0a65·6c73··l·-y·"aide"..els 
0003b4f0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b500:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b510:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b520:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b530:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b540:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b550:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b560:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b570:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b580:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b590:·6d32·3932·3722·2074·6162·696e·6465·783d··m2927"·tabindex= 
0003b5a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b5b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b5c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b5d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b5e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b5f0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b600:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b610:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b620:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b630:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b640:·3239·3237·223e·3c74·6162·6c65·2063·6c61··2927"><table·cla 
0003b650:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b660:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b670:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b680:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b690:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b6a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b6b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b6c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b6d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b6e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003b2b0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003b2c0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 0003b2d0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 0003b2e0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 0003b2f0:·6174·666f·726d·730a·6966·2064·706b·672d··atforms.if·dpkg-
 0003b300:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s
 0003b310:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db:
 0003b320:·5374·6174·7573·2d53·7461·7475·737d·0a27··Status-Status}.'
 0003b330:·2027·6c69·6e75·782d·6261·7365·2720·3226···'linux-base'·2&
 0003b340:·6774·3b2f·6465·762f·6e75·6c6c·207c·2067··gt;/dev/null·|·g
 0003b350:·7265·7020·2d71·205e·696e·7374·616c·6c65··rep·-q·^installe
 0003b360:·643b·2074·6865·6e0a·0a44·4542·4941·4e5f··d;·then..DEBIAN_
 0003b370:·4652·4f4e·5445·4e44·3d6e·6f6e·696e·7465··FRONTEND=noninte
 0003b380:·7261·6374·6976·6520·6170·742d·6765·7420··ractive·apt-get·
 0003b390:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003b3a0:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt;
Max diff block lines reached; 557820/577030 bytes (96.67%) of diff not shown.
41.9 KB
html2text {}
    
Offset 125, 19 lines modifiedOffset 125, 14 lines modified
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
127 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010127 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010
128 ············_\x8c_\x8i_\x8s············1.3.1128 ············_\x8c_\x8i_\x8s············1.3.1
129 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79129 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
130 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2130 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
131 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule131 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
133 [[packages]] 
134 name·=·"aide" 
135 version·=·"*" 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 #·Remediation·is·applicable·only·in·certain·platforms137 #·Remediation·is·applicable·only·in·certain·platforms
142 if·dpkg-query·--show·--showformat='${db:Status-Status}138 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 182, 14 lines modifiedOffset 177, 19 lines modified
182 ··-·PCI-DSSv4-11.5.2177 ··-·PCI-DSSv4-11.5.2
183 ··-·enable_strategy178 ··-·enable_strategy
184 ··-·low_complexity179 ··-·low_complexity
185 ··-·low_disruption180 ··-·low_disruption
186 ··-·medium_severity181 ··-·medium_severity
187 ··-·no_reboot_needed182 ··-·no_reboot_needed
188 ··-·package_aide_installed183 ··-·package_aide_installed
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 185 [[packages]]
 186 name·=·"aide"
 187 version·=·"*"
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
194 include·install_aide193 include·install_aide
  
Offset 1878, 19 lines modifiedOffset 1878, 14 lines modified
1878 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861878 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1879 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1879 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1880 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11880 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1881 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251881 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1882 ············_\x8c_\x8i_\x8s·····5.3.11882 ············_\x8c_\x8i_\x8s·····5.3.1
1883 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331883 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1884 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21884 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1885 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1886 [[packages]] 
1887 name·=·"sudo" 
1888 version·=·"*" 
1889 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81885 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1890 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1886 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1891 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1887 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1892 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1888 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1893 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1889 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1894 #·Remediation·is·applicable·only·in·certain·platforms1890 #·Remediation·is·applicable·only·in·certain·platforms
1895 if·dpkg-query·--show·--showformat='${db:Status-Status}1891 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1931, 14 lines modifiedOffset 1926, 19 lines modified
1931 ··-·PCI-DSSv4-2.2.61926 ··-·PCI-DSSv4-2.2.6
1932 ··-·enable_strategy1927 ··-·enable_strategy
1933 ··-·low_complexity1928 ··-·low_complexity
1934 ··-·low_disruption1929 ··-·low_disruption
1935 ··-·medium_severity1930 ··-·medium_severity
1936 ··-·no_reboot_needed1931 ··-·no_reboot_needed
1937 ··-·package_sudo_installed1932 ··-·package_sudo_installed
 1933 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1934 [[packages]]
 1935 name·=·"sudo"
 1936 version·=·"*"
1938 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81937 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1939 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1938 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1940 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1939 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1941 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1940 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1942 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1941 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1943 include·install_sudo1942 include·install_sudo
  
Offset 5422, 19 lines modifiedOffset 5422, 14 lines modified
5422 Severity: ··medium5422 Severity: ··medium
5423 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed5423 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
5424 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003665424 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
5425 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002255425 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
5426 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-2150105426 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-215010
5427 ············_\x8c_\x8i_\x8s·····5.4.15427 ············_\x8c_\x8i_\x8s·····5.4.1
5428 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule5428 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule
5429 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5430 [[packages]] 
5431 name·=·"libpam-pwquality" 
5432 version·=·"*" 
5433 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85429 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5434 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5430 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5435 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5431 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5436 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5432 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5437 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5433 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5438 #·Remediation·is·applicable·only·in·certain·platforms5434 #·Remediation·is·applicable·only·in·certain·platforms
5439 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-5435 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 5471, 14 lines modifiedOffset 5466, 19 lines modified
5471 ··-·DISA-STIG-UBTU-22-2150105466 ··-·DISA-STIG-UBTU-22-215010
5472 ··-·enable_strategy5467 ··-·enable_strategy
5473 ··-·low_complexity5468 ··-·low_complexity
5474 ··-·low_disruption5469 ··-·low_disruption
5475 ··-·medium_severity5470 ··-·medium_severity
5476 ··-·no_reboot_needed5471 ··-·no_reboot_needed
5477 ··-·package_pam_pwquality_installed5472 ··-·package_pam_pwquality_installed
 5473 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5474 [[packages]]
 5475 name·=·"libpam-pwquality"
 5476 version·=·"*"
5478 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85477 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5479 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5478 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5480 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5479 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5481 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5480 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5482 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5481 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5483 include·install_libpam-pwquality5482 include·install_libpam-pwquality
  
Offset 7722, 19 lines modifiedOffset 7722, 14 lines modified
7722 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022357722 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
7723 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,7723 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,
7724 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001557724 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
7725 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-4310107725 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-431010
7726 ············_\x8c_\x8i_\x8s·····1.6.1.17726 ············_\x8c_\x8i_\x8s·····1.6.1.1
7727 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R457727 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
7728 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260556r958702_rule7728 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260556r958702_rule
Max diff block lines reached; 37616/42831 bytes (87.82%) of diff not shown.
491 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level1_workstation.html
    
Offset 15112, 150 lines modifiedOffset 15112, 150 lines modified
0003b070:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b070:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b080:·646d·3239·3235·2220·7461·6269·6e64·6578··dm2925"·tabindex0003b080:·646d·3239·3235·2220·7461·6269·6e64·6578··dm2925"·tabindex
0003b090:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b090:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b0a0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b0a0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b0b0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b0b0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b0c0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b0c0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b0d0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b0d0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b0e0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b0e0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003b0f0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b100:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b110:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b120:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b130:·7365·2220·6964·3d22·6964·6d32·3932·3522··se"·id="idm2925"0003b0f0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003b100:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b110:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b120:·6c61·7073·6522·2069·643d·2269·646d·3239··lapse"·id="idm29
 0003b130:·3235·223e·3c74·6162·6c65·2063·6c61·7373··25"><table·class
 0003b140:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b150:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b160:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b170:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b180:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b190:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b1a0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b1b0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b1c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b1d0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b1e0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b1f0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b200:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b210:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b140:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p0003b220:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
0003b150:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b160:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b170:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003b180:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b190:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b1a0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b1b0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b1c0:·7461·7267·6574·3d22·2369·646d·3239·3236··target="#idm2926 
0003b1d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b1e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b1f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b200:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b210:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b220:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b230:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b240:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b250:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b260:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b270:·2069·643d·2269·646d·3239·3236·223e·3c74···id="idm2926"><t 
0003b280:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b290:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b2a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b2b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b2c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b2d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b2e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b2f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b300:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b310:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b320:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b330:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b340:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b230:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003b240:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003b250:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003b260:·730a·6966·2064·706b·672d·7175·6572·7920··s.if·dpkg-query·
 0003b270:·2d2d·7368·6f77·202d·2d73·686f·7766·6f72··--show·--showfor
 0003b280:·6d61·743d·2724·7b64·623a·5374·6174·7573··mat='${db:Status
 0003b290:·2d53·7461·7475·737d·0a27·2027·6c69·6e75··-Status}.'·'linu
 0003b2a0:·782d·6261·7365·2720·3226·6774·3b2f·6465··x-base'·2&gt;/de
 0003b2b0:·762f·6e75·6c6c·207c·2067·7265·7020·2d71··v/null·|·grep·-q
 0003b2c0:·205e·696e·7374·616c·6c65·643b·2074·6865···^installed;·the
 0003b2d0:·6e0a·0a44·4542·4941·4e5f·4652·4f4e·5445··n..DEBIAN_FRONTE
 0003b2e0:·4e44·3d6e·6f6e·696e·7465·7261·6374·6976··ND=noninteractiv
 0003b2f0:·6520·6170·742d·6765·7420·696e·7374·616c··e·apt-get·instal
 0003b300:·6c20·2d79·2022·6169·6465·220a·0a65·6c73··l·-y·"aide"..els
 0003b310:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003b320:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003b330:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003b340:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003b350:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 0003b360:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b370:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b380:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b390:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b3a0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b3b0:·6d32·3932·3622·2074·6162·696e·6465·783d··m2926"·tabindex=
 0003b3c0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b3d0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b3e0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b3f0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b400:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b410:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
 0003b420:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b430:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b440:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b450:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b460:·3239·3236·223e·3c74·6162·6c65·2063·6c61··2926"><table·cla
 0003b470:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b480:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b490:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b4a0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b4b0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b4c0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b4d0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b4e0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b4f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b500:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003b350:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b510:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b520:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b530:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003b360:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b370:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b380:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b390:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b3a0:·6e20·706c·6174·666f·726d·730a·6966·2064··n·platforms.if·d 
0003b3b0:·706b·672d·7175·6572·7920·2d2d·7368·6f77··pkg-query·--show 
0003b3c0:·202d·2d73·686f·7766·6f72·6d61·743d·2724···--showformat='$ 
0003b3d0:·7b64·623a·5374·6174·7573·2d53·7461·7475··{db:Status-Statu 
0003b3e0:·737d·0a27·2027·6c69·6e75·782d·6261·7365··s}.'·'linux-base 
0003b3f0:·2720·3226·6774·3b2f·6465·762f·6e75·6c6c··'·2&gt;/dev/null 
0003b400:·207c·2067·7265·7020·2d71·205e·696e·7374···|·grep·-q·^inst 
0003b410:·616c·6c65·643b·2074·6865·6e0a·0a44·4542··alled;·then..DEB 
0003b420:·4941·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e··IAN_FRONTEND=non 
0003b430:·696e·7465·7261·6374·6976·6520·6170·742d··interactive·apt- 
0003b440:·6765·7420·696e·7374·616c·6c20·2d79·2022··get·install·-y·" 
Max diff block lines reached; 449018/468366 bytes (95.87%) of diff not shown.
34.0 KB
html2text {}
    
Offset 123, 19 lines modifiedOffset 123, 14 lines modified
123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010125 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010
126 ············_\x8c_\x8i_\x8s············1.3.1126 ············_\x8c_\x8i_\x8s············1.3.1
127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule129 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
131 [[packages]] 
132 name·=·"aide" 
133 version·=·"*" 
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
139 #·Remediation·is·applicable·only·in·certain·platforms135 #·Remediation·is·applicable·only·in·certain·platforms
140 if·dpkg-query·--show·--showformat='${db:Status-Status}136 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 180, 14 lines modifiedOffset 175, 19 lines modified
180 ··-·PCI-DSSv4-11.5.2175 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy176 ··-·enable_strategy
182 ··-·low_complexity177 ··-·low_complexity
183 ··-·low_disruption178 ··-·low_disruption
184 ··-·medium_severity179 ··-·medium_severity
185 ··-·no_reboot_needed180 ··-·no_reboot_needed
186 ··-·package_aide_installed181 ··-·package_aide_installed
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide191 include·install_aide
  
Offset 1611, 19 lines modifiedOffset 1611, 14 lines modified
1611 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861611 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1612 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1612 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1613 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11613 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1614 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251614 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1615 ············_\x8c_\x8i_\x8s·····5.3.11615 ············_\x8c_\x8i_\x8s·····5.3.1
1616 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331616 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1617 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21617 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1618 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1619 [[packages]] 
1620 name·=·"sudo" 
1621 version·=·"*" 
1622 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81618 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1623 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1619 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1624 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1620 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1625 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1621 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1626 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1622 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1627 #·Remediation·is·applicable·only·in·certain·platforms1623 #·Remediation·is·applicable·only·in·certain·platforms
1628 if·dpkg-query·--show·--showformat='${db:Status-Status}1624 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1664, 14 lines modifiedOffset 1659, 19 lines modified
1664 ··-·PCI-DSSv4-2.2.61659 ··-·PCI-DSSv4-2.2.6
1665 ··-·enable_strategy1660 ··-·enable_strategy
1666 ··-·low_complexity1661 ··-·low_complexity
1667 ··-·low_disruption1662 ··-·low_disruption
1668 ··-·medium_severity1663 ··-·medium_severity
1669 ··-·no_reboot_needed1664 ··-·no_reboot_needed
1670 ··-·package_sudo_installed1665 ··-·package_sudo_installed
 1666 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1667 [[packages]]
 1668 name·=·"sudo"
 1669 version·=·"*"
1671 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81670 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1672 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1671 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1673 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1672 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1674 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1673 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1675 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1674 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1676 include·install_sudo1675 include·install_sudo
  
Offset 5155, 19 lines modifiedOffset 5155, 14 lines modified
5155 Severity: ··medium5155 Severity: ··medium
5156 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed5156 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
5157 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003665157 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
5158 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002255158 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
5159 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-2150105159 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-215010
5160 ············_\x8c_\x8i_\x8s·····5.4.15160 ············_\x8c_\x8i_\x8s·····5.4.1
5161 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule5161 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule
5162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5163 [[packages]] 
5164 name·=·"libpam-pwquality" 
5165 version·=·"*" 
5166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5171 #·Remediation·is·applicable·only·in·certain·platforms5167 #·Remediation·is·applicable·only·in·certain·platforms
5172 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-5168 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 5204, 14 lines modifiedOffset 5199, 19 lines modified
5204 ··-·DISA-STIG-UBTU-22-2150105199 ··-·DISA-STIG-UBTU-22-215010
5205 ··-·enable_strategy5200 ··-·enable_strategy
5206 ··-·low_complexity5201 ··-·low_complexity
5207 ··-·low_disruption5202 ··-·low_disruption
5208 ··-·medium_severity5203 ··-·medium_severity
5209 ··-·no_reboot_needed5204 ··-·no_reboot_needed
5210 ··-·package_pam_pwquality_installed5205 ··-·package_pam_pwquality_installed
 5206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5207 [[packages]]
 5208 name·=·"libpam-pwquality"
 5209 version·=·"*"
5211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5216 include·install_libpam-pwquality5215 include·install_libpam-pwquality
  
Offset 7455, 19 lines modifiedOffset 7455, 14 lines modified
7455 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022357455 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
7456 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,7456 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,
7457 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001557457 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
7458 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-4310107458 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-431010
7459 ············_\x8c_\x8i_\x8s·····1.6.1.17459 ············_\x8c_\x8i_\x8s·····1.6.1.1
7460 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R457460 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
7461 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260556r958702_rule7461 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260556r958702_rule
Max diff block lines reached; 29530/34745 bytes (84.99%) of diff not shown.
700 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_server.html
    
Offset 15129, 150 lines modifiedOffset 15129, 150 lines modified
0003b180:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b180:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b190:·646d·3239·3235·2220·7461·6269·6e64·6578··dm2925"·tabindex0003b190:·646d·3239·3235·2220·7461·6269·6e64·6578··dm2925"·tabindex
0003b1a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b1a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b1b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b1b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b1c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b1c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b1d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b1d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b1e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b1e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b1f0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b1f0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003b200:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b210:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b220:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b230:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b240:·7365·2220·6964·3d22·6964·6d32·3932·3522··se"·id="idm2925"0003b200:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003b210:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b220:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b230:·6c61·7073·6522·2069·643d·2269·646d·3239··lapse"·id="idm29
 0003b240:·3235·223e·3c74·6162·6c65·2063·6c61·7373··25"><table·class
 0003b250:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b260:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b270:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b280:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b290:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b2a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b2b0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b2c0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b2d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b2e0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b2f0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b300:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b310:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b320:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b250:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p0003b330:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
0003b260:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b270:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b280:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003b290:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b2a0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b2b0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b2c0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b2d0:·7461·7267·6574·3d22·2369·646d·3239·3236··target="#idm2926 
0003b2e0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b2f0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b300:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b310:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b320:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b330:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b340:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b350:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b360:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b370:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b380:·2069·643d·2269·646d·3239·3236·223e·3c74···id="idm2926"><t 
0003b390:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b3a0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b3b0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b3c0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b3d0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b3e0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b3f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b400:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b410:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b420:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b430:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b440:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b450:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b340:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003b350:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003b360:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003b370:·730a·6966·2064·706b·672d·7175·6572·7920··s.if·dpkg-query·
 0003b380:·2d2d·7368·6f77·202d·2d73·686f·7766·6f72··--show·--showfor
 0003b390:·6d61·743d·2724·7b64·623a·5374·6174·7573··mat='${db:Status
 0003b3a0:·2d53·7461·7475·737d·0a27·2027·6c69·6e75··-Status}.'·'linu
 0003b3b0:·782d·6261·7365·2720·3226·6774·3b2f·6465··x-base'·2&gt;/de
 0003b3c0:·762f·6e75·6c6c·207c·2067·7265·7020·2d71··v/null·|·grep·-q
 0003b3d0:·205e·696e·7374·616c·6c65·643b·2074·6865···^installed;·the
 0003b3e0:·6e0a·0a44·4542·4941·4e5f·4652·4f4e·5445··n..DEBIAN_FRONTE
 0003b3f0:·4e44·3d6e·6f6e·696e·7465·7261·6374·6976··ND=noninteractiv
 0003b400:·6520·6170·742d·6765·7420·696e·7374·616c··e·apt-get·instal
 0003b410:·6c20·2d79·2022·6169·6465·220a·0a65·6c73··l·-y·"aide"..els
 0003b420:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003b430:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003b440:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003b450:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003b460:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 0003b470:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b480:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b490:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b4a0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b4b0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b4c0:·6d32·3932·3622·2074·6162·696e·6465·783d··m2926"·tabindex=
 0003b4d0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b4e0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b4f0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b500:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b510:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b520:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
 0003b530:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 0003b540:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b550:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b560:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b570:·3239·3236·223e·3c74·6162·6c65·2063·6c61··2926"><table·cla
 0003b580:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b590:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b5a0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b5b0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b5c0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b5d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b5e0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b5f0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b600:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b610:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003b460:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b620:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b630:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b640:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003b470:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b480:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b490:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b4a0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b4b0:·6e20·706c·6174·666f·726d·730a·6966·2064··n·platforms.if·d 
0003b4c0:·706b·672d·7175·6572·7920·2d2d·7368·6f77··pkg-query·--show 
0003b4d0:·202d·2d73·686f·7766·6f72·6d61·743d·2724···--showformat='$ 
0003b4e0:·7b64·623a·5374·6174·7573·2d53·7461·7475··{db:Status-Statu 
0003b4f0:·737d·0a27·2027·6c69·6e75·782d·6261·7365··s}.'·'linux-base 
0003b500:·2720·3226·6774·3b2f·6465·762f·6e75·6c6c··'·2&gt;/dev/null 
0003b510:·207c·2067·7265·7020·2d71·205e·696e·7374···|·grep·-q·^inst 
0003b520:·616c·6c65·643b·2074·6865·6e0a·0a44·4542··alled;·then..DEB 
0003b530:·4941·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e··IAN_FRONTEND=non 
0003b540:·696e·7465·7261·6374·6976·6520·6170·742d··interactive·apt- 
0003b550:·6765·7420·696e·7374·616c·6c20·2d79·2022··get·install·-y·" 
Max diff block lines reached; 647364/666712 bytes (97.10%) of diff not shown.
48.6 KB
html2text {}
    
Offset 126, 19 lines modifiedOffset 126, 14 lines modified
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
127 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199127 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
128 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010128 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010
129 ············_\x8c_\x8i_\x8s············1.3.1129 ············_\x8c_\x8i_\x8s············1.3.1
130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
131 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2131 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
132 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule132 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
134 [[packages]] 
135 name·=·"aide" 
136 version·=·"*" 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 #·Remediation·is·applicable·only·in·certain·platforms138 #·Remediation·is·applicable·only·in·certain·platforms
143 if·dpkg-query·--show·--showformat='${db:Status-Status}139 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 183, 14 lines modifiedOffset 178, 19 lines modified
183 ··-·PCI-DSSv4-11.5.2178 ··-·PCI-DSSv4-11.5.2
184 ··-·enable_strategy179 ··-·enable_strategy
185 ··-·low_complexity180 ··-·low_complexity
186 ··-·low_disruption181 ··-·low_disruption
187 ··-·medium_severity182 ··-·medium_severity
188 ··-·no_reboot_needed183 ··-·no_reboot_needed
189 ··-·package_aide_installed184 ··-·package_aide_installed
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 186 [[packages]]
 187 name·=·"aide"
 188 version·=·"*"
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
195 include·install_aide194 include·install_aide
  
Offset 2062, 19 lines modifiedOffset 2062, 14 lines modified
2062 ············_\x8i_\x8s_\x8m·····1382,·1384,·13862062 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
2063 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)2063 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
2064 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.12064 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
2065 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001252065 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
2066 ············_\x8c_\x8i_\x8s·····5.3.12066 ············_\x8c_\x8i_\x8s·····5.3.1
2067 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R332067 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
2068 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.22068 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
2069 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2070 [[packages]] 
2071 name·=·"sudo" 
2072 version·=·"*" 
2073 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82069 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2074 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2070 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2075 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2071 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2076 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2072 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2077 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2073 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2078 #·Remediation·is·applicable·only·in·certain·platforms2074 #·Remediation·is·applicable·only·in·certain·platforms
2079 if·dpkg-query·--show·--showformat='${db:Status-Status}2075 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2115, 14 lines modifiedOffset 2110, 19 lines modified
2115 ··-·PCI-DSSv4-2.2.62110 ··-·PCI-DSSv4-2.2.6
2116 ··-·enable_strategy2111 ··-·enable_strategy
2117 ··-·low_complexity2112 ··-·low_complexity
2118 ··-·low_disruption2113 ··-·low_disruption
2119 ··-·medium_severity2114 ··-·medium_severity
2120 ··-·no_reboot_needed2115 ··-·no_reboot_needed
2121 ··-·package_sudo_installed2116 ··-·package_sudo_installed
 2117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2118 [[packages]]
 2119 name·=·"sudo"
 2120 version·=·"*"
2122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2127 include·install_sudo2126 include·install_sudo
  
Offset 5752, 19 lines modifiedOffset 5752, 14 lines modified
5752 Severity: ··medium5752 Severity: ··medium
5753 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed5753 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
5754 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003665754 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
5755 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002255755 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
5756 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-2150105756 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-215010
5757 ············_\x8c_\x8i_\x8s·····5.4.15757 ············_\x8c_\x8i_\x8s·····5.4.1
5758 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule5758 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule
5759 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5760 [[packages]] 
5761 name·=·"libpam-pwquality" 
5762 version·=·"*" 
5763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85759 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5764 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5760 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5765 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5761 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5766 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5762 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5767 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5763 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5768 #·Remediation·is·applicable·only·in·certain·platforms5764 #·Remediation·is·applicable·only·in·certain·platforms
5769 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-5765 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 5801, 14 lines modifiedOffset 5796, 19 lines modified
5801 ··-·DISA-STIG-UBTU-22-2150105796 ··-·DISA-STIG-UBTU-22-215010
5802 ··-·enable_strategy5797 ··-·enable_strategy
5803 ··-·low_complexity5798 ··-·low_complexity
5804 ··-·low_disruption5799 ··-·low_disruption
5805 ··-·medium_severity5800 ··-·medium_severity
5806 ··-·no_reboot_needed5801 ··-·no_reboot_needed
5807 ··-·package_pam_pwquality_installed5802 ··-·package_pam_pwquality_installed
 5803 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5804 [[packages]]
 5805 name·=·"libpam-pwquality"
 5806 version·=·"*"
5808 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85807 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5809 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5808 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5810 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5809 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5811 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5810 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5812 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5811 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5813 include·install_libpam-pwquality5812 include·install_libpam-pwquality
  
Offset 8052, 19 lines modifiedOffset 8052, 14 lines modified
8052 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022358052 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
8053 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,8053 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,
8054 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001558054 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
8055 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-4310108055 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-431010
8056 ············_\x8c_\x8i_\x8s·····1.6.1.18056 ············_\x8c_\x8i_\x8s·····1.6.1.1
8057 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R458057 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
8058 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260556r958702_rule8058 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260556r958702_rule
Max diff block lines reached; 44542/49757 bytes (89.52%) of diff not shown.
700 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-cis_level2_workstation.html
    
Offset 15125, 150 lines modifiedOffset 15125, 150 lines modified
0003b140:·612d·7461·7267·6574·3d22·2369·646d·3239··a-target="#idm290003b140:·612d·7461·7267·6574·3d22·2369·646d·3239··a-target="#idm29
0003b150:·3235·2220·7461·6269·6e64·6578·3d22·3022··25"·tabindex="0"0003b150:·3235·2220·7461·6269·6e64·6578·3d22·3022··25"·tabindex="0"
0003b160:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b160:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b170:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b170:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b180:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b180:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b190:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b190:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b1a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b1a0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b1b0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003b1c0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003b1d0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b1e0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b1f0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b200:·6964·3d22·6964·6d32·3932·3522·3e3c·7072··id="idm2925"><pr 
0003b210:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003b220:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003b230:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003b240:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003b250:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b260:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b270:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b280:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b290:·6574·3d22·2369·646d·3239·3236·2220·7461··et="#idm2926"·ta 
0003b2a0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b2b0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b2c0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b2d0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b2e0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b2f0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b300:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b310:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b320:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b330:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b340:·2269·646d·3239·3236·223e·3c74·6162·6c65··"idm2926"><table 
0003b350:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b360:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b370:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b380:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b390:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b3a0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b3b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b3c0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b3d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b3e0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b3f0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b400:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b410:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003b1b0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003b1c0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003b1d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b1e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b1f0:·6522·2069·643d·2269·646d·3239·3235·223e··e"·id="idm2925">
 0003b200:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b210:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b220:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b230:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b240:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b250:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b260:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b270:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b280:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b290:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b2a0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b2b0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b2c0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b2d0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b2e0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b2f0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003b300:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003b310:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003b320:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003b330:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh
 0003b340:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat=
 0003b350:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta
 0003b360:·7475·737d·0a27·2027·6c69·6e75·782d·6261··tus}.'·'linux-ba
 0003b370:·7365·2720·3226·6774·3b2f·6465·762f·6e75··se'·2&gt;/dev/nu
 0003b380:·6c6c·207c·2067·7265·7020·2d71·205e·696e··ll·|·grep·-q·^in
 0003b390:·7374·616c·6c65·643b·2074·6865·6e0a·0a44··stalled;·then..D
 0003b3a0:·4542·4941·4e5f·4652·4f4e·5445·4e44·3d6e··EBIAN_FRONTEND=n
 0003b3b0:·6f6e·696e·7465·7261·6374·6976·6520·6170··oninteractive·ap
 0003b3c0:·742d·6765·7420·696e·7374·616c·6c20·2d79··t-get·install·-y
 0003b3d0:·2022·6169·6465·220a·0a65·6c73·650a·2020···"aide"..else.··
 0003b3e0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003b3f0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003b400:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003b410:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 0003b420:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 0003b430:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003b440:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003b450:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003b460:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003b470:·2d74·6172·6765·743d·2223·6964·6d32·3932··-target="#idm292
 0003b480:·3622·2074·6162·696e·6465·783d·2230·2220··6"·tabindex="0"·
 0003b490:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003b4a0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003b4b0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003b4c0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003b4d0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b4e0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
 0003b4f0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b500:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b510:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b520:·7073·6522·2069·643d·2269·646d·3239·3236··pse"·id="idm2926
 0003b530:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b540:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b550:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b560:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b570:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b580:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b590:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b5a0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b5b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b5c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b5d0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b420:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003b5e0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b5f0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b600:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b610:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b620:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
 0003b630:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac
 0003b640:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac
 0003b650:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.····
 0003b660:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.··
 0003b670:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
 0003b680:·2e31·302e·312e·330a·2020·2d20·4449·5341··.10.1.3.··-·DISA
 0003b690:·2d53·5449·472d·5542·5455·2d32·322d·3635··-STIG-UBTU-22-65
 0003b6a0:·3130·3130·0a20·202d·204e·4953·542d·3830··1010.··-·NIST-80
 0003b6b0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
0003b430:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
Max diff block lines reached; 647502/666850 bytes (97.10%) of diff not shown.
48.6 KB
html2text {}
    
Offset 125, 19 lines modifiedOffset 125, 14 lines modified
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
127 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010127 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010
128 ············_\x8c_\x8i_\x8s············1.3.1128 ············_\x8c_\x8i_\x8s············1.3.1
129 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79129 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
130 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2130 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
131 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule131 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
133 [[packages]] 
134 name·=·"aide" 
135 version·=·"*" 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 #·Remediation·is·applicable·only·in·certain·platforms137 #·Remediation·is·applicable·only·in·certain·platforms
142 if·dpkg-query·--show·--showformat='${db:Status-Status}138 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 182, 14 lines modifiedOffset 177, 19 lines modified
182 ··-·PCI-DSSv4-11.5.2177 ··-·PCI-DSSv4-11.5.2
183 ··-·enable_strategy178 ··-·enable_strategy
184 ··-·low_complexity179 ··-·low_complexity
185 ··-·low_disruption180 ··-·low_disruption
186 ··-·medium_severity181 ··-·medium_severity
187 ··-·no_reboot_needed182 ··-·no_reboot_needed
188 ··-·package_aide_installed183 ··-·package_aide_installed
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 185 [[packages]]
 186 name·=·"aide"
 187 version·=·"*"
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
194 include·install_aide193 include·install_aide
  
Offset 1980, 19 lines modifiedOffset 1980, 14 lines modified
1980 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861980 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1981 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1981 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1982 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11982 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1983 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251983 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1984 ············_\x8c_\x8i_\x8s·····5.3.11984 ············_\x8c_\x8i_\x8s·····5.3.1
1985 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331985 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1986 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21986 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1987 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1988 [[packages]] 
1989 name·=·"sudo" 
1990 version·=·"*" 
1991 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81987 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1992 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1988 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1993 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1989 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1994 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1990 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1995 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1991 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1996 #·Remediation·is·applicable·only·in·certain·platforms1992 #·Remediation·is·applicable·only·in·certain·platforms
1997 if·dpkg-query·--show·--showformat='${db:Status-Status}1993 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2033, 14 lines modifiedOffset 2028, 19 lines modified
2033 ··-·PCI-DSSv4-2.2.62028 ··-·PCI-DSSv4-2.2.6
2034 ··-·enable_strategy2029 ··-·enable_strategy
2035 ··-·low_complexity2030 ··-·low_complexity
2036 ··-·low_disruption2031 ··-·low_disruption
2037 ··-·medium_severity2032 ··-·medium_severity
2038 ··-·no_reboot_needed2033 ··-·no_reboot_needed
2039 ··-·package_sudo_installed2034 ··-·package_sudo_installed
 2035 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2036 [[packages]]
 2037 name·=·"sudo"
 2038 version·=·"*"
2040 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82039 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2041 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2040 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2042 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2041 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2043 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2042 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2044 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2043 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2045 include·install_sudo2044 include·install_sudo
  
Offset 5670, 19 lines modifiedOffset 5670, 14 lines modified
5670 Severity: ··medium5670 Severity: ··medium
5671 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed5671 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
5672 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003665672 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
5673 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002255673 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
5674 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-2150105674 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-215010
5675 ············_\x8c_\x8i_\x8s·····5.4.15675 ············_\x8c_\x8i_\x8s·····5.4.1
5676 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule5676 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule
5677 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5678 [[packages]] 
5679 name·=·"libpam-pwquality" 
5680 version·=·"*" 
5681 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85677 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5682 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5678 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5683 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5679 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5684 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5680 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5685 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5681 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5686 #·Remediation·is·applicable·only·in·certain·platforms5682 #·Remediation·is·applicable·only·in·certain·platforms
5687 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-5683 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 5719, 14 lines modifiedOffset 5714, 19 lines modified
5719 ··-·DISA-STIG-UBTU-22-2150105714 ··-·DISA-STIG-UBTU-22-215010
5720 ··-·enable_strategy5715 ··-·enable_strategy
5721 ··-·low_complexity5716 ··-·low_complexity
5722 ··-·low_disruption5717 ··-·low_disruption
5723 ··-·medium_severity5718 ··-·medium_severity
5724 ··-·no_reboot_needed5719 ··-·no_reboot_needed
5725 ··-·package_pam_pwquality_installed5720 ··-·package_pam_pwquality_installed
 5721 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5722 [[packages]]
 5723 name·=·"libpam-pwquality"
 5724 version·=·"*"
5726 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5727 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5728 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5729 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5730 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5731 include·install_libpam-pwquality5730 include·install_libpam-pwquality
  
Offset 7970, 19 lines modifiedOffset 7970, 14 lines modified
7970 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022357970 ············_\x8d_\x8i_\x8s_\x8a····CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
7971 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,7971 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,
7972 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001557972 ····················SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
7973 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-4310107973 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-431010
7974 ············_\x8c_\x8i_\x8s·····1.6.1.17974 ············_\x8c_\x8i_\x8s·····1.6.1.1
7975 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R457975 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
7976 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260556r958702_rule7976 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260556r958702_rule
Max diff block lines reached; 44542/49757 bytes (89.52%) of diff not shown.
242 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-standard.html
    
Offset 20128, 140 lines modifiedOffset 20128, 140 lines modified
0004e9f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0004e9f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0004ea00:·646d·3131·3335·3622·2074·6162·696e·6465··dm11356"·tabinde0004ea00:·646d·3131·3335·3622·2074·6162·696e·6465··dm11356"·tabinde
0004ea10:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0004ea10:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0004ea20:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0004ea20:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0004ea30:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0004ea30:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0004ea40:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0004ea40:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0004ea50:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0004ea50:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0004ea60:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0004ea60:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0004ea70:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0004ea80:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0004ea90:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0004eaa0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0004eab0:·7073·6522·2069·643d·2269·646d·3131·3335··pse"·id="idm11350004ea70:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0004ea80:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0004ea90:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0004eaa0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 0004eab0:·3133·3536·223e·3c74·6162·6c65·2063·6c61··1356"><table·cla
 0004eac0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0004ead0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0004eae0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0004eaf0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0004eb00:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0004eb10:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0004eb20:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0004eb30:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0004eb40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0004eb50:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0004eb60:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0004eb70:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0004eb80:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0004eb90:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0004eac0:·3622·3e3c·7072·653e·3c63·6f64·653e·0a5b··6"><pre><code>.[0004eba0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
0004ead0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0004eae0:·203d·2022·7273·7973·6c6f·6722·0a76·6572···=·"rsyslog".ver 
0004eaf0:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0004eb00:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0004eb10:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0004eb20:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0004eb30:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0004eb40:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0004eb50:·6d31·3133·3537·2220·7461·6269·6e64·6578··m11357"·tabindex 
0004eb60:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0004eb70:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0004eb80:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0004eb90:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0004eba0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0004ebb0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·0004ebb0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
0004ebc0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0004ebd0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0004ebe0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0004ebf0:·6c61·7073·6522·2069·643d·2269·646d·3131··lapse"·id="idm11 
0004ec00:·3335·3722·3e3c·7461·626c·6520·636c·6173··357"><table·clas 
0004ec10:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0004ec20:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0004ec30:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0004ec40:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0004ec50:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0004ec60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0004ec70:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0004ec80:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0004ec90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0004eca0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0004ebc0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0004ebd0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0004ebe0:·726d·730a·6966·2064·706b·672d·7175·6572··rms.if·dpkg-quer
 0004ebf0:·7920·2d2d·7368·6f77·202d·2d73·686f·7766··y·--show·--showf
 0004ec00:·6f72·6d61·743d·2724·7b64·623a·5374·6174··ormat='${db:Stat
 0004ec10:·7573·2d53·7461·7475·737d·0a27·2027·6c69··us-Status}.'·'li
 0004ec20:·6e75·782d·6261·7365·2720·3226·6774·3b2f··nux-base'·2&gt;/
 0004ec30:·6465·762f·6e75·6c6c·207c·2067·7265·7020··dev/null·|·grep·
 0004ec40:·2d71·205e·696e·7374·616c·6c65·643b·2074··-q·^installed;·t
 0004ec50:·6865·6e0a·0a44·4542·4941·4e5f·4652·4f4e··hen..DEBIAN_FRON
 0004ec60:·5445·4e44·3d6e·6f6e·696e·7465·7261·6374··TEND=noninteract
 0004ec70:·6976·6520·6170·742d·6765·7420·696e·7374··ive·apt-get·inst
 0004ec80:·616c·6c20·2d79·2022·7273·7973·6c6f·6722··all·-y·"rsyslog"
 0004ec90:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0004eca0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0004ecb0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0004ecc0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0004ecd0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 0004ece0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0004ecf0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0004ed00:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0004ed10:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0004ed20:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0004ed30:·3d22·2369·646d·3131·3335·3722·2074·6162··="#idm11357"·tab
 0004ed40:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0004ed50:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0004ed60:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0004ed70:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0004ed80:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0004ed90:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
 0004eda0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
 0004edb0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0004edc0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0004edd0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0004ede0:·643d·2269·646d·3131·3335·3722·3e3c·7461··d="idm11357"><ta
 0004edf0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0004ee00:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0004ee10:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0004ee20:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0004ee30:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0004ee40:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0004ee50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0004ee60:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0004ee70:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0004ee80:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0004ee90:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0004eea0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0004eeb0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0004ecb0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0004eec0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0004ecc0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0004ecd0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0004ece0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0004ecf0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0004ed00:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0004ed10:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0004ed20:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0004ed30:·6d73·0a69·6620·6470·6b67·2d71·7565·7279··ms.if·dpkg-query 
0004ed40:·202d·2d73·686f·7720·2d2d·7368·6f77·666f···--show·--showfo 
0004ed50:·726d·6174·3d27·247b·6462·3a53·7461·7475··rmat='${db:Statu 
0004ed60:·732d·5374·6174·7573·7d0a·2720·276c·696e··s-Status}.'·'lin 
0004ed70:·7578·2d62·6173·6527·2032·2667·743b·2f64··ux-base'·2&gt;/d 
0004ed80:·6576·2f6e·756c·6c20·7c20·6772·6570·202d··ev/null·|·grep·-0004eed0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0004eee0:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat
 0004eef0:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package·
 0004ef00:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_
 0004ef10:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag
Max diff block lines reached; 212744/230712 bytes (92.21%) of diff not shown.
16.1 KB
html2text {}
    
Offset 1669, 19 lines modifiedOffset 1669, 14 lines modified
1669 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91669 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1670 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11670 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1671 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1671 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1672 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11672 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1673 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1673 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1674 ···························SRG-OS-000480-GPOS-002271674 ···························SRG-OS-000480-GPOS-00227
1675 ············_\x8c_\x8i_\x8s············4.2.2.11675 ············_\x8c_\x8i_\x8s············4.2.2.1
1676 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1677 [[packages]] 
1678 name·=·"rsyslog" 
1679 version·=·"*" 
1680 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81676 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1681 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1677 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1682 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1678 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1683 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1679 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1684 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1680 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1685 #·Remediation·is·applicable·only·in·certain·platforms1681 #·Remediation·is·applicable·only·in·certain·platforms
1686 if·dpkg-query·--show·--showformat='${db:Status-Status}1682 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1718, 14 lines modifiedOffset 1713, 19 lines modified
1718 ··-·NIST-800-53-CM-6(a)1713 ··-·NIST-800-53-CM-6(a)
1719 ··-·enable_strategy1714 ··-·enable_strategy
1720 ··-·low_complexity1715 ··-·low_complexity
1721 ··-·low_disruption1716 ··-·low_disruption
1722 ··-·medium_severity1717 ··-·medium_severity
1723 ··-·no_reboot_needed1718 ··-·no_reboot_needed
1724 ··-·package_rsyslog_installed1719 ··-·package_rsyslog_installed
 1720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1721 [[packages]]
 1722 name·=·"rsyslog"
 1723 version·=·"*"
1725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81724 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1725 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1726 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1727 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1728 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1730 include·install_rsyslog1729 include·install_rsyslog
  
Offset 1757, 18 lines modifiedOffset 1757, 14 lines modified
1757 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11757 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1758 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1758 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1759 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11759 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1760 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002271760 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
1761 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-6520101761 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-652010
1762 ············_\x8c_\x8i_\x8s············4.2.2.21762 ············_\x8c_\x8i_\x8s············4.2.2.2
1763 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260588r991562_rule1763 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260588r991562_rule
1764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1765 [customizations.services] 
1766 enabled·=·["rsyslog"] 
1767 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1768 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1765 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1769 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1766 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1770 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1767 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1771 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1768 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1772 #·Remediation·is·applicable·only·in·certain·platforms1769 #·Remediation·is·applicable·only·in·certain·platforms
1773 if·dpkg-query·--show·--showformat='${db:Status-Status}1770 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1825, 14 lines modifiedOffset 1821, 18 lines modified
1825 ··-·NIST-800-53-CM-6(a)1821 ··-·NIST-800-53-CM-6(a)
1826 ··-·enable_strategy1822 ··-·enable_strategy
1827 ··-·low_complexity1823 ··-·low_complexity
1828 ··-·low_disruption1824 ··-·low_disruption
1829 ··-·medium_severity1825 ··-·medium_severity
1830 ··-·no_reboot_needed1826 ··-·no_reboot_needed
1831 ··-·service_rsyslog_enabled1827 ··-·service_rsyslog_enabled
 1828 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1829 [customizations.services]
 1830 enabled·=·["rsyslog"]
1832 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81831 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1833 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1832 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1834 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1833 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1835 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1834 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1836 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1835 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1837 include·enable_rsyslog1836 include·enable_rsyslog
  
Offset 3618, 18 lines modifiedOffset 3618, 14 lines modified
3618 $·sudo·systemctl·mask·--now·apport.service3618 $·sudo·systemctl·mask·--now·apport.service
3619 ············The·Apport·service·modifies·the·kernel·fs.suid_dumpable3619 ············The·Apport·service·modifies·the·kernel·fs.suid_dumpable
3620 Rationale:··configuration·at·runtime·which·prevents·other·hardening·from·being3620 Rationale:··configuration·at·runtime·which·prevents·other·hardening·from·being
3621 ············persistent.·Disabling·the·service·prevents·this·behavior.3621 ············persistent.·Disabling·the·service·prevents·this·behavior.
3622 Severity: ··unknown3622 Severity: ··unknown
3623 Rule·ID:····xccdf_org.ssgproject.content_rule_service_apport_disabled3623 Rule·ID:····xccdf_org.ssgproject.content_rule_service_apport_disabled
3624 References:·_\x8c_\x8i_\x8s·1.5.33624 References:·_\x8c_\x8i_\x8s·1.5.3
3625 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3626 [customizations.services] 
3627 masked·=·["apport"] 
3628 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83625 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3629 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3626 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3630 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3627 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3631 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3628 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3632 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3629 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3633 #·Remediation·is·applicable·only·in·certain·platforms3630 #·Remediation·is·applicable·only·in·certain·platforms
3634 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null3631 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'apport'·2>/dev/null
Offset 3652, 14 lines modifiedOffset 3648, 33 lines modified
3652 #·so·let's·reset·the·state·so·OVAL·checks·pass.3648 #·so·let's·reset·the·state·so·OVAL·checks·pass.
3653 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.3649 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
3654 "$SYSTEMCTL_EXEC"·reset-failed·'apport.service'·||·true3650 "$SYSTEMCTL_EXEC"·reset-failed·'apport.service'·||·true
  
3655 else3651 else
3656 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'3652 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
3657 fi3653 fi
 3654 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 3655 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 3656 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 3657 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 3658 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
 3659 apiVersion:·machineconfiguration.openshift.io/v1
 3660 kind:·MachineConfig
 3661 spec:
 3662 ··config:
 3663 ····ignition:
 3664 ······version:·3.1.0
 3665 ····systemd:
 3666 ······units:
 3667 ······-·name:·apport.service
 3668 ········enabled:·false
 3669 ········mask:·true
 3670 ······-·name:·apport.socket
 3671 ········enabled:·false
 3672 ········mask:·true
3658 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83673 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3659 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3674 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3660 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3675 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3661 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3676 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 11263/16501 bytes (68.26%) of diff not shown.
422 KB
./usr/share/doc/ssg-debderived/ssg-ubuntu2204-guide-stig.html
    
Offset 15079, 150 lines modifiedOffset 15079, 150 lines modified
0003ae60:·6172·6765·743d·2223·6964·6d32·3932·3522··arget="#idm2925"0003ae60:·6172·6765·743d·2223·6964·6d32·3932·3522··arget="#idm2925"
0003ae70:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003ae70:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003ae80:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003ae80:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003ae90:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003ae90:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003aea0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003aea0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003aeb0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003aeb0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003aec0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003aec0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003aed0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003aee0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003aef0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003af00:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003af10:·6964·3d22·6964·6d32·3932·3522·3e3c·7461··id="idm2925"><ta
 0003af20:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003af30:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003af40:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003af50:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003af60:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003af70:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003af80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003af90:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003afa0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003afb0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003afc0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003afd0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003afe0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003aed0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003aee0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003aef0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003af00:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003af10:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003af20:·2269·646d·3239·3235·223e·3c70·7265·3e3c··"idm2925"><pre>< 
0003af30:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003af40:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003af50:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003af60:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003af70:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003af80:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003af90:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003afa0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003afb0:·2223·6964·6d32·3932·3622·2074·6162·696e··"#idm2926"·tabin 
0003afc0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003afd0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003afe0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003aff0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b000:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b010:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b020:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b030:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b040:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b050:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b060:·6d32·3932·3622·3e3c·7461·626c·6520·636c··m2926"><table·cl 
0003b070:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b080:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b090:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b0a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b0b0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b0c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b0d0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b0e0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b0f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b100:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003b110:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003aff0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003b000:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b010:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0003b020:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0003b030:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0003b040:·2070·6c61·7466·6f72·6d73·0a69·6620·6470···platforms.if·dp
 0003b050:·6b67·2d71·7565·7279·202d·2d73·686f·7720··kg-query·--show·
 0003b060:·2d2d·7368·6f77·666f·726d·6174·3d27·247b··--showformat='${
 0003b070:·6462·3a53·7461·7475·732d·5374·6174·7573··db:Status-Status
 0003b080:·7d0a·2720·276c·696e·7578·2d62·6173·6527··}.'·'linux-base'
 0003b090:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null·
 0003b0a0:·7c20·6772·6570·202d·7120·5e69·6e73·7461··|·grep·-q·^insta
 0003b0b0:·6c6c·6564·3b20·7468·656e·0a0a·4445·4249··lled;·then..DEBI
 0003b0c0:·414e·5f46·524f·4e54·454e·443d·6e6f·6e69··AN_FRONTEND=noni
 0003b0d0:·6e74·6572·6163·7469·7665·2061·7074·2d67··nteractive·apt-g
 0003b0e0:·6574·2069·6e73·7461·6c6c·202d·7920·2261··et·install·-y·"a
 0003b0f0:·6964·6522·0a0a·656c·7365·0a20·2020·2026··ide"..else.····&
 0003b100:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
0003b120:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003b130:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003b140:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003b150:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0003b160:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b170:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b180:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b190:·6f72·6d73·0a69·6620·6470·6b67·2d71·7565··orms.if·dpkg-que 
0003b1a0:·7279·202d·2d73·686f·7720·2d2d·7368·6f77··ry·--show·--show 
0003b1b0:·666f·726d·6174·3d27·247b·6462·3a53·7461··format='${db:Sta 
0003b1c0:·7475·732d·5374·6174·7573·7d0a·2720·276c··tus-Status}.'·'l 
0003b1d0:·696e·7578·2d62·6173·6527·2032·2667·743b··inux-base'·2&gt; 
0003b1e0:·2f64·6576·2f6e·756c·6c20·7c20·6772·6570··/dev/null·|·grep 
0003b1f0:·202d·7120·5e69·6e73·7461·6c6c·6564·3b20···-q·^installed;· 
0003b200:·7468·656e·0a0a·4445·4249·414e·5f46·524f··then..DEBIAN_FRO 
0003b210:·4e54·454e·443d·6e6f·6e69·6e74·6572·6163··NTEND=noninterac 
0003b220:·7469·7665·2061·7074·2d67·6574·2069·6e73··tive·apt-get·ins 
0003b230:·7461·6c6c·202d·7920·2261·6964·6522·0a0a··tall·-y·"aide".. 
0003b240:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b250:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b260:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b270:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b280:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b290:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b2a0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b2b0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b2c0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b2d0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b2e0:·2369·646d·3239·3237·2220·7461·6269·6e64··#idm2927"·tabind 
0003b2f0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b300:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b310:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b320:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b330:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b340:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003b110:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
0003b350:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b360:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b370:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b380:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b390:·6964·6d32·3932·3722·3e3c·7461·626c·6520··idm2927"><table· 
0003b3a0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b3b0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b3c0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b3d0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b3e0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b3f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b400:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003b410:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
Max diff block lines reached; 381776/401124 bytes (95.18%) of diff not shown.
30.2 KB
html2text {}
    
Offset 115, 19 lines modifiedOffset 115, 14 lines modified
115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
117 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010117 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········UBTU-22-651010
118 ············_\x8c_\x8i_\x8s············1.3.1118 ············_\x8c_\x8i_\x8s············1.3.1
119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
121 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule121 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-260582r958944_rule
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
123 [[packages]] 
124 name·=·"aide" 
125 version·=·"*" 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
131 #·Remediation·is·applicable·only·in·certain·platforms127 #·Remediation·is·applicable·only·in·certain·platforms
132 if·dpkg-query·--show·--showformat='${db:Status-Status}128 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 172, 14 lines modifiedOffset 167, 19 lines modified
172 ··-·PCI-DSSv4-11.5.2167 ··-·PCI-DSSv4-11.5.2
173 ··-·enable_strategy168 ··-·enable_strategy
174 ··-·low_complexity169 ··-·low_complexity
175 ··-·low_disruption170 ··-·low_disruption
176 ··-·medium_severity171 ··-·medium_severity
177 ··-·no_reboot_needed172 ··-·no_reboot_needed
178 ··-·package_aide_installed173 ··-·package_aide_installed
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 175 [[packages]]
 176 name·=·"aide"
 177 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
184 include·install_aide183 include·install_aide
  
Offset 5993, 19 lines modifiedOffset 5993, 14 lines modified
5993 Severity: ··medium5993 Severity: ··medium
5994 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed5994 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
5995 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003665995 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
5996 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002255996 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00225
5997 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-2150105997 References:·_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-215010
5998 ············_\x8c_\x8i_\x8s·····5.4.15998 ············_\x8c_\x8i_\x8s·····5.4.1
5999 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule5999 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260478r991587_rule
6000 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6001 [[packages]] 
6002 name·=·"libpam-pwquality" 
6003 version·=·"*" 
6004 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86000 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6005 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6001 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6006 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6002 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6007 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6003 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6008 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6004 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6009 #·Remediation·is·applicable·only·in·certain·platforms6005 #·Remediation·is·applicable·only·in·certain·platforms
6010 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-6006 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 6042, 14 lines modifiedOffset 6037, 19 lines modified
6042 ··-·DISA-STIG-UBTU-22-2150106037 ··-·DISA-STIG-UBTU-22-215010
6043 ··-·enable_strategy6038 ··-·enable_strategy
6044 ··-·low_complexity6039 ··-·low_complexity
6045 ··-·low_disruption6040 ··-·low_disruption
6046 ··-·medium_severity6041 ··-·medium_severity
6047 ··-·no_reboot_needed6042 ··-·no_reboot_needed
6048 ··-·package_pam_pwquality_installed6043 ··-·package_pam_pwquality_installed
 6044 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 6045 [[packages]]
 6046 name·=·"libpam-pwquality"
 6047 version·=·"*"
6049 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86048 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6050 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6049 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6051 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6050 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6052 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6051 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6053 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6052 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6054 include·install_libpam-pwquality6053 include·install_libpam-pwquality
  
Offset 6442, 19 lines modifiedOffset 6442, 14 lines modified
6442 ············reauthenticates.·No·other·activity·aside·from·reauthentication·must·unlock·the·system.6442 ············reauthenticates.·No·other·activity·aside·from·reauthentication·must·unlock·the·system.
6443 Severity: ··medium6443 Severity: ··medium
6444 Rule·ID:····xccdf_org.ssgproject.content_rule_vlock_installed6444 Rule·ID:····xccdf_org.ssgproject.content_rule_vlock_installed
6445 ············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-0000606445 ············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-000060
6446 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-000116446 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-00011
6447 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-4120256447 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-412025
6448 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260553r986283_rule6448 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260553r986283_rule
6449 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6450 [[packages]] 
6451 name·=·"vlock" 
6452 version·=·"*" 
6453 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86449 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6454 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6450 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6455 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6451 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6456 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6452 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6457 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6453 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6458 #·Remediation·is·applicable·only·in·certain·platforms6454 #·Remediation·is·applicable·only·in·certain·platforms
6459 if·dpkg-query·--show·--showformat='${db:Status-Status}6455 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 6491, 14 lines modifiedOffset 6486, 19 lines modified
6491 ··-·DISA-STIG-UBTU-22-4120256486 ··-·DISA-STIG-UBTU-22-412025
6492 ··-·enable_strategy6487 ··-·enable_strategy
6493 ··-·low_complexity6488 ··-·low_complexity
6494 ··-·low_disruption6489 ··-·low_disruption
6495 ··-·medium_severity6490 ··-·medium_severity
6496 ··-·no_reboot_needed6491 ··-·no_reboot_needed
6497 ··-·vlock_installed6492 ··-·vlock_installed
 6493 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 6494 [[packages]]
 6495 name·=·"vlock"
 6496 version·=·"*"
6498 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86497 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6499 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6498 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6500 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6499 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6501 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6500 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6502 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6501 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6503 include·install_vlock6502 include·install_vlock
  
Offset 6526, 19 lines modifiedOffset 6526, 14 lines modified
6526 Rule·ID:····xccdf_org.ssgproject.content_rule_package_opensc_installed6526 Rule·ID:····xccdf_org.ssgproject.content_rule_package_opensc_installed
6527 ············_\x8d_\x8i_\x8s_\x8a····CCI-001953,·CCI-0040466527 ············_\x8d_\x8i_\x8s_\x8a····CCI-001953,·CCI-004046
6528 ············_\x8i_\x8s_\x8m·····1382,·1384,·13866528 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
6529 References:·_\x8n_\x8i_\x8s_\x8t····CM-6(a)6529 References:·_\x8n_\x8i_\x8s_\x8t····CM-6(a)
6530 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-001616530 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161
6531 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-6120156531 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··UBTU-22-612015
6532 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260574r958816_rule6532 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-260574r958816_rule
Max diff block lines reached; 25564/30875 bytes (82.80%) of diff not shown.
1.53 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2404-guide-cis_level1_server.html
    
Offset 15092, 146 lines modifiedOffset 15092, 146 lines modified
0003af30:·612d·7461·7267·6574·3d22·2369·646d·3235··a-target="#idm250003af30:·612d·7461·7267·6574·3d22·2369·646d·3235··a-target="#idm25
0003af40:·3639·2220·7461·6269·6e64·6578·3d22·3022··69"·tabindex="0"0003af40:·3639·2220·7461·6269·6e64·6578·3d22·3022··69"·tabindex="0"
0003af50:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003af50:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003af60:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003af60:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003af70:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003af70:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003af80:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003af80:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003af90:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003af90:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003afa0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003afb0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003afc0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003afd0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003afe0:·6522·2069·643d·2269·646d·3235·3639·223e··e"·id="idm2569">
 0003aff0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b000:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b010:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b020:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b030:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b040:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b050:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b060:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b070:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b080:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b090:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003afa0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003afb0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003afc0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003afd0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003afe0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003aff0:·6964·3d22·6964·6d32·3536·3922·3e3c·7072··id="idm2569"><pr 
0003b000:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003b010:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003b020:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003b030:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003b040:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b050:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b060:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b070:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b080:·6574·3d22·2369·646d·3235·3730·2220·7461··et="#idm2570"·ta 
0003b090:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b0a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b0b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b0c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b0d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b0e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b0f0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003b100:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b110:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b120:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b130:·2269·646d·3235·3730·223e·3c74·6162·6c65··"idm2570"><table 
0003b140:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b150:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b160:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b170:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b180:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b190:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b1a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b1b0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b1c0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b1d0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b1e0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b1f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b200:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b210:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003b0a0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b0b0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b0c0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b0d0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b0e0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003b0f0:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003b100:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003b110:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003b120:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh
 0003b130:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat=
 0003b140:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta
 0003b150:·7475·737d·0a27·2027·6c69·6e75·782d·6261··tus}.'·'linux-ba
 0003b160:·7365·2720·3226·6774·3b2f·6465·762f·6e75··se'·2&gt;/dev/nu
 0003b170:·6c6c·207c·2067·7265·7020·2d71·205e·696e··ll·|·grep·-q·^in
 0003b180:·7374·616c·6c65·643b·2074·6865·6e0a·0a44··stalled;·then..D
 0003b190:·4542·4941·4e5f·4652·4f4e·5445·4e44·3d6e··EBIAN_FRONTEND=n
 0003b1a0:·6f6e·696e·7465·7261·6374·6976·6520·6170··oninteractive·ap
 0003b1b0:·742d·6765·7420·696e·7374·616c·6c20·2d79··t-get·install·-y
 0003b1c0:·2022·6169·6465·220a·0a65·6c73·650a·2020···"aide"..else.··
 0003b1d0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
0003b220:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b230:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b240:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b250:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b260:·6174·666f·726d·730a·6966·2064·706b·672d··atforms.if·dpkg- 
0003b270:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s 
0003b280:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db: 
0003b290:·5374·6174·7573·2d53·7461·7475·737d·0a27··Status-Status}.' 
0003b2a0:·2027·6c69·6e75·782d·6261·7365·2720·3226···'linux-base'·2& 
0003b2b0:·6774·3b2f·6465·762f·6e75·6c6c·207c·2067··gt;/dev/null·|·g 
0003b2c0:·7265·7020·2d71·205e·696e·7374·616c·6c65··rep·-q·^installe 
0003b2d0:·643b·2074·6865·6e0a·0a44·4542·4941·4e5f··d;·then..DEBIAN_ 
0003b2e0:·4652·4f4e·5445·4e44·3d6e·6f6e·696e·7465··FRONTEND=noninte 
0003b2f0:·7261·6374·6976·6520·6170·742d·6765·7420··ractive·apt-get· 
0003b300:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003b310:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt; 
0003b320:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b330:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b340:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b350:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b360:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b370:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b380:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b390:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b3a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b3b0:·743d·2223·6964·6d32·3537·3122·2074·6162··t="#idm2571"·tab 
0003b3c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b3d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b3e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b3f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b400:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b410:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003b1e0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
0003b420:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b430:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b440:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b450:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b460:·643d·2269·646d·3235·3731·223e·3c74·6162··d="idm2571"><tab 
0003b470:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b480:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b490:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b4a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b4b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b4c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b4d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b4e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
Max diff block lines reached; 1464850/1483646 bytes (98.73%) of diff not shown.
115 KB
html2text {}
    
Offset 121, 19 lines modifiedOffset 121, 14 lines modified
121 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)121 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
126 ············_\x8c_\x8i_\x8s············6.3.1126 ············_\x8c_\x8i_\x8s············6.3.1
127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
129 [[packages]] 
130 name·=·"aide" 
131 version·=·"*" 
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
137 #·Remediation·is·applicable·only·in·certain·platforms133 #·Remediation·is·applicable·only·in·certain·platforms
138 if·dpkg-query·--show·--showformat='${db:Status-Status}134 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 176, 14 lines modifiedOffset 171, 19 lines modified
176 ··-·PCI-DSSv4-11.5.2171 ··-·PCI-DSSv4-11.5.2
177 ··-·enable_strategy172 ··-·enable_strategy
178 ··-·low_complexity173 ··-·low_complexity
179 ··-·low_disruption174 ··-·low_disruption
180 ··-·medium_severity175 ··-·medium_severity
181 ··-·no_reboot_needed176 ··-·no_reboot_needed
182 ··-·package_aide_installed177 ··-·package_aide_installed
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 179 [[packages]]
 180 name·=·"aide"
 181 version·=·"*"
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
188 include·install_aide187 include·install_aide
  
Offset 1645, 19 lines modifiedOffset 1645, 14 lines modified
1645 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861645 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1646 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1646 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1647 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11647 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1648 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251648 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1649 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331649 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1650 ············_\x8c_\x8i_\x8s·····5.2.11650 ············_\x8c_\x8i_\x8s·····5.2.1
1651 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21651 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1652 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1653 [[packages]] 
1654 name·=·"sudo" 
1655 version·=·"*" 
1656 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81652 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1657 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1653 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1658 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1654 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1659 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1655 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1660 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1656 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1661 #·Remediation·is·applicable·only·in·certain·platforms1657 #·Remediation·is·applicable·only·in·certain·platforms
1662 if·dpkg-query·--show·--showformat='${db:Status-Status}1658 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1698, 14 lines modifiedOffset 1693, 19 lines modified
1698 ··-·PCI-DSSv4-2.2.61693 ··-·PCI-DSSv4-2.2.6
1699 ··-·enable_strategy1694 ··-·enable_strategy
1700 ··-·low_complexity1695 ··-·low_complexity
1701 ··-·low_disruption1696 ··-·low_disruption
1702 ··-·medium_severity1697 ··-·medium_severity
1703 ··-·no_reboot_needed1698 ··-·no_reboot_needed
1704 ··-·package_sudo_installed1699 ··-·package_sudo_installed
 1700 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1701 [[packages]]
 1702 name·=·"sudo"
 1703 version·=·"*"
1705 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1706 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1705 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1707 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1706 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1708 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1707 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1709 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1708 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1710 include·install_sudo1709 include·install_sudo
  
Offset 6933, 19 lines modifiedOffset 6933, 14 lines modified
6933 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·p\x8pa\x8am\x8m-\x8-m\x8mo\x8od\x8du\x8ul\x8le\x8es\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*6933 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·p\x8pa\x8am\x8m-\x8-m\x8mo\x8od\x8du\x8ul\x8le\x8es\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
6934 The·libpam-modules·package·can·be·installed·with·the·following·command:6934 The·libpam-modules·package·can·be·installed·with·the·following·command:
6935 $·apt-get·install·libpam-modules6935 $·apt-get·install·libpam-modules
6936 Rationale:··libpam-modules·contains·PAM·modules·that·are·needed·by·other·rules·when·configuring·PAM·options.6936 Rationale:··libpam-modules·contains·PAM·modules·that·are·needed·by·other·rules·when·configuring·PAM·options.
6937 Severity: ··medium6937 Severity: ··medium
6938 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_modules_installed6938 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_modules_installed
6939 References:·_\x8c_\x8i_\x8s·5.3.1.26939 References:·_\x8c_\x8i_\x8s·5.3.1.2
6940 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6941 [[packages]] 
6942 name·=·"libpam-modules" 
6943 version·=·"*" 
6944 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86940 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6945 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6941 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6946 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6942 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6947 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6943 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6948 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6944 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6949 #·Remediation·is·applicable·only·in·certain·platforms6945 #·Remediation·is·applicable·only·in·certain·platforms
6950 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-q·'^installed';6946 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-q·'^installed';
Offset 6980, 14 lines modifiedOffset 6975, 19 lines modified
6980 ··tags:6975 ··tags:
6981 ··-·enable_strategy6976 ··-·enable_strategy
6982 ··-·low_complexity6977 ··-·low_complexity
6983 ··-·low_disruption6978 ··-·low_disruption
6984 ··-·medium_severity6979 ··-·medium_severity
6985 ··-·no_reboot_needed6980 ··-·no_reboot_needed
6986 ··-·package_pam_modules_installed6981 ··-·package_pam_modules_installed
 6982 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 6983 [[packages]]
 6984 name·=·"libpam-modules"
 6985 version·=·"*"
6987 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86986 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6988 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6987 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6989 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6988 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6990 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6989 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6991 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6990 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6992 include·install_libpam-modules6991 include·install_libpam-modules
  
Offset 7004, 19 lines modifiedOffset 7004, 14 lines modified
7004 ············at·guessing·and·brute-force·attacks.·"pwquality"·enforces·complex·password·construction·configuration7004 ············at·guessing·and·brute-force·attacks.·"pwquality"·enforces·complex·password·construction·configuration
7005 ············and·has·the·ability·to·limit·brute-force·attacks·on·the·system.7005 ············and·has·the·ability·to·limit·brute-force·attacks·on·the·system.
7006 Severity: ··medium7006 Severity: ··medium
7007 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed7007 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
7008 ············_\x8d_\x8i_\x8s_\x8a···CCI-0003667008 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366
7009 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002257009 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00225
7010 ············_\x8c_\x8i_\x8s····5.3.1.37010 ············_\x8c_\x8i_\x8s····5.3.1.3
Max diff block lines reached; 112740/118101 bytes (95.46%) of diff not shown.
1.3 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2404-guide-cis_level1_workstation.html
    
Offset 15083, 146 lines modifiedOffset 15083, 146 lines modified
0003aea0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003aea0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003aeb0:·6964·6d32·3536·3922·2074·6162·696e·6465··idm2569"·tabinde0003aeb0:·6964·6d32·3536·3922·2074·6162·696e·6465··idm2569"·tabinde
0003aec0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003aec0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003aed0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003aed0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003aee0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003aee0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003aef0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003aef0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003af00:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003af00:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003af10:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003af10:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003af20:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003af30:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003af40:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003af50:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
 0003af60:·3536·3922·3e3c·7461·626c·6520·636c·6173··569"><table·clas
 0003af70:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003af80:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003af90:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003afa0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003afb0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003afc0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003afd0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003afe0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003aff0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b000:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b010:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b020:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b030:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003af20:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003af30:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003af40:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003af50:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003af60:·7073·6522·2069·643d·2269·646d·3235·3639··pse"·id="idm2569 
0003af70:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003af80:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003af90:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003afa0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003afb0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003afc0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003afd0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003afe0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003aff0:·2d74·6172·6765·743d·2223·6964·6d32·3537··-target="#idm257 
0003b000:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"· 
0003b010:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b020:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b030:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b040:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b050:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b060:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b070:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b080:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b090:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b0a0:·2220·6964·3d22·6964·6d32·3537·3022·3e3c··"·id="idm2570">< 
0003b0b0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b0c0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b0d0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b0e0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b0f0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b100:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b110:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b040:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b120:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b130:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b140:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b150:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b160:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b170:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003b050:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 0003b060:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003b070:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003b080:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003b090:·6d73·0a69·6620·6470·6b67·2d71·7565·7279··ms.if·dpkg-query
 0003b0a0:·202d·2d73·686f·7720·2d2d·7368·6f77·666f···--show·--showfo
 0003b0b0:·726d·6174·3d27·247b·6462·3a53·7461·7475··rmat='${db:Statu
 0003b0c0:·732d·5374·6174·7573·7d0a·2720·276c·696e··s-Status}.'·'lin
 0003b0d0:·7578·2d62·6173·6527·2032·2667·743b·2f64··ux-base'·2&gt;/d
 0003b0e0:·6576·2f6e·756c·6c20·7c20·6772·6570·202d··ev/null·|·grep·-
 0003b0f0:·7120·5e69·6e73·7461·6c6c·6564·3b20·7468··q·^installed;·th
 0003b100:·656e·0a0a·4445·4249·414e·5f46·524f·4e54··en..DEBIAN_FRONT
 0003b110:·454e·443d·6e6f·6e69·6e74·6572·6163·7469··END=noninteracti
 0003b120:·7665·2061·7074·2d67·6574·2069·6e73·7461··ve·apt-get·insta
 0003b130:·6c6c·202d·7920·2261·6964·6522·0a0a·656c··ll·-y·"aide"..el
 0003b140:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0003b150:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0003b160:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0003b170:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0003b180:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
 0003b190:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003b1a0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b1b0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003b1c0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003b1d0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003b1e0:·646d·3235·3730·2220·7461·6269·6e64·6578··dm2570"·tabindex
 0003b1f0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003b200:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003b210:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003b220:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003b230:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003b240:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
 0003b250:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
 0003b260:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b270:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b280:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b290:·6d32·3537·3022·3e3c·7461·626c·6520·636c··m2570"><table·cl
 0003b2a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b2b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b2c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b2d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b2e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b2f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b300:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b310:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b320:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b330:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b180:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003b340:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b350:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b360:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003b190:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b1a0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003b1b0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003b1c0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b1d0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b1e0:·6470·6b67·2d71·7565·7279·202d·2d73·686f··dpkg-query·--sho 
0003b1f0:·7720·2d2d·7368·6f77·666f·726d·6174·3d27··w·--showformat=' 
0003b200:·247b·6462·3a53·7461·7475·732d·5374·6174··${db:Status-Stat 
0003b210:·7573·7d0a·2720·276c·696e·7578·2d62·6173··us}.'·'linux-bas 
0003b220:·6527·2032·2667·743b·2f64·6576·2f6e·756c··e'·2&gt;/dev/nul 
0003b230:·6c20·7c20·6772·6570·202d·7120·5e69·6e73··l·|·grep·-q·^ins 
0003b240:·7461·6c6c·6564·3b20·7468·656e·0a0a·4445··talled;·then..DE 
0003b250:·4249·414e·5f46·524f·4e54·454e·443d·6e6f··BIAN_FRONTEND=no 
0003b260:·6e69·6e74·6572·6163·7469·7665·2061·7074··ninteractive·apt 
Max diff block lines reached; 1240896/1259692 bytes (98.51%) of diff not shown.
98.9 KB
html2text {}
    
Offset 120, 19 lines modifiedOffset 120, 14 lines modified
120 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)120 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
125 ············_\x8c_\x8i_\x8s············6.3.1125 ············_\x8c_\x8i_\x8s············6.3.1
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
128 [[packages]] 
129 name·=·"aide" 
130 version·=·"*" 
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
136 #·Remediation·is·applicable·only·in·certain·platforms132 #·Remediation·is·applicable·only·in·certain·platforms
137 if·dpkg-query·--show·--showformat='${db:Status-Status}133 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 175, 14 lines modifiedOffset 170, 19 lines modified
175 ··-·PCI-DSSv4-11.5.2170 ··-·PCI-DSSv4-11.5.2
176 ··-·enable_strategy171 ··-·enable_strategy
177 ··-·low_complexity172 ··-·low_complexity
178 ··-·low_disruption173 ··-·low_disruption
179 ··-·medium_severity174 ··-·medium_severity
180 ··-·no_reboot_needed175 ··-·no_reboot_needed
181 ··-·package_aide_installed176 ··-·package_aide_installed
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 178 [[packages]]
 179 name·=·"aide"
 180 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
187 include·install_aide186 include·install_aide
  
Offset 1388, 19 lines modifiedOffset 1388, 14 lines modified
1388 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861388 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1389 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1389 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1390 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11390 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1391 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251391 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1392 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331392 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1393 ············_\x8c_\x8i_\x8s·····5.2.11393 ············_\x8c_\x8i_\x8s·····5.2.1
1394 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21394 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1395 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1396 [[packages]] 
1397 name·=·"sudo" 
1398 version·=·"*" 
1399 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81395 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1400 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1396 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1401 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1397 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1402 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1398 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1403 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1399 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1404 #·Remediation·is·applicable·only·in·certain·platforms1400 #·Remediation·is·applicable·only·in·certain·platforms
1405 if·dpkg-query·--show·--showformat='${db:Status-Status}1401 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1441, 14 lines modifiedOffset 1436, 19 lines modified
1441 ··-·PCI-DSSv4-2.2.61436 ··-·PCI-DSSv4-2.2.6
1442 ··-·enable_strategy1437 ··-·enable_strategy
1443 ··-·low_complexity1438 ··-·low_complexity
1444 ··-·low_disruption1439 ··-·low_disruption
1445 ··-·medium_severity1440 ··-·medium_severity
1446 ··-·no_reboot_needed1441 ··-·no_reboot_needed
1447 ··-·package_sudo_installed1442 ··-·package_sudo_installed
 1443 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1444 [[packages]]
 1445 name·=·"sudo"
 1446 version·=·"*"
1448 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1449 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1448 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1450 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1449 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1451 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1450 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1452 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1451 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1453 include·install_sudo1452 include·install_sudo
  
Offset 6676, 19 lines modifiedOffset 6676, 14 lines modified
6676 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·p\x8pa\x8am\x8m-\x8-m\x8mo\x8od\x8du\x8ul\x8le\x8es\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*6676 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·p\x8pa\x8am\x8m-\x8-m\x8mo\x8od\x8du\x8ul\x8le\x8es\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
6677 The·libpam-modules·package·can·be·installed·with·the·following·command:6677 The·libpam-modules·package·can·be·installed·with·the·following·command:
6678 $·apt-get·install·libpam-modules6678 $·apt-get·install·libpam-modules
6679 Rationale:··libpam-modules·contains·PAM·modules·that·are·needed·by·other·rules·when·configuring·PAM·options.6679 Rationale:··libpam-modules·contains·PAM·modules·that·are·needed·by·other·rules·when·configuring·PAM·options.
6680 Severity: ··medium6680 Severity: ··medium
6681 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_modules_installed6681 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_modules_installed
6682 References:·_\x8c_\x8i_\x8s·5.3.1.26682 References:·_\x8c_\x8i_\x8s·5.3.1.2
6683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6684 [[packages]] 
6685 name·=·"libpam-modules" 
6686 version·=·"*" 
6687 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6688 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6684 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6689 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6685 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6690 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6686 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6691 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6687 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6692 #·Remediation·is·applicable·only·in·certain·platforms6688 #·Remediation·is·applicable·only·in·certain·platforms
6693 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-q·'^installed';6689 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-q·'^installed';
Offset 6723, 14 lines modifiedOffset 6718, 19 lines modified
6723 ··tags:6718 ··tags:
6724 ··-·enable_strategy6719 ··-·enable_strategy
6725 ··-·low_complexity6720 ··-·low_complexity
6726 ··-·low_disruption6721 ··-·low_disruption
6727 ··-·medium_severity6722 ··-·medium_severity
6728 ··-·no_reboot_needed6723 ··-·no_reboot_needed
6729 ··-·package_pam_modules_installed6724 ··-·package_pam_modules_installed
 6725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 6726 [[packages]]
 6727 name·=·"libpam-modules"
 6728 version·=·"*"
6730 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86729 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6731 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6730 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6732 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6731 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6733 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6732 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6734 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6733 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6735 include·install_libpam-modules6734 include·install_libpam-modules
  
Offset 6747, 19 lines modifiedOffset 6747, 14 lines modified
6747 ············at·guessing·and·brute-force·attacks.·"pwquality"·enforces·complex·password·construction·configuration6747 ············at·guessing·and·brute-force·attacks.·"pwquality"·enforces·complex·password·construction·configuration
6748 ············and·has·the·ability·to·limit·brute-force·attacks·on·the·system.6748 ············and·has·the·ability·to·limit·brute-force·attacks·on·the·system.
6749 Severity: ··medium6749 Severity: ··medium
6750 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed6750 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
6751 ············_\x8d_\x8i_\x8s_\x8a···CCI-0003666751 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366
6752 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002256752 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00225
6753 ············_\x8c_\x8i_\x8s····5.3.1.36753 ············_\x8c_\x8i_\x8s····5.3.1.3
Max diff block lines reached; 95937/101298 bytes (94.71%) of diff not shown.
1.64 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2404-guide-cis_level2_server.html
    
Offset 15127, 146 lines modifiedOffset 15127, 146 lines modified
0003b160:·6574·3d22·2369·646d·3235·3639·2220·7461··et="#idm2569"·ta0003b160:·6574·3d22·2369·646d·3235·3639·2220·7461··et="#idm2569"·ta
0003b170:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b170:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b180:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b180:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b190:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b190:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b1a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b1a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b1b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b1b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b1c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b1c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b1d0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003b1e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b1f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b200:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b210:·2269·646d·3235·3639·223e·3c74·6162·6c65··"idm2569"><table
 0003b220:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003b230:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003b240:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003b250:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b260:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003b270:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b280:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b290:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003b2a0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b2b0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003b2c0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003b2d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003b2e0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b1d0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003b1e0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003b1f0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b200:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b210:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b220:·6d32·3536·3922·3e3c·7072·653e·3c63·6f64··m2569"><pre><cod 
0003b230:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003b240:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003b250:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003b260:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b270:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b280:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b290:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b2a0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b2b0:·646d·3235·3730·2220·7461·6269·6e64·6578··dm2570"·tabindex 
0003b2c0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b2d0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b2e0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b2f0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b300:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b310:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b320:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003b330:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b340:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b350:·6c61·7073·6522·2069·643d·2269·646d·3235··lapse"·id="idm25 
0003b360:·3730·223e·3c74·6162·6c65·2063·6c61·7373··70"><table·class 
0003b370:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b380:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b390:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b3a0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b3b0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b3c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b3d0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b3e0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b3f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b400:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b410:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b2f0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003b420:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b430:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b440:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b450:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
0003b460:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b470:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b480:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b490:·730a·6966·2064·706b·672d·7175·6572·7920··s.if·dpkg-query· 
0003b4a0:·2d2d·7368·6f77·202d·2d73·686f·7766·6f72··--show·--showfor 
0003b4b0:·6d61·743d·2724·7b64·623a·5374·6174·7573··mat='${db:Status 
0003b4c0:·2d53·7461·7475·737d·0a27·2027·6c69·6e75··-Status}.'·'linu 
0003b4d0:·782d·6261·7365·2720·3226·6774·3b2f·6465··x-base'·2&gt;/de 
0003b4e0:·762f·6e75·6c6c·207c·2067·7265·7020·2d71··v/null·|·grep·-q 
0003b4f0:·205e·696e·7374·616c·6c65·643b·2074·6865···^installed;·the 
0003b500:·6e0a·0a44·4542·4941·4e5f·4652·4f4e·5445··n..DEBIAN_FRONTE 
0003b510:·4e44·3d6e·6f6e·696e·7465·7261·6374·6976··ND=noninteractiv 
0003b520:·6520·6170·742d·6765·7420·696e·7374·616c··e·apt-get·instal 
0003b530:·6c20·2d79·2022·6169·6465·220a·0a65·6c73··l·-y·"aide"..els 
0003b540:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b550:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b560:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b570:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b580:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b590:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b5a0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b5b0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b5c0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b5d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b5e0:·6d32·3537·3122·2074·6162·696e·6465·783d··m2571"·tabindex= 
0003b5f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b600:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b610:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b620:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b630:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b640:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b650:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b660:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b670:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b680:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b690:·3235·3731·223e·3c74·6162·6c65·2063·6c61··2571"><table·cla 
0003b6a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b6b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b6c0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b6d0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b6e0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b6f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b700:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b710:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b720:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b730:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003b300:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003b310:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 0003b320:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 0003b330:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 0003b340:·6174·666f·726d·730a·6966·2064·706b·672d··atforms.if·dpkg-
 0003b350:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s
 0003b360:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db:
 0003b370:·5374·6174·7573·2d53·7461·7475·737d·0a27··Status-Status}.'
 0003b380:·2027·6c69·6e75·782d·6261·7365·2720·3226···'linux-base'·2&
 0003b390:·6774·3b2f·6465·762f·6e75·6c6c·207c·2067··gt;/dev/null·|·g
 0003b3a0:·7265·7020·2d71·205e·696e·7374·616c·6c65··rep·-q·^installe
 0003b3b0:·643b·2074·6865·6e0a·0a44·4542·4941·4e5f··d;·then..DEBIAN_
 0003b3c0:·4652·4f4e·5445·4e44·3d6e·6f6e·696e·7465··FRONTEND=noninte
 0003b3d0:·7261·6374·6976·6520·6170·742d·6765·7420··ractive·apt-get·
 0003b3e0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003b3f0:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt;
Max diff block lines reached; 1573951/1592747 bytes (98.82%) of diff not shown.
124 KB
html2text {}
    
Offset 126, 19 lines modifiedOffset 126, 14 lines modified
126 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)126 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
127 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3127 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
131 ············_\x8c_\x8i_\x8s············6.3.1131 ············_\x8c_\x8i_\x8s············6.3.1
132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
134 [[packages]] 
135 name·=·"aide" 
136 version·=·"*" 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 #·Remediation·is·applicable·only·in·certain·platforms138 #·Remediation·is·applicable·only·in·certain·platforms
143 if·dpkg-query·--show·--showformat='${db:Status-Status}139 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 181, 14 lines modifiedOffset 176, 19 lines modified
181 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
182 ··-·enable_strategy177 ··-·enable_strategy
183 ··-·low_complexity178 ··-·low_complexity
184 ··-·low_disruption179 ··-·low_disruption
185 ··-·medium_severity180 ··-·medium_severity
186 ··-·no_reboot_needed181 ··-·no_reboot_needed
187 ··-·package_aide_installed182 ··-·package_aide_installed
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 184 [[packages]]
 185 name·=·"aide"
 186 version·=·"*"
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
193 include·install_aide192 include·install_aide
  
Offset 2001, 19 lines modifiedOffset 2001, 14 lines modified
2001 ············_\x8i_\x8s_\x8m·····1382,·1384,·13862001 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
2002 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)2002 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
2003 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.12003 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
2004 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001252004 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
2005 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R332005 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
2006 ············_\x8c_\x8i_\x8s·····5.2.12006 ············_\x8c_\x8i_\x8s·····5.2.1
2007 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.22007 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
2008 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2009 [[packages]] 
2010 name·=·"sudo" 
2011 version·=·"*" 
2012 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82008 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2013 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2009 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2014 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2010 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2015 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2011 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2016 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2012 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2017 #·Remediation·is·applicable·only·in·certain·platforms2013 #·Remediation·is·applicable·only·in·certain·platforms
2018 if·dpkg-query·--show·--showformat='${db:Status-Status}2014 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2054, 14 lines modifiedOffset 2049, 19 lines modified
2054 ··-·PCI-DSSv4-2.2.62049 ··-·PCI-DSSv4-2.2.6
2055 ··-·enable_strategy2050 ··-·enable_strategy
2056 ··-·low_complexity2051 ··-·low_complexity
2057 ··-·low_disruption2052 ··-·low_disruption
2058 ··-·medium_severity2053 ··-·medium_severity
2059 ··-·no_reboot_needed2054 ··-·no_reboot_needed
2060 ··-·package_sudo_installed2055 ··-·package_sudo_installed
 2056 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2057 [[packages]]
 2058 name·=·"sudo"
 2059 version·=·"*"
2061 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82060 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2062 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2061 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2063 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2062 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2064 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2063 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2065 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2064 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2066 include·install_sudo2065 include·install_sudo
  
Offset 7529, 19 lines modifiedOffset 7529, 14 lines modified
7529 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·p\x8pa\x8am\x8m-\x8-m\x8mo\x8od\x8du\x8ul\x8le\x8es\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*7529 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·p\x8pa\x8am\x8m-\x8-m\x8mo\x8od\x8du\x8ul\x8le\x8es\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
7530 The·libpam-modules·package·can·be·installed·with·the·following·command:7530 The·libpam-modules·package·can·be·installed·with·the·following·command:
7531 $·apt-get·install·libpam-modules7531 $·apt-get·install·libpam-modules
7532 Rationale:··libpam-modules·contains·PAM·modules·that·are·needed·by·other·rules·when·configuring·PAM·options.7532 Rationale:··libpam-modules·contains·PAM·modules·that·are·needed·by·other·rules·when·configuring·PAM·options.
7533 Severity: ··medium7533 Severity: ··medium
7534 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_modules_installed7534 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_modules_installed
7535 References:·_\x8c_\x8i_\x8s·5.3.1.27535 References:·_\x8c_\x8i_\x8s·5.3.1.2
7536 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
7537 [[packages]] 
7538 name·=·"libpam-modules" 
7539 version·=·"*" 
7540 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87536 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7541 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7537 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7542 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7538 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7543 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7539 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7544 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7540 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7545 #·Remediation·is·applicable·only·in·certain·platforms7541 #·Remediation·is·applicable·only·in·certain·platforms
7546 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-q·'^installed';7542 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-q·'^installed';
Offset 7576, 14 lines modifiedOffset 7571, 19 lines modified
7576 ··tags:7571 ··tags:
7577 ··-·enable_strategy7572 ··-·enable_strategy
7578 ··-·low_complexity7573 ··-·low_complexity
7579 ··-·low_disruption7574 ··-·low_disruption
7580 ··-·medium_severity7575 ··-·medium_severity
7581 ··-·no_reboot_needed7576 ··-·no_reboot_needed
7582 ··-·package_pam_modules_installed7577 ··-·package_pam_modules_installed
 7578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 7579 [[packages]]
 7580 name·=·"libpam-modules"
 7581 version·=·"*"
7583 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87582 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7584 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7583 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7585 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7584 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7586 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7585 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7587 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7586 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7588 include·install_libpam-modules7587 include·install_libpam-modules
  
Offset 7600, 19 lines modifiedOffset 7600, 14 lines modified
7600 ············at·guessing·and·brute-force·attacks.·"pwquality"·enforces·complex·password·construction·configuration7600 ············at·guessing·and·brute-force·attacks.·"pwquality"·enforces·complex·password·construction·configuration
7601 ············and·has·the·ability·to·limit·brute-force·attacks·on·the·system.7601 ············and·has·the·ability·to·limit·brute-force·attacks·on·the·system.
7602 Severity: ··medium7602 Severity: ··medium
7603 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed7603 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
7604 ············_\x8d_\x8i_\x8s_\x8a···CCI-0003667604 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366
7605 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002257605 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00225
7606 ············_\x8c_\x8i_\x8s····5.3.1.37606 ············_\x8c_\x8i_\x8s····5.3.1.3
Max diff block lines reached; 121472/126833 bytes (95.77%) of diff not shown.
1.64 MB
./usr/share/doc/ssg-debderived/ssg-ubuntu2404-guide-cis_level2_workstation.html
    
Offset 15123, 146 lines modifiedOffset 15123, 146 lines modified
0003b120:·6765·743d·2223·6964·6d32·3536·3922·2074··get="#idm2569"·t0003b120:·6765·743d·2223·6964·6d32·3536·3922·2074··get="#idm2569"·t
0003b130:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b130:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b140:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b140:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b150:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b150:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b160:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b160:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b170:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b170:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b180:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b180:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003b190:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003b1a0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b1b0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b1c0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b1d0:·3d22·6964·6d32·3536·3922·3e3c·7461·626c··="idm2569"><tabl
 0003b1e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b1f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b200:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b210:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b220:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b230:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b240:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b250:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b260:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b270:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b280:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b290:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b2a0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003b190:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003b1a0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003b1b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b1c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b1d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b1e0:·646d·3235·3639·223e·3c70·7265·3e3c·636f··dm2569"><pre><co 
0003b1f0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003b200:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003b210:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003b220:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b230:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b240:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b250:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b260:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b270:·6964·6d32·3537·3022·2074·6162·696e·6465··idm2570"·tabinde 
0003b280:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b290:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b2a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b2b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b2c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b2d0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b2e0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b2f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b300:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b310:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
0003b320:·3537·3022·3e3c·7461·626c·6520·636c·6173··570"><table·clas 
0003b330:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b340:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b350:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b360:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b370:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b380:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b390:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b3a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b3b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b3c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b3d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b2b0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003b3e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b3f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b400:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b410:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b420:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b430:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b440:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b450:·6d73·0a69·6620·6470·6b67·2d71·7565·7279··ms.if·dpkg-query 
0003b460:·202d·2d73·686f·7720·2d2d·7368·6f77·666f···--show·--showfo 
0003b470:·726d·6174·3d27·247b·6462·3a53·7461·7475··rmat='${db:Statu 
0003b480:·732d·5374·6174·7573·7d0a·2720·276c·696e··s-Status}.'·'lin 
0003b490:·7578·2d62·6173·6527·2032·2667·743b·2f64··ux-base'·2&gt;/d 
0003b4a0:·6576·2f6e·756c·6c20·7c20·6772·6570·202d··ev/null·|·grep·- 
0003b4b0:·7120·5e69·6e73·7461·6c6c·6564·3b20·7468··q·^installed;·th 
0003b4c0:·656e·0a0a·4445·4249·414e·5f46·524f·4e54··en..DEBIAN_FRONT 
0003b4d0:·454e·443d·6e6f·6e69·6e74·6572·6163·7469··END=noninteracti 
0003b4e0:·7665·2061·7074·2d67·6574·2069·6e73·7461··ve·apt-get·insta 
0003b4f0:·6c6c·202d·7920·2261·6964·6522·0a0a·656c··ll·-y·"aide"..el 
0003b500:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003b510:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003b520:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003b530:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003b540:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003b550:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b560:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b570:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b580:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b590:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b5a0:·646d·3235·3731·2220·7461·6269·6e64·6578··dm2571"·tabindex 
0003b5b0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b5c0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b5d0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b5e0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b5f0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b600:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl 
0003b610:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a 
0003b620:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b630:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b640:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b650:·6d32·3537·3122·3e3c·7461·626c·6520·636c··m2571"><table·cl 
0003b660:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b670:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b680:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b690:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b6a0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b6b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b6c0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b6d0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b6e0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b6f0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b2c0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b2d0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003b2e0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003b2f0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003b300:·6c61·7466·6f72·6d73·0a69·6620·6470·6b67··latforms.if·dpkg
 0003b310:·2d71·7565·7279·202d·2d73·686f·7720·2d2d··-query·--show·--
 0003b320:·7368·6f77·666f·726d·6174·3d27·247b·6462··showformat='${db
 0003b330:·3a53·7461·7475·732d·5374·6174·7573·7d0a··:Status-Status}.
 0003b340:·2720·276c·696e·7578·2d62·6173·6527·2032··'·'linux-base'·2
 0003b350:·2667·743b·2f64·6576·2f6e·756c·6c20·7c20··&gt;/dev/null·|·
 0003b360:·6772·6570·202d·7120·5e69·6e73·7461·6c6c··grep·-q·^install
 0003b370:·6564·3b20·7468·656e·0a0a·4445·4249·414e··ed;·then..DEBIAN
 0003b380:·5f46·524f·4e54·454e·443d·6e6f·6e69·6e74··_FRONTEND=nonint
 0003b390:·6572·6163·7469·7665·2061·7074·2d67·6574··eractive·apt-get
 0003b3a0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003b3b0:·6522·0a0a·656c·7365·0a20·2020·2026·6774··e"..else.····&gt
Max diff block lines reached; 1573813/1592609 bytes (98.82%) of diff not shown.
124 KB
html2text {}
    
Offset 126, 19 lines modifiedOffset 126, 14 lines modified
126 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)126 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
127 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3127 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
131 ············_\x8c_\x8i_\x8s············6.3.1131 ············_\x8c_\x8i_\x8s············6.3.1
132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
134 [[packages]] 
135 name·=·"aide" 
136 version·=·"*" 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 #·Remediation·is·applicable·only·in·certain·platforms138 #·Remediation·is·applicable·only·in·certain·platforms
143 if·dpkg-query·--show·--showformat='${db:Status-Status}139 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 181, 14 lines modifiedOffset 176, 19 lines modified
181 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
182 ··-·enable_strategy177 ··-·enable_strategy
183 ··-·low_complexity178 ··-·low_complexity
184 ··-·low_disruption179 ··-·low_disruption
185 ··-·medium_severity180 ··-·medium_severity
186 ··-·no_reboot_needed181 ··-·no_reboot_needed
187 ··-·package_aide_installed182 ··-·package_aide_installed
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 184 [[packages]]
 185 name·=·"aide"
 186 version·=·"*"
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
193 include·install_aide192 include·install_aide
  
Offset 1922, 19 lines modifiedOffset 1922, 14 lines modified
1922 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861922 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1923 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1923 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1924 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11924 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1925 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251925 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1926 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331926 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1927 ············_\x8c_\x8i_\x8s·····5.2.11927 ············_\x8c_\x8i_\x8s·····5.2.1
1928 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21928 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1930 [[packages]] 
1931 name·=·"sudo" 
1932 version·=·"*" 
1933 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1934 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1930 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1935 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1931 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1936 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1932 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1937 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1933 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1938 #·Remediation·is·applicable·only·in·certain·platforms1934 #·Remediation·is·applicable·only·in·certain·platforms
1939 if·dpkg-query·--show·--showformat='${db:Status-Status}1935 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1975, 14 lines modifiedOffset 1970, 19 lines modified
1975 ··-·PCI-DSSv4-2.2.61970 ··-·PCI-DSSv4-2.2.6
1976 ··-·enable_strategy1971 ··-·enable_strategy
1977 ··-·low_complexity1972 ··-·low_complexity
1978 ··-·low_disruption1973 ··-·low_disruption
1979 ··-·medium_severity1974 ··-·medium_severity
1980 ··-·no_reboot_needed1975 ··-·no_reboot_needed
1981 ··-·package_sudo_installed1976 ··-·package_sudo_installed
 1977 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1978 [[packages]]
 1979 name·=·"sudo"
 1980 version·=·"*"
1982 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81981 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1983 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1982 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1984 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1983 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1985 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1984 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1986 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1985 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1987 include·install_sudo1986 include·install_sudo
  
Offset 7450, 19 lines modifiedOffset 7450, 14 lines modified
7450 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·p\x8pa\x8am\x8m-\x8-m\x8mo\x8od\x8du\x8ul\x8le\x8es\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*7450 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·p\x8pa\x8am\x8m-\x8-m\x8mo\x8od\x8du\x8ul\x8le\x8es\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
7451 The·libpam-modules·package·can·be·installed·with·the·following·command:7451 The·libpam-modules·package·can·be·installed·with·the·following·command:
7452 $·apt-get·install·libpam-modules7452 $·apt-get·install·libpam-modules
7453 Rationale:··libpam-modules·contains·PAM·modules·that·are·needed·by·other·rules·when·configuring·PAM·options.7453 Rationale:··libpam-modules·contains·PAM·modules·that·are·needed·by·other·rules·when·configuring·PAM·options.
7454 Severity: ··medium7454 Severity: ··medium
7455 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_modules_installed7455 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_modules_installed
7456 References:·_\x8c_\x8i_\x8s·5.3.1.27456 References:·_\x8c_\x8i_\x8s·5.3.1.2
7457 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
7458 [[packages]] 
7459 name·=·"libpam-modules" 
7460 version·=·"*" 
7461 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87457 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7462 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7458 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7463 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7459 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7464 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7460 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7465 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7461 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7466 #·Remediation·is·applicable·only·in·certain·platforms7462 #·Remediation·is·applicable·only·in·certain·platforms
7467 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-q·'^installed';7463 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-q·'^installed';
Offset 7497, 14 lines modifiedOffset 7492, 19 lines modified
7497 ··tags:7492 ··tags:
7498 ··-·enable_strategy7493 ··-·enable_strategy
7499 ··-·low_complexity7494 ··-·low_complexity
7500 ··-·low_disruption7495 ··-·low_disruption
7501 ··-·medium_severity7496 ··-·medium_severity
7502 ··-·no_reboot_needed7497 ··-·no_reboot_needed
7503 ··-·package_pam_modules_installed7498 ··-·package_pam_modules_installed
 7499 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 7500 [[packages]]
 7501 name·=·"libpam-modules"
 7502 version·=·"*"
7504 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87503 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7505 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7504 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7506 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7505 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7507 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7506 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7508 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7507 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7509 include·install_libpam-modules7508 include·install_libpam-modules
  
Offset 7521, 19 lines modifiedOffset 7521, 14 lines modified
7521 ············at·guessing·and·brute-force·attacks.·"pwquality"·enforces·complex·password·construction·configuration7521 ············at·guessing·and·brute-force·attacks.·"pwquality"·enforces·complex·password·construction·configuration
7522 ············and·has·the·ability·to·limit·brute-force·attacks·on·the·system.7522 ············and·has·the·ability·to·limit·brute-force·attacks·on·the·system.
7523 Severity: ··medium7523 Severity: ··medium
7524 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed7524 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
7525 ············_\x8d_\x8i_\x8s_\x8a···CCI-0003667525 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366
7526 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002257526 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00225
7527 ············_\x8c_\x8i_\x8s····5.3.1.37527 ············_\x8c_\x8i_\x8s····5.3.1.3
Max diff block lines reached; 121460/126821 bytes (95.77%) of diff not shown.
777 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
777 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ds.xml
Max HTML report size reached
656 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
656 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-ocil.xml
Max HTML report size reached
84.6 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
84.5 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1604-xccdf.xml
Ordering differences only
    
Offset 72, 50 lines modifiedOffset 72, 74 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
82 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
 89 ····<cpe-lang:platform·id="not_aarch64_arch">
 90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 92 ······</cpe-lang:logical-test>
 93 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">94 ····<cpe-lang:platform·id="package_systemd">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
 97 ······</cpe-lang:logical-test>
 98 ····</cpe-lang:platform>
 99 ····<cpe-lang:platform·id="package_postfix">
 100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
 102 ······</cpe-lang:logical-test>
 103 ····</cpe-lang:platform>
 104 ····<cpe-lang:platform·id="package_shadow-utils">
 105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
 107 ······</cpe-lang:logical-test>
 108 ····</cpe-lang:platform>
 109 ····<cpe-lang:platform·id="package_rsyslog">
 110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
88 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="system_with_kernel">114 ····<cpe-lang:platform·id="system_with_kernel">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
93 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="package_systemd">119 ····<cpe-lang:platform·id="package_chrony">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
98 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">124 ····<cpe-lang:platform·id="not_container">
 125 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 127 ······</cpe-lang:logical-test>
 128 ····</cpe-lang:platform>
 129 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
105 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
106 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
107 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">135 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="OR"·negate="false">
109 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
110 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
111 ········</cpe-lang:logical-test> 
112 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
113 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
114 ········</cpe-lang:logical-test> 
115 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="x86_64_arch">141 ····<cpe-lang:platform·id="x86_64_arch">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
120 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
121 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
Offset 126, 25 lines modifiedOffset 150, 35 lines modified
126 ········</cpe-lang:logical-test>150 ········</cpe-lang:logical-test>
127 ········<cpe-lang:logical-test·operator="AND"·negate="true">151 ········<cpe-lang:logical-test·operator="AND"·negate="true">
128 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>152 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
129 ········</cpe-lang:logical-test>153 ········</cpe-lang:logical-test>
130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
131 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
132 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
133 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">157 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
134 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
137 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="package_rsh-server">163 ····<cpe-lang:platform·id="package_rsh-server">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
142 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
 168 ····<cpe-lang:platform·id="package_iptables">
 169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 171 ······</cpe-lang:logical-test>
 172 ····</cpe-lang:platform>
 173 ····<cpe-lang:platform·id="machine">
 174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 176 ······</cpe-lang:logical-test>
 177 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">178 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">179 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:logical-test·operator="AND"·negate="true">180 ········<cpe-lang:logical-test·operator="AND"·negate="true">
147 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>181 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
148 ········</cpe-lang:logical-test>182 ········</cpe-lang:logical-test>
149 ········<cpe-lang:logical-test·operator="AND"·negate="true">183 ········<cpe-lang:logical-test·operator="AND"·negate="true">
150 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>184 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
Offset 157, 90 lines modifiedOffset 191, 56 lines modified
157 ······</cpe-lang:logical-test>191 ······</cpe-lang:logical-test>
158 ····</cpe-lang:platform>192 ····</cpe-lang:platform>
159 ····<cpe-lang:platform·id="aarch64_arch">193 ····<cpe-lang:platform·id="aarch64_arch">
160 ······<cpe-lang:logical-test·operator="AND"·negate="false">194 ······<cpe-lang:logical-test·operator="AND"·negate="false">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>195 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
162 ······</cpe-lang:logical-test>196 ······</cpe-lang:logical-test>
163 ····</cpe-lang:platform>197 ····</cpe-lang:platform>
164 ····<cpe-lang:platform·id="package_audit">198 ····<cpe-lang:platform·id="package_logrotate">
165 ······<cpe-lang:logical-test·operator="AND"·negate="false">199 ······<cpe-lang:logical-test·operator="AND"·negate="false">
166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>200 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1604-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
167 ······</cpe-lang:logical-test>201 ······</cpe-lang:logical-test>
Max diff block lines reached; 74649/86367 bytes (86.43%) of diff not shown.
816 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
816 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ds.xml
Max HTML report size reached
688 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
688 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-ocil.xml
Max HTML report size reached
90.5 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
90.4 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu1804-xccdf.xml
Ordering differences only
    
Offset 72, 60 lines modifiedOffset 72, 79 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
82 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
 89 ····<cpe-lang:platform·id="not_aarch64_arch">
 90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 92 ······</cpe-lang:logical-test>
 93 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">94 ····<cpe-lang:platform·id="package_systemd">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
88 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="system_with_kernel">99 ····<cpe-lang:platform·id="package_postfix">
91 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
93 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="package_systemd">104 ····<cpe-lang:platform·id="package_shadow-utils">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
98 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">109 ····<cpe-lang:platform·id="package_rsyslog">
 110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 112 ······</cpe-lang:logical-test>
 113 ····</cpe-lang:platform>
 114 ····<cpe-lang:platform·id="system_with_kernel">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
105 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
106 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
107 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">119 ····<cpe-lang:platform·id="package_chrony">
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
109 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
110 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
111 ········</cpe-lang:logical-test> 
112 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
113 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
114 ········</cpe-lang:logical-test> 
115 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="mount_home">124 ····<cpe-lang:platform·id="mount_tmp">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
120 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
121 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
122 ····<cpe-lang:platform·id="mount_var-tmp">129 ····<cpe-lang:platform·id="not_container">
 130 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 132 ······</cpe-lang:logical-test>
 133 ····</cpe-lang:platform>
 134 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
123 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
 137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 138 ······</cpe-lang:logical-test>
 139 ····</cpe-lang:platform>
 140 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 141 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
125 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
126 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
127 ····<cpe-lang:platform·id="x86_64_arch">146 ····<cpe-lang:platform·id="x86_64_arch">
128 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
130 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
Offset 136, 25 lines modifiedOffset 155, 35 lines modified
136 ········</cpe-lang:logical-test>155 ········</cpe-lang:logical-test>
137 ········<cpe-lang:logical-test·operator="AND"·negate="true">156 ········<cpe-lang:logical-test·operator="AND"·negate="true">
138 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>157 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
139 ········</cpe-lang:logical-test>158 ········</cpe-lang:logical-test>
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
141 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">162 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
147 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="package_rsh-server">168 ····<cpe-lang:platform·id="package_rsh-server">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
152 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
 173 ····<cpe-lang:platform·id="package_iptables">
 174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 176 ······</cpe-lang:logical-test>
 177 ····</cpe-lang:platform>
 178 ····<cpe-lang:platform·id="machine">
 179 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
 181 ······</cpe-lang:logical-test>
 182 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">183 ····<cpe-lang:platform·id="not_package_chrony_and_not_package_ntp">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">184 ······<cpe-lang:logical-test·operator="AND"·negate="false">
156 ········<cpe-lang:logical-test·operator="AND"·negate="true">185 ········<cpe-lang:logical-test·operator="AND"·negate="true">
157 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>186 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
158 ········</cpe-lang:logical-test>187 ········</cpe-lang:logical-test>
159 ········<cpe-lang:logical-test·operator="AND"·negate="true">188 ········<cpe-lang:logical-test·operator="AND"·negate="true">
160 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>189 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu1804-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>
Offset 167, 101 lines modifiedOffset 196, 72 lines modified
167 ······</cpe-lang:logical-test>196 ······</cpe-lang:logical-test>
168 ····</cpe-lang:platform>197 ····</cpe-lang:platform>
169 ····<cpe-lang:platform·id="aarch64_arch">198 ····<cpe-lang:platform·id="aarch64_arch">
Max diff block lines reached; 80596/92458 bytes (87.17%) of diff not shown.
1.53 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
1.53 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ds.xml
Max HTML report size reached
1.31 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
1.31 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-ocil.xml
Max HTML report size reached
166 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
165 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2004-xccdf.xml
Ordering differences only
    
Offset 72, 335 lines modifiedOffset 72, 335 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ····<cpe-lang:platform·id="machine"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:logical-test·operator="AND"·negate="true">81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
87 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
88 ········</cpe-lang:logical-test>86 ········</cpe-lang:logical-test>
89 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
90 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
91 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
92 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">89 ····<cpe-lang:platform·id="not_aarch64_arch">
93 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
96 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
101 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">99 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
107 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="package_systemd">105 ····<cpe-lang:platform·id="package_systemd">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
112 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel"> 
115 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
119 ······</cpe-lang:logical-test> 
120 ····</cpe-lang:platform> 
121 ····<cpe-lang:platform·id="uefi">110 ····<cpe-lang:platform·id="package_postfix">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
124 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">115 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
131 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
132 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
133 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">122 ····<cpe-lang:platform·id="package_shadow-utils">
134 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
135 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
136 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
137 ········</cpe-lang:logical-test> 
138 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
139 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
140 ········</cpe-lang:logical-test> 
141 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="mount_home">127 ····<cpe-lang:platform·id="package_rsyslog">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
146 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="mount_var-tmp">132 ····<cpe-lang:platform·id="system_with_kernel">
149 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
151 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">137 ····<cpe-lang:platform·id="package_chrony">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/> 
158 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="x86_64_arch">142 ····<cpe-lang:platform·id="mount_tmp">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
163 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">147 ····<cpe-lang:platform·id="not_container">
 148 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 150 ······</cpe-lang:logical-test>
 151 ····</cpe-lang:platform>
 152 ····<cpe-lang:platform·id="not_s390x_arch">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
168 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
169 ········</cpe-lang:logical-test> 
170 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
171 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
172 ········</cpe-lang:logical-test> 
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
174 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">157 ····<cpe-lang:platform·id="package_ufw">
177 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
178 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
179 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
180 ········</cpe-lang:logical-test> 
181 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
182 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
183 ········</cpe-lang:logical-test> 
184 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
185 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
186 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
187 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">162 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
188 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2004-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
Max diff block lines reached; 155404/169287 bytes (91.80%) of diff not shown.
1.6 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
1.6 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ds.xml
Max HTML report size reached
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
1.36 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-ocil.xml
Max HTML report size reached
170 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
170 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2204-xccdf.xml
Ordering differences only
    
Offset 72, 350 lines modifiedOffset 72, 350 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ····<cpe-lang:platform·id="machine"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:logical-test·operator="AND"·negate="true">81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
87 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
88 ········</cpe-lang:logical-test>86 ········</cpe-lang:logical-test>
89 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
90 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
91 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
92 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">89 ····<cpe-lang:platform·id="not_aarch64_arch">
93 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
96 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
97 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
98 ····<cpe-lang:platform·id="system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
99 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
101 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">99 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
107 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="package_systemd">105 ····<cpe-lang:platform·id="package_systemd">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
112 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel"> 
115 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
119 ······</cpe-lang:logical-test> 
120 ····</cpe-lang:platform> 
121 ····<cpe-lang:platform·id="uefi">110 ····<cpe-lang:platform·id="package_postfix">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
124 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">115 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
131 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
132 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
 122 ····<cpe-lang:platform·id="package_shadow-utils">
133 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw"> 
134 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
135 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
136 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
137 ········</cpe-lang:logical-test> 
138 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
139 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
140 ········</cpe-lang:logical-test> 
141 ······</cpe-lang:logical-test> 
142 ····</cpe-lang:platform> 
143 ····<cpe-lang:platform·id="mount_home"> 
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
146 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="mount_var-tmp">127 ····<cpe-lang:platform·id="mount_var">
149 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
151 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="mount_var-log">132 ····<cpe-lang:platform·id="package_rsyslog">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
156 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
157 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
158 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">137 ····<cpe-lang:platform·id="system_with_kernel">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/> 
163 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="x86_64_arch">142 ····<cpe-lang:platform·id="package_chrony">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
168 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
169 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
170 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">147 ····<cpe-lang:platform·id="mount_tmp">
171 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
172 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
173 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
174 ········</cpe-lang:logical-test> 
175 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
176 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
177 ········</cpe-lang:logical-test> 
178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
179 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
180 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
 152 ····<cpe-lang:platform·id="not_container">
181 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel"> 
182 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
183 ········<cpe-lang:logical-test·operator="AND"·negate="true">153 ······<cpe-lang:logical-test·operator="AND"·negate="true">
184 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
185 ········</cpe-lang:logical-test> 
186 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
187 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
188 ········</cpe-lang:logical-test> 
189 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2204-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
190 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
191 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
192 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">157 ····<cpe-lang:platform·id="not_s390x_arch">
Max diff block lines reached; 160602/173781 bytes (92.42%) of diff not shown.
1.07 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
1.07 MB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ds.xml
Max HTML report size reached
880 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
880 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-ocil.xml
Max HTML report size reached
167 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-xccdf.xml
167 KB
./usr/share/xml/scap/ssg/content/ssg-ubuntu2404-xccdf.xml
Ordering differences only
    
Offset 72, 296 lines modifiedOffset 72, 296 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_systemd-timesyncd">79 ····<cpe-lang:platform·id="not_aarch64_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd-timesyncd:def:1"/>81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="machine"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/> 
87 ······</cpe-lang:logical-test>82 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>83 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">84 ····<cpe-lang:platform·id="ipv6_enabled">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">85 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
93 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="system_with_kernel">89 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">90 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
98 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">95 ····<cpe-lang:platform·id="package_pam_and_system_with_kernel">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
104 ······</cpe-lang:logical-test>99 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>100 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="package_systemd">101 ····<cpe-lang:platform·id="package_systemd">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">102 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
109 ······</cpe-lang:logical-test>104 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>105 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="uefi">106 ····<cpe-lang:platform·id="package_postfix">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">107 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
114 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">111 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
121 ······</cpe-lang:logical-test>116 ······</cpe-lang:logical-test>
122 ····</cpe-lang:platform>117 ····</cpe-lang:platform>
123 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">118 ····<cpe-lang:platform·id="package_shadow-utils">
124 ······<cpe-lang:logical-test·operator="AND"·negate="false">119 ······<cpe-lang:logical-test·operator="AND"·negate="false">
125 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
126 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
127 ········</cpe-lang:logical-test> 
128 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
129 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
130 ········</cpe-lang:logical-test> 
131 ······</cpe-lang:logical-test>121 ······</cpe-lang:logical-test>
132 ····</cpe-lang:platform>122 ····</cpe-lang:platform>
133 ····<cpe-lang:platform·id="mount_home">123 ····<cpe-lang:platform·id="mount_var">
134 ······<cpe-lang:logical-test·operator="AND"·negate="false">124 ······<cpe-lang:logical-test·operator="AND"·negate="false">
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
136 ······</cpe-lang:logical-test>126 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>127 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="mount_var-tmp">128 ····<cpe-lang:platform·id="system_with_kernel">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">129 ······<cpe-lang:logical-test·operator="AND"·negate="false">
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
141 ······</cpe-lang:logical-test>131 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>132 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="mount_var-log">133 ····<cpe-lang:platform·id="package_chrony">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">134 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
146 ······</cpe-lang:logical-test>136 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>137 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">138 ····<cpe-lang:platform·id="mount_tmp">
149 ······<cpe-lang:logical-test·operator="AND"·negate="false">139 ······<cpe-lang:logical-test·operator="AND"·negate="false">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
152 ······</cpe-lang:logical-test>141 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>142 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">143 ····<cpe-lang:platform·id="not_container">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="AND"·negate="true">
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/> 
159 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">148 ····<cpe-lang:platform·id="package_ufw">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
164 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
165 ········</cpe-lang:logical-test> 
166 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
167 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
168 ········</cpe-lang:logical-test> 
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
170 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">153 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
176 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
177 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
178 ····<cpe-lang:platform·id="wifi-iface">159 ····<cpe-lang:platform·id="mount_var-log-audit">
179 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/>
181 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
182 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
183 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel">164 ····<cpe-lang:platform·id="package_systemd-timesyncd">
184 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
185 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_systemd-timesyncd:def:1"/>
186 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
187 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
188 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
189 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
190 ····<cpe-lang:platform·id="service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel">169 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">
191 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
192 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_iptables:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
193 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
194 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ubuntu2404-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
195 ······</cpe-lang:logical-test>173 ······</cpe-lang:logical-test>
196 ····</cpe-lang:platform>174 ····</cpe-lang:platform>
Max diff block lines reached; 155551/170555 bytes (91.20%) of diff not shown.
5.9 MB
ssg-debian_0.1.76-1_all.deb
367 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0·····1976·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0·····1976·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0··1228524·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0··1228136·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
5.9 MB
data.tar.xz
5.9 MB
data.tar
90.0 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_average.html
    
Offset 20653, 140 lines modifiedOffset 20653, 140 lines modified
00050ac0:·6765·743d·2223·6964·6d35·3337·3622·2074··get="#idm5376"·t00050ac0:·6765·743d·2223·6964·6d35·3337·3622·2074··get="#idm5376"·t
00050ad0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00050ad0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00050ae0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00050ae0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00050af0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00050af0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00050b00:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00050b00:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00050b10:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00050b10:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00050b20:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00050b20:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 00050b30:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 00050b40:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00050b50:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00050b60:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00050b70:·3d22·6964·6d35·3337·3622·3e3c·7461·626c··="idm5376"><tabl
 00050b80:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00050b90:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00050ba0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00050bb0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00050bc0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00050bd0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00050be0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00050bf0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
00050b30:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
00050b40:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
00050b50:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00050b60:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00050b70:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00050b80:·646d·3533·3736·223e·3c70·7265·3e3c·636f··dm5376"><pre><co 
00050b90:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
00050ba0:·0a6e·616d·6520·3d20·2273·7973·6c6f·672d··.name·=·"syslog- 
00050bb0:·6e67·220a·7665·7273·696f·6e20·3d20·222a··ng".version·=·"* 
00050bc0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
00050bd0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00050be0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00050bf0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00050c00:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00050c10:·6574·3d22·2369·646d·3533·3737·2220·7461··et="#idm5377"·ta 
00050c20:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00050c30:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00050c40:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00050c50:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00050c60:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00050c70:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00050c80:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
00050c90:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00050ca0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00050cb0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00050cc0:·2269·646d·3533·3737·223e·3c74·6162·6c65··"idm5377"><table 
00050cd0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
00050ce0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
00050cf0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
00050d00:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
00050d10:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
00050d20:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00050d30:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
00050d40:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
00050d50:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00050d60:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
00050d70:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
00050d80:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
00050d90:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
00050da0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><00050c00:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00050db0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
00050dc0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
00050dd0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
00050de0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
00050df0:·6174·666f·726d·730a·6966·2064·706b·672d··atforms.if·dpkg- 
00050e00:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s 
00050e10:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db: 
00050e20:·5374·6174·7573·2d53·7461·7475·737d·0a27··Status-Status}.' 
00050e30:·2027·6c69·6e75·782d·6261·7365·2720·3226···'linux-base'·2& 
00050e40:·6774·3b2f·6465·762f·6e75·6c6c·207c·2067··gt;/dev/null·|·g 
00050e50:·7265·7020·2d71·205e·696e·7374·616c·6c65··rep·-q·^installe00050c10:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 00050c20:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 00050c30:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00050c40:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00050c50:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 00050c60:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 00050c70:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 00050c80:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 00050c90:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 00050ca0:·6c61·7466·6f72·6d73·0a69·6620·6470·6b67··latforms.if·dpkg
 00050cb0:·2d71·7565·7279·202d·2d73·686f·7720·2d2d··-query·--show·--
 00050cc0:·7368·6f77·666f·726d·6174·3d27·247b·6462··showformat='${db
 00050cd0:·3a53·7461·7475·732d·5374·6174·7573·7d0a··:Status-Status}.
 00050ce0:·2720·276c·696e·7578·2d62·6173·6527·2032··'·'linux-base'·2
 00050cf0:·2667·743b·2f64·6576·2f6e·756c·6c20·7c20··&gt;/dev/null·|·
 00050d00:·6772·6570·202d·7120·5e69·6e73·7461·6c6c··grep·-q·^install
00050e60:·643b·2074·6865·6e0a·0a44·4542·4941·4e5f··d;·then..DEBIAN_00050d10:·6564·3b20·7468·656e·0a0a·4445·4249·414e··ed;·then..DEBIAN
00050e70:·4652·4f4e·5445·4e44·3d6e·6f6e·696e·7465··FRONTEND=noninte 
00050e80:·7261·6374·6976·6520·6170·742d·6765·7420··ractive·apt-get· 
00050e90:·696e·7374·616c·6c20·2d79·2022·7379·736c··install·-y·"sysl 
00050ea0:·6f67·2d6e·6722·0a0a·656c·7365·0a20·2020··og-ng"..else.··· 
00050eb0:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
00050ec0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
00050ed0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
00050ee0:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
00050ef0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
00050f00:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
00050f10:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
00050f20:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
00050f30:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
00050f40:·7461·7267·6574·3d22·2369·646d·3533·3738··target="#idm5378 
00050f50:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
00050f60:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
00050f70:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
00050f80:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
00050f90:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
00050fa0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
00050fb0:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip00050d20:·5f46·524f·4e54·454e·443d·6e6f·6e69·6e74··_FRONTEND=nonint
 00050d30:·6572·6163·7469·7665·2061·7074·2d67·6574··eractive·apt-get
 00050d40:·2069·6e73·7461·6c6c·202d·7920·2273·7973···install·-y·"sys
 00050d50:·6c6f·672d·6e67·220a·0a65·6c73·650a·2020··log-ng"..else.··
 00050d60:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 00050d70:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 00050d80:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 00050d90:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 00050da0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 00050db0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00050dc0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00050dd0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 00050de0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 00050df0:·2d74·6172·6765·743d·2223·6964·6d35·3337··-target="#idm537
 00050e00:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·
 00050e10:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 00050e20:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 00050e30:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 00050e40:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 00050e50:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
Max diff block lines reached; 65800/83768 bytes (78.55%) of diff not shown.
8.01 KB
html2text {}
    
Offset 1816, 19 lines modifiedOffset 1816, 14 lines modified
1816 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-0013121816 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312
1817 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,1817 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
1818 References:················4.4.2.41818 References:················4.4.2.4
1819 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91819 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1820 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11820 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1821 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1821 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1822 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11822 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1823 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1824 [[packages]] 
1825 name·=·"syslog-ng" 
1826 version·=·"*" 
1827 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81823 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1828 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1824 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1829 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1825 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1830 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1826 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1831 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1827 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1832 #·Remediation·is·applicable·only·in·certain·platforms1828 #·Remediation·is·applicable·only·in·certain·platforms
1833 if·dpkg-query·--show·--showformat='${db:Status-Status}1829 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1865, 14 lines modifiedOffset 1860, 19 lines modified
1865 ··-·NIST-800-53-CM-6(a)1860 ··-·NIST-800-53-CM-6(a)
1866 ··-·enable_strategy1861 ··-·enable_strategy
1867 ··-·low_complexity1862 ··-·low_complexity
1868 ··-·low_disruption1863 ··-·low_disruption
1869 ··-·medium_severity1864 ··-·medium_severity
1870 ··-·no_reboot_needed1865 ··-·no_reboot_needed
1871 ··-·package_syslogng_installed1866 ··-·package_syslogng_installed
 1867 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1868 [[packages]]
 1869 name·=·"syslog-ng"
 1870 version·=·"*"
1872 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81871 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1873 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1872 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1874 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1873 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1875 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1874 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1876 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1875 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1877 include·install_syslog-ng1876 include·install_syslog-ng
  
Offset 1900, 18 lines modifiedOffset 1900, 14 lines modified
1900 ···························4.4.2.2,·4.4.2.41900 ···························4.4.2.2,·4.4.2.4
1901 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,1901 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
1902 ···························SR·6.2,·SR·7.1,·SR·7.21902 ···························SR·6.2,·SR·7.1,·SR·7.2
1903 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,1903 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
1904 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11904 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1905 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1905 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1906 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11906 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1908 [customizations.services] 
1909 enabled·=·["syslog-ng"] 
1910 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1911 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1912 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1913 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1914 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1915 -·name:·Gather·the·package·facts1912 -·name:·Gather·the·package·facts
1916 ··package_facts:1913 ··package_facts:
Offset 1947, 14 lines modifiedOffset 1943, 18 lines modified
1947 ··-·NIST-800-53-CM-6(a)1943 ··-·NIST-800-53-CM-6(a)
1948 ··-·enable_strategy1944 ··-·enable_strategy
1949 ··-·low_complexity1945 ··-·low_complexity
1950 ··-·low_disruption1946 ··-·low_disruption
1951 ··-·medium_severity1947 ··-·medium_severity
1952 ··-·no_reboot_needed1948 ··-·no_reboot_needed
1953 ··-·service_syslogng_enabled1949 ··-·service_syslogng_enabled
 1950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1951 [customizations.services]
 1952 enabled·=·["syslog-ng"]
1954 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1955 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1954 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1956 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1955 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1957 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1956 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1958 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1957 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1959 include·enable_syslog-ng1958 include·enable_syslog-ng
  
Offset 1980, 19 lines modifiedOffset 1980, 14 lines modified
1980 References:················4.4.2.41980 References:················4.4.2.4
1981 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91981 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1982 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11982 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1983 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1983 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1984 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11984 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1985 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1985 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1986 ···························SRG-OS-000480-GPOS-002271986 ···························SRG-OS-000480-GPOS-00227
1987 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1988 [[packages]] 
1989 name·=·"rsyslog" 
1990 version·=·"*" 
1991 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81987 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1992 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1988 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1993 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1989 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1994 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1990 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1995 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1991 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1996 #·Remediation·is·applicable·only·in·certain·platforms1992 #·Remediation·is·applicable·only·in·certain·platforms
1997 if·dpkg-query·--show·--showformat='${db:Status-Status}1993 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2029, 14 lines modifiedOffset 2024, 19 lines modified
2029 ··-·NIST-800-53-CM-6(a)2024 ··-·NIST-800-53-CM-6(a)
2030 ··-·enable_strategy2025 ··-·enable_strategy
2031 ··-·low_complexity2026 ··-·low_complexity
2032 ··-·low_disruption2027 ··-·low_disruption
2033 ··-·medium_severity2028 ··-·medium_severity
2034 ··-·no_reboot_needed2029 ··-·no_reboot_needed
2035 ··-·package_rsyslog_installed2030 ··-·package_rsyslog_installed
 2031 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2032 [[packages]]
 2033 name·=·"rsyslog"
 2034 version·=·"*"
2036 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82035 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2037 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2036 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2038 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2037 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2039 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2038 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2040 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2039 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2041 include·install_rsyslog2040 include·install_rsyslog
  
Offset 2065, 18 lines modifiedOffset 2065, 14 lines modified
2065 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,2065 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
2066 ···························SR·6.2,·SR·7.1,·SR·7.22066 ···························SR·6.2,·SR·7.1,·SR·7.2
2067 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,2067 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
2068 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.12068 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
2069 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)2069 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
2070 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-12070 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
2071 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272071 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2072 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 2429/8183 bytes (29.68%) of diff not shown.
170 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_high.html
    
Offset 21243, 140 lines modifiedOffset 21243, 140 lines modified
00052fa0:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm500052fa0:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
00052fb0:·3337·3622·2074·6162·696e·6465·783d·2230··376"·tabindex="000052fb0:·3337·3622·2074·6162·696e·6465·783d·2230··376"·tabindex="0
00052fc0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00052fc0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00052fd0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00052fd0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00052fe0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00052fe0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00052ff0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00052ff0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00053000:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00053000:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00053010:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B00053010:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 00053020:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
00053020:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
00053030:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00053040:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00053050:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00053060:·2069·643d·2269·646d·3533·3736·223e·3c70···id="idm5376"><p 
00053070:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
00053080:·6167·6573·5d5d·0a6e·616d·6520·3d20·2273··ages]].name·=·"s 
00053090:·7973·6c6f·672d·6e67·220a·7665·7273·696f··yslog-ng".versio 
000530a0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
000530b0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
000530c0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
000530d0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
000530e0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
000530f0:·612d·7461·7267·6574·3d22·2369·646d·3533··a-target="#idm53 
00053100:·3737·2220·7461·6269·6e64·6578·3d22·3022··77"·tabindex="0" 
00053110:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00053120:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00053130:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00053140:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
00053150:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
00053160:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
00053170:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
00053180:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-00053030:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00053190:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
000531a0:·6522·2069·643d·2269·646d·3533·3737·223e··e"·id="idm5377"> 
000531b0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
000531c0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe00053040:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00053050:·7365·2220·6964·3d22·6964·6d35·3337·3622··se"·id="idm5376"
 00053060:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00053070:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00053080:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
000531d0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered00053090:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
000531e0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
000531f0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
00053200:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
00053210:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00053220:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
00053230:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00053240:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
00053250:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals000530a0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 000530b0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 000530c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 000530d0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 000530e0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 000530f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 00053100:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 00053110:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 00053120:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 00053130:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 00053140:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00053150:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 00053160:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 00053170:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 00053180:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 00053190:·6620·6470·6b67·2d71·7565·7279·202d·2d73··f·dpkg-query·--s
 000531a0:·686f·7720·2d2d·7368·6f77·666f·726d·6174··how·--showformat
 000531b0:·3d27·247b·6462·3a53·7461·7475·732d·5374··='${db:Status-St
 000531c0:·6174·7573·7d0a·2720·276c·696e·7578·2d62··atus}.'·'linux-b
 000531d0:·6173·6527·2032·2667·743b·2f64·6576·2f6e··ase'·2&gt;/dev/n
 000531e0:·756c·6c20·7c20·6772·6570·202d·7120·5e69··ull·|·grep·-q·^i
 000531f0:·6e73·7461·6c6c·6564·3b20·7468·656e·0a0a··nstalled;·then..
 00053200:·4445·4249·414e·5f46·524f·4e54·454e·443d··DEBIAN_FRONTEND=
 00053210:·6e6f·6e69·6e74·6572·6163·7469·7665·2061··noninteractive·a
 00053220:·7074·2d67·6574·2069·6e73·7461·6c6c·202d··pt-get·install·-
 00053230:·7920·2273·7973·6c6f·672d·6e67·220a·0a65··y·"syslog-ng"..e
 00053240:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp
 00053250:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia
 00053260:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl
 00053270:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·
 00053280:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c
 00053290:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 000532a0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 000532b0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 000532c0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 000532d0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 000532e0:·6964·6d35·3337·3722·2074·6162·696e·6465··idm5377"·tabinde
 000532f0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 00053300:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 00053310:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 00053320:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 00053330:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 00053340:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib
 00053350:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</
 00053360:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00053370:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00053380:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00053390:·646d·3533·3737·223e·3c74·6162·6c65·2063··dm5377"><table·c
 000533a0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 000533b0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 000533c0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 000533d0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 000533e0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 000533f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00053400:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 00053410:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 00053420:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00053430:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 00053440:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 00053450:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 00053460:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
00053260:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><00053470:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
00053270:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00053280:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00053290:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
000532a0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
000532b0:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
000532c0:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
000532d0:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
000532e0:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh 
000532f0:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat= 
00053300:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta 
00053310:·7475·737d·0a27·2027·6c69·6e75·782d·6261··tus}.'·'linux-ba 
00053320:·7365·2720·3226·6774·3b2f·6465·762f·6e75··se'·2&gt;/dev/nu 
00053330:·6c6c·207c·2067·7265·7020·2d71·205e·696e··ll·|·grep·-q·^in 
00053340:·7374·616c·6c65·643b·2074·6865·6e0a·0a44··stalled;·then..D 
00053350:·4542·4941·4e5f·4652·4f4e·5445·4e44·3d6e··EBIAN_FRONTEND=n 
00053360:·6f6e·696e·7465·7261·6374·6976·6520·6170··oninteractive·ap 
00053370:·742d·6765·7420·696e·7374·616c·6c20·2d79··t-get·install·-y 
Max diff block lines reached; 141536/159504 bytes (88.74%) of diff not shown.
14.1 KB
html2text {}
    
Offset 2008, 19 lines modifiedOffset 2008, 14 lines modified
2008 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-0013122008 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312
2009 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,2009 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
2010 References:················4.4.2.42010 References:················4.4.2.4
2011 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.92011 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
2012 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.12012 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
2013 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)2013 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
2014 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-12014 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
2015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2016 [[packages]] 
2017 name·=·"syslog-ng" 
2018 version·=·"*" 
2019 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2020 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2016 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2021 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2017 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2022 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2018 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2023 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2019 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2024 #·Remediation·is·applicable·only·in·certain·platforms2020 #·Remediation·is·applicable·only·in·certain·platforms
2025 if·dpkg-query·--show·--showformat='${db:Status-Status}2021 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2057, 14 lines modifiedOffset 2052, 19 lines modified
2057 ··-·NIST-800-53-CM-6(a)2052 ··-·NIST-800-53-CM-6(a)
2058 ··-·enable_strategy2053 ··-·enable_strategy
2059 ··-·low_complexity2054 ··-·low_complexity
2060 ··-·low_disruption2055 ··-·low_disruption
2061 ··-·medium_severity2056 ··-·medium_severity
2062 ··-·no_reboot_needed2057 ··-·no_reboot_needed
2063 ··-·package_syslogng_installed2058 ··-·package_syslogng_installed
 2059 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2060 [[packages]]
 2061 name·=·"syslog-ng"
 2062 version·=·"*"
2064 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82063 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2065 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2064 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2066 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2065 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2067 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2066 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2068 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2067 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2069 include·install_syslog-ng2068 include·install_syslog-ng
  
Offset 2092, 18 lines modifiedOffset 2092, 14 lines modified
2092 ···························4.4.2.2,·4.4.2.42092 ···························4.4.2.2,·4.4.2.4
2093 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,2093 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
2094 ···························SR·6.2,·SR·7.1,·SR·7.22094 ···························SR·6.2,·SR·7.1,·SR·7.2
2095 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,2095 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
2096 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.12096 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
2097 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)2097 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
2098 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-12098 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
2099 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2100 [customizations.services] 
2101 enabled·=·["syslog-ng"] 
2102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82099 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2103 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2100 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2104 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2101 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2105 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2102 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2106 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2103 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2107 -·name:·Gather·the·package·facts2104 -·name:·Gather·the·package·facts
2108 ··package_facts:2105 ··package_facts:
Offset 2139, 14 lines modifiedOffset 2135, 18 lines modified
2139 ··-·NIST-800-53-CM-6(a)2135 ··-·NIST-800-53-CM-6(a)
2140 ··-·enable_strategy2136 ··-·enable_strategy
2141 ··-·low_complexity2137 ··-·low_complexity
2142 ··-·low_disruption2138 ··-·low_disruption
2143 ··-·medium_severity2139 ··-·medium_severity
2144 ··-·no_reboot_needed2140 ··-·no_reboot_needed
2145 ··-·service_syslogng_enabled2141 ··-·service_syslogng_enabled
 2142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2143 [customizations.services]
 2144 enabled·=·["syslog-ng"]
2146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2151 include·enable_syslog-ng2150 include·enable_syslog-ng
  
Offset 2172, 19 lines modifiedOffset 2172, 14 lines modified
2172 References:················4.4.2.42172 References:················4.4.2.4
2173 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.92173 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
2174 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.12174 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
2175 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)2175 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
2176 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-12176 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
2177 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,2177 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
2178 ···························SRG-OS-000480-GPOS-002272178 ···························SRG-OS-000480-GPOS-00227
2179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2180 [[packages]] 
2181 name·=·"rsyslog" 
2182 version·=·"*" 
2183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2188 #·Remediation·is·applicable·only·in·certain·platforms2184 #·Remediation·is·applicable·only·in·certain·platforms
2189 if·dpkg-query·--show·--showformat='${db:Status-Status}2185 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2221, 14 lines modifiedOffset 2216, 19 lines modified
2221 ··-·NIST-800-53-CM-6(a)2216 ··-·NIST-800-53-CM-6(a)
2222 ··-·enable_strategy2217 ··-·enable_strategy
2223 ··-·low_complexity2218 ··-·low_complexity
2224 ··-·low_disruption2219 ··-·low_disruption
2225 ··-·medium_severity2220 ··-·medium_severity
2226 ··-·no_reboot_needed2221 ··-·no_reboot_needed
2227 ··-·package_rsyslog_installed2222 ··-·package_rsyslog_installed
 2223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2224 [[packages]]
 2225 name·=·"rsyslog"
 2226 version·=·"*"
2228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2229 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2230 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2231 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2230 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2232 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2231 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2233 include·install_rsyslog2232 include·install_rsyslog
  
Offset 2257, 18 lines modifiedOffset 2257, 14 lines modified
2257 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,2257 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
2258 ···························SR·6.2,·SR·7.1,·SR·7.22258 ···························SR·6.2,·SR·7.1,·SR·7.2
2259 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,2259 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
2260 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.12260 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
2261 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)2261 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
2262 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-12262 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
2263 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272263 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2264 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 8664/14418 bytes (60.09%) of diff not shown.
70.1 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_minimal.html
    
Offset 15651, 141 lines modifiedOffset 15651, 141 lines modified
0003d220:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003d220:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003d230:·743d·2223·6964·6d35·3337·3622·2074·6162··t="#idm5376"·tab0003d230:·743d·2223·6964·6d35·3337·3622·2074·6162··t="#idm5376"·tab
0003d240:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003d240:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003d250:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003d250:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003d260:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003d260:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003d270:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003d270:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003d280:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003d280:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003d290:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003d290:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 0003d2a0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 0003d2b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003d2c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003d2d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003d2e0:·6964·6d35·3337·3622·3e3c·7461·626c·6520··idm5376"><table·
 0003d2f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003d300:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003d310:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003d320:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003d330:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003d340:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003d350:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003d360:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003d2a0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003d2b0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003d2c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003d2d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003d2e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003d2f0:·3533·3736·223e·3c70·7265·3e3c·636f·6465··5376"><pre><code 
0003d300:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003d310:·616d·6520·3d20·2273·7973·6c6f·672d·6e67··ame·=·"syslog-ng 
0003d320:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003d330:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003d340:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003d350:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003d360:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003d370:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003d380:·3d22·2369·646d·3533·3737·2220·7461·6269··="#idm5377"·tabi 
0003d390:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003d3a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003d3b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003d3c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003d3d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003d3e0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003d3f0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003d400:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003d410:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003d420:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003d430:·646d·3533·3737·223e·3c74·6162·6c65·2063··dm5377"><table·c 
0003d440:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003d450:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003d460:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003d470:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003d480:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003d490:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003d4a0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003d4b0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003d4c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003d4d0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003d4e0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003d4f0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003d500:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003d510:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003d370:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003d520:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003d530:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003d540:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003d550:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003d560:·666f·726d·730a·6966·2064·706b·672d·7175··forms.if·dpkg-qu 
0003d570:·6572·7920·2d2d·7368·6f77·202d·2d73·686f··ery·--show·--sho 
0003d580:·7766·6f72·6d61·743d·2724·7b64·623a·5374··wformat='${db:St 
0003d590:·6174·7573·2d53·7461·7475·737d·0a27·2027··atus-Status}.'·' 
0003d5a0:·6c69·6e75·782d·6261·7365·2720·3226·6774··linux-base'·2&gt 
0003d5b0:·3b2f·6465·762f·6e75·6c6c·207c·2067·7265··;/dev/null·|·gre 
0003d5c0:·7020·2d71·205e·696e·7374·616c·6c65·643b··p·-q·^installed;0003d380:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003d390:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003d3a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003d3b0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003d3c0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003d3d0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003d3e0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003d3f0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003d400:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003d410:·7466·6f72·6d73·0a69·6620·6470·6b67·2d71··tforms.if·dpkg-q
 0003d420:·7565·7279·202d·2d73·686f·7720·2d2d·7368··uery·--show·--sh
 0003d430:·6f77·666f·726d·6174·3d27·247b·6462·3a53··owformat='${db:S
 0003d440:·7461·7475·732d·5374·6174·7573·7d0a·2720··tatus-Status}.'·
 0003d450:·276c·696e·7578·2d62·6173·6527·2032·2667··'linux-base'·2&g
 0003d460:·743b·2f64·6576·2f6e·756c·6c20·7c20·6772··t;/dev/null·|·gr
 0003d470:·6570·202d·7120·5e69·6e73·7461·6c6c·6564··ep·-q·^installed
0003d5d0:·2074·6865·6e0a·0a44·4542·4941·4e5f·4652···then..DEBIAN_FR0003d480:·3b20·7468·656e·0a0a·4445·4249·414e·5f46··;·then..DEBIAN_F
0003d5e0:·4f4e·5445·4e44·3d6e·6f6e·696e·7465·7261··ONTEND=nonintera 
0003d5f0:·6374·6976·6520·6170·742d·6765·7420·696e··ctive·apt-get·in 
0003d600:·7374·616c·6c20·2d79·2022·7379·736c·6f67··stall·-y·"syslog 
0003d610:·2d6e·6722·0a0a·656c·7365·0a20·2020·2026··-ng"..else.····& 
0003d620:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003d630:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003d640:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003d650:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003d660:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003d670:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003d680:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003d490:·524f·4e54·454e·443d·6e6f·6e69·6e74·6572··RONTEND=noninter
 0003d4a0:·6163·7469·7665·2061·7074·2d67·6574·2069··active·apt-get·i
 0003d4b0:·6e73·7461·6c6c·202d·7920·2273·7973·6c6f··nstall·-y·"syslo
 0003d4c0:·672d·6e67·220a·0a65·6c73·650a·2020·2020··g-ng"..else.····
 0003d4d0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003d4e0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003d4f0:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003d500:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 0003d510:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
 0003d520:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 0003d530:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003d690:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003d540:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003d6a0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003d6b0:·7267·6574·3d22·2369·646d·3533·3738·2220··rget="#idm5378"· 
0003d6c0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003d6d0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003d6e0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003d6f0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003d700:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003d710:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003d720:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe0003d550:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 0003d560:·6172·6765·743d·2223·6964·6d35·3337·3722··arget="#idm5377"
 0003d570:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 0003d580:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 0003d590:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 0003d5a0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 0003d5b0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 0003d5c0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003d5d0:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
Max diff block lines reached; 47004/65110 bytes (72.19%) of diff not shown.
6.42 KB
html2text {}
    
Offset 276, 19 lines modifiedOffset 276, 14 lines modified
276 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312276 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312
277 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,277 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
278 References:················4.4.2.4278 References:················4.4.2.4
279 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9279 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
280 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1280 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
281 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)281 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
282 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1282 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
284 [[packages]] 
285 name·=·"syslog-ng" 
286 version·=·"*" 
287 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
288 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low284 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
289 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low285 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
290 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false286 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
291 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable287 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
292 #·Remediation·is·applicable·only·in·certain·platforms288 #·Remediation·is·applicable·only·in·certain·platforms
293 if·dpkg-query·--show·--showformat='${db:Status-Status}289 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 325, 14 lines modifiedOffset 320, 19 lines modified
325 ··-·NIST-800-53-CM-6(a)320 ··-·NIST-800-53-CM-6(a)
326 ··-·enable_strategy321 ··-·enable_strategy
327 ··-·low_complexity322 ··-·low_complexity
328 ··-·low_disruption323 ··-·low_disruption
329 ··-·medium_severity324 ··-·medium_severity
330 ··-·no_reboot_needed325 ··-·no_reboot_needed
331 ··-·package_syslogng_installed326 ··-·package_syslogng_installed
 327 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 328 [[packages]]
 329 name·=·"syslog-ng"
 330 version·=·"*"
332 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8331 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
333 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low332 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
334 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low333 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
335 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false334 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
336 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable335 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
337 include·install_syslog-ng336 include·install_syslog-ng
  
Offset 360, 18 lines modifiedOffset 360, 14 lines modified
360 ···························4.4.2.2,·4.4.2.4360 ···························4.4.2.2,·4.4.2.4
361 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,361 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
362 ···························SR·6.2,·SR·7.1,·SR·7.2362 ···························SR·6.2,·SR·7.1,·SR·7.2
363 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,363 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
364 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1364 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
365 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)365 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
366 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1366 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
368 [customizations.services] 
369 enabled·=·["syslog-ng"] 
370 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
371 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low368 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
372 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low369 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
373 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false370 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
374 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable371 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
375 -·name:·Gather·the·package·facts372 -·name:·Gather·the·package·facts
376 ··package_facts:373 ··package_facts:
Offset 407, 14 lines modifiedOffset 403, 18 lines modified
407 ··-·NIST-800-53-CM-6(a)403 ··-·NIST-800-53-CM-6(a)
408 ··-·enable_strategy404 ··-·enable_strategy
409 ··-·low_complexity405 ··-·low_complexity
410 ··-·low_disruption406 ··-·low_disruption
411 ··-·medium_severity407 ··-·medium_severity
412 ··-·no_reboot_needed408 ··-·no_reboot_needed
413 ··-·service_syslogng_enabled409 ··-·service_syslogng_enabled
 410 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 411 [customizations.services]
 412 enabled·=·["syslog-ng"]
414 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
415 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low414 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
416 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low415 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
417 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false416 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
418 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable417 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
419 include·enable_syslog-ng418 include·enable_syslog-ng
  
Offset 440, 19 lines modifiedOffset 440, 14 lines modified
440 References:················4.4.2.4440 References:················4.4.2.4
441 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9441 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
442 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1442 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
443 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)443 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
444 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1444 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
445 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,445 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
446 ···························SRG-OS-000480-GPOS-00227446 ···························SRG-OS-000480-GPOS-00227
447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
448 [[packages]] 
449 name·=·"rsyslog" 
450 version·=·"*" 
451 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
452 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low448 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
453 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low449 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
454 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false450 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
455 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable451 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
456 #·Remediation·is·applicable·only·in·certain·platforms452 #·Remediation·is·applicable·only·in·certain·platforms
457 if·dpkg-query·--show·--showformat='${db:Status-Status}453 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 489, 14 lines modifiedOffset 484, 19 lines modified
489 ··-·NIST-800-53-CM-6(a)484 ··-·NIST-800-53-CM-6(a)
490 ··-·enable_strategy485 ··-·enable_strategy
491 ··-·low_complexity486 ··-·low_complexity
492 ··-·low_disruption487 ··-·low_disruption
493 ··-·medium_severity488 ··-·medium_severity
494 ··-·no_reboot_needed489 ··-·no_reboot_needed
495 ··-·package_rsyslog_installed490 ··-·package_rsyslog_installed
 491 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 492 [[packages]]
 493 name·=·"rsyslog"
 494 version·=·"*"
496 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8495 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
497 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low496 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
498 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low497 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
499 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false498 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
500 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable499 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
501 include·install_rsyslog500 include·install_rsyslog
  
Offset 525, 18 lines modifiedOffset 525, 14 lines modified
525 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,525 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
526 ···························SR·6.2,·SR·7.1,·SR·7.2526 ···························SR·6.2,·SR·7.1,·SR·7.2
527 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,527 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
528 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1528 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
529 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)529 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
530 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1530 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
531 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227531 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
532 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 813/6553 bytes (12.41%) of diff not shown.
170 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-anssi_np_nt28_restrictive.html
    
Offset 20663, 141 lines modifiedOffset 20663, 141 lines modified
00050b60:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00050b60:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00050b70:·2223·6964·6d35·3337·3622·2074·6162·696e··"#idm5376"·tabin00050b70:·2223·6964·6d35·3337·3622·2074·6162·696e··"#idm5376"·tabin
00050b80:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00050b80:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00050b90:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00050b90:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00050ba0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00050ba0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00050bb0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00050bb0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00050bc0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00050bc0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00050bd0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB00050bd0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
00050be0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
00050bf0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00050c00:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00050c10:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00050c20:·6c61·7073·6522·2069·643d·2269·646d·3533··lapse"·id="idm5300050be0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 00050bf0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00050c00:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00050c10:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00050c20:·6d35·3337·3622·3e3c·7461·626c·6520·636c··m5376"><table·cl
 00050c30:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00050c40:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 00050c50:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 00050c60:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00050c70:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 00050c80:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00050c90:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00050ca0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00050cb0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00050cc0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00050cd0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00050ce0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00050cf0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 00050d00:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
00050c30:·3736·223e·3c70·7265·3e3c·636f·6465·3e0a··76"><pre><code>.00050d10:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
00050c40:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
00050c50:·6520·3d20·2273·7973·6c6f·672d·6e67·220a··e·=·"syslog-ng". 
00050c60:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
00050c70:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00050c80:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00050c90:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00050ca0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00050cb0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00050cc0:·2369·646d·3533·3737·2220·7461·6269·6e64··#idm5377"·tabind 
00050cd0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00050ce0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00050cf0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00050d00:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00050d10:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00050d20:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
00050d30:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>00050d20:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 00050d30:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 00050d40:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 00050d50:·6f72·6d73·0a69·6620·6470·6b67·2d71·7565··orms.if·dpkg-que
 00050d60:·7279·202d·2d73·686f·7720·2d2d·7368·6f77··ry·--show·--show
 00050d70:·666f·726d·6174·3d27·247b·6462·3a53·7461··format='${db:Sta
 00050d80:·7475·732d·5374·6174·7573·7d0a·2720·276c··tus-Status}.'·'l
 00050d90:·696e·7578·2d62·6173·6527·2032·2667·743b··inux-base'·2&gt;
 00050da0:·2f64·6576·2f6e·756c·6c20·7c20·6772·6570··/dev/null·|·grep
 00050db0:·202d·7120·5e69·6e73·7461·6c6c·6564·3b20···-q·^installed;·
 00050dc0:·7468·656e·0a0a·4445·4249·414e·5f46·524f··then..DEBIAN_FRO
 00050dd0:·4e54·454e·443d·6e6f·6e69·6e74·6572·6163··NTEND=noninterac
 00050de0:·7469·7665·2061·7074·2d67·6574·2069·6e73··tive·apt-get·ins
 00050df0:·7461·6c6c·202d·7920·2273·7973·6c6f·672d··tall·-y·"syslog-
 00050e00:·6e67·220a·0a65·6c73·650a·2020·2020·2667··ng"..else.····&g
 00050e10:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 00050e20:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 00050e30:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 00050e40:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 00050e50:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
00050d40:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00050e60:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
00050d50:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
00050d60:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
00050d70:·3533·3737·223e·3c74·6162·6c65·2063·6c61··5377"><table·cla 
00050d80:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
00050d90:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
00050da0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
00050db0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
00050dc0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
00050dd0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00050de0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
00050df0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
00050e00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00050e10:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t00050e70:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 00050e80:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 00050e90:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 00050ea0:·6765·743d·2223·6964·6d35·3337·3722·2074··get="#idm5377"·t
 00050eb0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 00050ec0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 00050ed0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 00050ee0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 00050ef0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 00050f00:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 00050f10:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
 00050f20:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00050f30:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00050f40:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00050f50:·2069·643d·2269·646d·3533·3737·223e·3c74···id="idm5377"><t
 00050f60:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00050f70:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00050f80:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00050f90:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00050fa0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 00050fb0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00050fc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00050fd0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00050fe0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00050ff0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00051000:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 00051010:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00051020:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00050e20:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr00051030:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
00050e30:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
00050e40:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
00050e50:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
00050e60:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
00050e70:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
00050e80:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
00050e90:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
00050ea0:·726d·730a·6966·2064·706b·672d·7175·6572··rms.if·dpkg-quer 
00050eb0:·7920·2d2d·7368·6f77·202d·2d73·686f·7766··y·--show·--showf 
00050ec0:·6f72·6d61·743d·2724·7b64·623a·5374·6174··ormat='${db:Stat 
00050ed0:·7573·2d53·7461·7475·737d·0a27·2027·6c69··us-Status}.'·'li 
00050ee0:·6e75·782d·6261·7365·2720·3226·6774·3b2f··nux-base'·2&gt;/ 
00050ef0:·6465·762f·6e75·6c6c·207c·2067·7265·7020··dev/null·|·grep· 
00050f00:·2d71·205e·696e·7374·616c·6c65·643b·2074··-q·^installed;·t 
00050f10:·6865·6e0a·0a44·4542·4941·4e5f·4652·4f4e··hen..DEBIAN_FRON 
00050f20:·5445·4e44·3d6e·6f6e·696e·7465·7261·6374··TEND=noninteract 
00050f30:·6976·6520·6170·742d·6765·7420·696e·7374··ive·apt-get·inst 
00050f40:·616c·6c20·2d79·2022·7379·736c·6f67·2d6e··all·-y·"syslog-n 
Max diff block lines reached; 141536/159642 bytes (88.66%) of diff not shown.
14.1 KB
html2text {}
    
Offset 1818, 19 lines modifiedOffset 1818, 14 lines modified
1818 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-0013121818 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312
1819 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,1819 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
1820 References:················4.4.2.41820 References:················4.4.2.4
1821 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91821 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1822 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11822 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1823 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1823 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1824 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11824 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1825 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1826 [[packages]] 
1827 name·=·"syslog-ng" 
1828 version·=·"*" 
1829 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81825 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1830 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1826 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1831 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1827 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1832 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1828 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1833 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1829 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1834 #·Remediation·is·applicable·only·in·certain·platforms1830 #·Remediation·is·applicable·only·in·certain·platforms
1835 if·dpkg-query·--show·--showformat='${db:Status-Status}1831 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1867, 14 lines modifiedOffset 1862, 19 lines modified
1867 ··-·NIST-800-53-CM-6(a)1862 ··-·NIST-800-53-CM-6(a)
1868 ··-·enable_strategy1863 ··-·enable_strategy
1869 ··-·low_complexity1864 ··-·low_complexity
1870 ··-·low_disruption1865 ··-·low_disruption
1871 ··-·medium_severity1866 ··-·medium_severity
1872 ··-·no_reboot_needed1867 ··-·no_reboot_needed
1873 ··-·package_syslogng_installed1868 ··-·package_syslogng_installed
 1869 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1870 [[packages]]
 1871 name·=·"syslog-ng"
 1872 version·=·"*"
1874 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81873 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1875 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1874 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1876 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1875 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1877 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1876 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1878 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1877 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1879 include·install_syslog-ng1878 include·install_syslog-ng
  
Offset 1902, 18 lines modifiedOffset 1902, 14 lines modified
1902 ···························4.4.2.2,·4.4.2.41902 ···························4.4.2.2,·4.4.2.4
1903 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,1903 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
1904 ···························SR·6.2,·SR·7.1,·SR·7.21904 ···························SR·6.2,·SR·7.1,·SR·7.2
1905 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,1905 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
1906 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11906 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1907 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1907 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1908 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11908 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1909 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1910 [customizations.services] 
1911 enabled·=·["syslog-ng"] 
1912 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81909 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1913 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1910 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1914 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1911 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1915 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1912 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1916 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1913 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1917 -·name:·Gather·the·package·facts1914 -·name:·Gather·the·package·facts
1918 ··package_facts:1915 ··package_facts:
Offset 1949, 14 lines modifiedOffset 1945, 18 lines modified
1949 ··-·NIST-800-53-CM-6(a)1945 ··-·NIST-800-53-CM-6(a)
1950 ··-·enable_strategy1946 ··-·enable_strategy
1951 ··-·low_complexity1947 ··-·low_complexity
1952 ··-·low_disruption1948 ··-·low_disruption
1953 ··-·medium_severity1949 ··-·medium_severity
1954 ··-·no_reboot_needed1950 ··-·no_reboot_needed
1955 ··-·service_syslogng_enabled1951 ··-·service_syslogng_enabled
 1952 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1953 [customizations.services]
 1954 enabled·=·["syslog-ng"]
1956 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81955 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1957 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1956 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1958 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1957 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1959 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1958 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1960 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1959 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1961 include·enable_syslog-ng1960 include·enable_syslog-ng
  
Offset 1982, 19 lines modifiedOffset 1982, 14 lines modified
1982 References:················4.4.2.41982 References:················4.4.2.4
1983 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91983 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1984 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11984 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1985 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1985 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1986 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11986 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1987 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1987 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1988 ···························SRG-OS-000480-GPOS-002271988 ···························SRG-OS-000480-GPOS-00227
1989 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1990 [[packages]] 
1991 name·=·"rsyslog" 
1992 version·=·"*" 
1993 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81989 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1994 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1990 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1995 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1991 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1996 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1992 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1997 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1993 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1998 #·Remediation·is·applicable·only·in·certain·platforms1994 #·Remediation·is·applicable·only·in·certain·platforms
1999 if·dpkg-query·--show·--showformat='${db:Status-Status}1995 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2031, 14 lines modifiedOffset 2026, 19 lines modified
2031 ··-·NIST-800-53-CM-6(a)2026 ··-·NIST-800-53-CM-6(a)
2032 ··-·enable_strategy2027 ··-·enable_strategy
2033 ··-·low_complexity2028 ··-·low_complexity
2034 ··-·low_disruption2029 ··-·low_disruption
2035 ··-·medium_severity2030 ··-·medium_severity
2036 ··-·no_reboot_needed2031 ··-·no_reboot_needed
2037 ··-·package_rsyslog_installed2032 ··-·package_rsyslog_installed
 2033 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2034 [[packages]]
 2035 name·=·"rsyslog"
 2036 version·=·"*"
2038 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82037 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2039 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2038 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2040 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2039 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2041 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2040 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2042 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2041 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2043 include·install_rsyslog2042 include·install_rsyslog
  
Offset 2067, 18 lines modifiedOffset 2067, 14 lines modified
2067 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,2067 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
2068 ···························SR·6.2,·SR·7.1,·SR·7.22068 ···························SR·6.2,·SR·7.1,·SR·7.2
2069 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,2069 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
2070 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.12070 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
2071 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)2071 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
2072 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-12072 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
2073 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272073 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2074 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 8664/14418 bytes (60.09%) of diff not shown.
150 KB
./usr/share/doc/ssg-debian/ssg-debian11-guide-standard.html
    
Offset 19787, 140 lines modifiedOffset 19787, 140 lines modified
0004d4a0:·612d·7461·7267·6574·3d22·2369·646d·3438··a-target="#idm480004d4a0:·612d·7461·7267·6574·3d22·2369·646d·3438··a-target="#idm48
0004d4b0:·3337·2220·7461·6269·6e64·6578·3d22·3022··37"·tabindex="0"0004d4b0:·3337·2220·7461·6269·6e64·6578·3d22·3022··37"·tabindex="0"
0004d4c0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0004d4c0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0004d4d0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0004d4d0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0004d4e0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0004d4e0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0004d4f0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0004d4f0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0004d500:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0004d500:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0004d510:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
0004d510:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0004d520:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0004d530:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0004d540:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0004d550:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0004d560:·6964·3d22·6964·6d34·3833·3722·3e3c·7072··id="idm4837"><pr 
0004d570:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0004d580:·6765·735d·5d0a·6e61·6d65·203d·2022·7273··ges]].name·=·"rs 
0004d590:·7973·6c6f·6722·0a76·6572·7369·6f6e·203d··yslog".version·= 
0004d5a0:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0004d5b0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0004d5c0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0004d5d0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0004d5e0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0004d5f0:·6172·6765·743d·2223·6964·6d34·3833·3822··arget="#idm4838" 
0004d600:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0004d610:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0004d620:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0004d630:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0004d640:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0004d650:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0004d660:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0004d670:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0004d680:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0004d690:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0004d6a0:·6964·3d22·6964·6d34·3833·3822·3e3c·7461··id="idm4838"><ta 
0004d6b0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0004d6c0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0004d6d0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0004d6e0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0004d6f0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0004d700:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0004d710:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0004d720:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0004d730:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0004d740:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0004d750:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0004d760:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0004d770:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0004d780:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0004d790:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0004d7a0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0004d7b0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0004d7c0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0004d7d0:·2070·6c61·7466·6f72·6d73·0a69·6620·6470···platforms.if·dp 
0004d7e0:·6b67·2d71·7565·7279·202d·2d73·686f·7720··kg-query·--show· 
0004d7f0:·2d2d·7368·6f77·666f·726d·6174·3d27·247b··--showformat='${ 
0004d800:·6462·3a53·7461·7475·732d·5374·6174·7573··db:Status-Status 
0004d810:·7d0a·2720·276c·696e·7578·2d62·6173·6527··}.'·'linux-base' 
0004d820:·2032·2667·743b·2f64·6576·2f6e·756c·6c20···2&gt;/dev/null· 
0004d830:·7c20·6772·6570·202d·7120·5e69·6e73·7461··|·grep·-q·^insta 
0004d840:·6c6c·6564·3b20·7468·656e·0a0a·4445·4249··lled;·then..DEBI 
0004d850:·414e·5f46·524f·4e54·454e·443d·6e6f·6e69··AN_FRONTEND=noni 
0004d860:·6e74·6572·6163·7469·7665·2061·7074·2d67··nteractive·apt-g 
0004d870:·6574·2069·6e73·7461·6c6c·202d·7920·2272··et·install·-y·"r 
0004d880:·7379·736c·6f67·220a·0a65·6c73·650a·2020··syslog"..else.·· 
0004d890:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0004d8a0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0004d8b0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0004d8c0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0004d8d0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0004d8e0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0004d8f0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0004d900:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0004d910:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0004d920:·2d74·6172·6765·743d·2223·6964·6d34·3833··-target="#idm483 
0004d930:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"· 
0004d940:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0004d950:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0004d960:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0004d970:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0004d980:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0004d990:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0004d9a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0004d520:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0004d9b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0004d530:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0004d9c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0004d540:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0004d9d0:·7073·6522·2069·643d·2269·646d·3438·3339··pse"·id="idm48390004d550:·6522·2069·643d·2269·646d·3438·3337·223e··e"·id="idm4837">
0004d9e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0004d560:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0004d9f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0004d570:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0004da00:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0004d580:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0004da10:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0004d590:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0004da20:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0004d5a0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0004da30:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0004d5b0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0004da40:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0004d5c0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0004da50:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0004d5d0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0004da60:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0004d5e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0004da70:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0004d5f0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0004da80:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0004d600:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0004da90:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0004d610:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0004daa0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0004d620:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0004dab0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0004d630:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0004dac0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0004d640:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
0004dad0:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name0004d650:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
0004dae0:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac 
0004daf0:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac 
0004db00:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.···· 
0004db10:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.·· 
0004db20:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-8 
0004db30:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).·· 
0004db40:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0004db50:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple0004d660:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0004d670:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0004d680:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0004d690:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh
 0004d6a0:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat=
 0004d6b0:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta
 0004d6c0:·7475·737d·0a27·2027·6c69·6e75·782d·6261··tus}.'·'linux-ba
 0004d6d0:·7365·2720·3226·6774·3b2f·6465·762f·6e75··se'·2&gt;/dev/nu
 0004d6e0:·6c6c·207c·2067·7265·7020·2d71·205e·696e··ll·|·grep·-q·^in
 0004d6f0:·7374·616c·6c65·643b·2074·6865·6e0a·0a44··stalled;·then..D
 0004d700:·4542·4941·4e5f·4652·4f4e·5445·4e44·3d6e··EBIAN_FRONTEND=n
 0004d710:·6f6e·696e·7465·7261·6374·6976·6520·6170··oninteractive·ap
 0004d720:·742d·6765·7420·696e·7374·616c·6c20·2d79··t-get·install·-y
 0004d730:·2022·7273·7973·6c6f·6722·0a0a·656c·7365···"rsyslog"..else
 0004d740:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0004d750:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0004d760:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0004d770:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0004d780:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
Max diff block lines reached; 122326/140294 bytes (87.19%) of diff not shown.
12.4 KB
html2text {}
    
Offset 1631, 19 lines modifiedOffset 1631, 14 lines modified
1631 References:················4.4.2.41631 References:················4.4.2.4
1632 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91632 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1633 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11633 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1634 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1634 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1635 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11635 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1636 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1636 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1637 ···························SRG-OS-000480-GPOS-002271637 ···························SRG-OS-000480-GPOS-00227
1638 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1639 [[packages]] 
1640 name·=·"rsyslog" 
1641 version·=·"*" 
1642 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81638 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1643 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1639 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1644 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1640 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1645 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1641 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1646 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1642 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1647 #·Remediation·is·applicable·only·in·certain·platforms1643 #·Remediation·is·applicable·only·in·certain·platforms
1648 if·dpkg-query·--show·--showformat='${db:Status-Status}1644 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1680, 14 lines modifiedOffset 1675, 19 lines modified
1680 ··-·NIST-800-53-CM-6(a)1675 ··-·NIST-800-53-CM-6(a)
1681 ··-·enable_strategy1676 ··-·enable_strategy
1682 ··-·low_complexity1677 ··-·low_complexity
1683 ··-·low_disruption1678 ··-·low_disruption
1684 ··-·medium_severity1679 ··-·medium_severity
1685 ··-·no_reboot_needed1680 ··-·no_reboot_needed
1686 ··-·package_rsyslog_installed1681 ··-·package_rsyslog_installed
 1682 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1683 [[packages]]
 1684 name·=·"rsyslog"
 1685 version·=·"*"
1687 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81686 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1688 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1687 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1689 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1688 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1690 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1689 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1691 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1690 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1692 include·install_rsyslog1691 include·install_rsyslog
  
Offset 1716, 18 lines modifiedOffset 1716, 14 lines modified
1716 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,1716 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
1717 ···························SR·6.2,·SR·7.1,·SR·7.21717 ···························SR·6.2,·SR·7.1,·SR·7.2
1718 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,1718 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
1719 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11719 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1720 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1720 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1721 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11721 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1722 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002271722 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
1723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1724 [customizations.services] 
1725 enabled·=·["rsyslog"] 
1726 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1727 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1724 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1728 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1725 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1729 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1726 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1730 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1727 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1731 -·name:·Gather·the·package·facts1728 -·name:·Gather·the·package·facts
1732 ··package_facts:1729 ··package_facts:
Offset 1763, 14 lines modifiedOffset 1759, 18 lines modified
1763 ··-·NIST-800-53-CM-6(a)1759 ··-·NIST-800-53-CM-6(a)
1764 ··-·enable_strategy1760 ··-·enable_strategy
1765 ··-·low_complexity1761 ··-·low_complexity
1766 ··-·low_disruption1762 ··-·low_disruption
1767 ··-·medium_severity1763 ··-·medium_severity
1768 ··-·no_reboot_needed1764 ··-·no_reboot_needed
1769 ··-·service_rsyslog_enabled1765 ··-·service_rsyslog_enabled
 1766 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1767 [customizations.services]
 1768 enabled·=·["rsyslog"]
1770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81769 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1771 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1770 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1772 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1771 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1773 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1772 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1774 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1773 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1775 include·enable_rsyslog1774 include·enable_rsyslog
  
Offset 3561, 19 lines modifiedOffset 3561, 14 lines modified
3561 ···························SR·2.7,·SR·7.63561 ···························SR·2.7,·SR·7.6
3562 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3562 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3563 ···························A.14.2.4,·A.9.1.23563 ···························A.14.2.4,·A.9.1.2
3564 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3564 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3565 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33565 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3566 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002273566 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
3567 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.23567 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
3568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3569 [[packages]] 
3570 name·=·"cron" 
3571 version·=·"*" 
3572 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3573 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3574 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3575 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3576 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3577 #·Remediation·is·applicable·only·in·certain·platforms3573 #·Remediation·is·applicable·only·in·certain·platforms
3578 if·dpkg-query·--show·--showformat='${db:Status-Status}3574 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 3614, 14 lines modifiedOffset 3609, 19 lines modified
3614 ··-·PCI-DSSv4-2.2.63609 ··-·PCI-DSSv4-2.2.6
3615 ··-·enable_strategy3610 ··-·enable_strategy
3616 ··-·low_complexity3611 ··-·low_complexity
3617 ··-·low_disruption3612 ··-·low_disruption
3618 ··-·medium_severity3613 ··-·medium_severity
3619 ··-·no_reboot_needed3614 ··-·no_reboot_needed
3620 ··-·package_cron_installed3615 ··-·package_cron_installed
 3616 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3617 [[packages]]
 3618 name·=·"cron"
 3619 version·=·"*"
3621 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83620 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3622 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3621 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3623 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3622 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3624 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3623 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3625 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3624 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3626 include·install_cron3625 include·install_cron
  
Offset 3655, 18 lines modifiedOffset 3655, 14 lines modified
3655 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR3655 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR
3656 ···························1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,3656 ···························1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,
3657 ···························SR·2.7,·SR·7.63657 ···························SR·2.7,·SR·7.6
3658 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3658 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3659 ···························A.14.2.4,·A.9.1.23659 ···························A.14.2.4,·A.9.1.2
3660 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3660 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3661 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33661 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3662 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 7109/12699 bytes (55.98%) of diff not shown.
246 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_bp28_enhanced.html
    
Offset 15037, 147 lines modifiedOffset 15037, 147 lines modified
0003abc0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003abc0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003abd0:·3d22·2369·646d·3236·3833·2220·7461·6269··="#idm2683"·tabi0003abd0:·3d22·2369·646d·3236·3833·2220·7461·6269··="#idm2683"·tabi
0003abe0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003abe0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003abf0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003abf0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003ac00:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003ac00:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003ac10:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003ac10:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003ac20:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003ac20:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003ac30:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003ac30:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003ac40:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003ac50:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003ac60:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003ac70:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003ac80:·646d·3236·3833·223e·3c74·6162·6c65·2063··dm2683"><table·c
 0003ac90:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003aca0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003acb0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003acc0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003acd0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003ace0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003acf0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003ad00:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003ad10:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003ad20:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003ad30:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003ad40:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003ad50:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003ac40:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003ac50:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003ac60:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003ac70:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003ac80:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
0003ac90:·3638·3322·3e3c·7072·653e·3c63·6f64·653e··683"><pre><code> 
0003aca0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003acb0:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003acc0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003acd0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003ace0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003acf0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003ad00:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003ad10:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003ad20:·3236·3834·2220·7461·6269·6e64·6578·3d22··2684"·tabindex=" 
0003ad30:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003ad40:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003ad50:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003ad60:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003ad70:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003ad80:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003ad90:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003ada0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003adb0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003adc0:·7073·6522·2069·643d·2269·646d·3236·3834··pse"·id="idm2684 
0003add0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003ade0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003adf0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003ae00:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003ae10:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003ae20:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003ae30:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003ae40:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003ae50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003ae60:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003ae70:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003ae80:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003ad60:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003ae90:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003aea0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003aeb0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003aec0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003aed0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003aee0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003aef0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003af00:·6966·2064·706b·672d·7175·6572·7920·2d2d··if·dpkg-query·-- 
0003af10:·7368·6f77·202d·2d73·686f·7766·6f72·6d61··show·--showforma 
0003af20:·743d·2724·7b64·623a·5374·6174·7573·2d53··t='${db:Status-S 
0003af30:·7461·7475·737d·0a27·2027·6c69·6e75·782d··tatus}.'·'linux- 
0003af40:·6261·7365·2720·3226·6774·3b2f·6465·762f··base'·2&gt;/dev/ 
0003af50:·6e75·6c6c·207c·2067·7265·7020·2d71·205e··null·|·grep·-q·^ 
0003af60:·696e·7374·616c·6c65·643b·2074·6865·6e0a··installed;·then. 
0003af70:·0a44·4542·4941·4e5f·4652·4f4e·5445·4e44··.DEBIAN_FRONTEND 
0003af80:·3d6e·6f6e·696e·7465·7261·6374·6976·6520··=noninteractive· 
0003af90:·6170·742d·6765·7420·696e·7374·616c·6c20··apt-get·install· 
0003afa0:·2d79·2022·6169·6465·220a·0a65·6c73·650a··-y·"aide"..else. 
0003afb0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e0003ad70:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003ad80:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003ad90:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003ada0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003adb0:·666f·726d·730a·6966·2064·706b·672d·7175··forms.if·dpkg-qu
 0003adc0:·6572·7920·2d2d·7368·6f77·202d·2d73·686f··ery·--show·--sho
 0003add0:·7766·6f72·6d61·743d·2724·7b64·623a·5374··wformat='${db:St
 0003ade0:·6174·7573·2d53·7461·7475·737d·0a27·2027··atus-Status}.'·'
 0003adf0:·6c69·6e75·782d·6261·7365·2720·3226·6774··linux-base'·2&gt
 0003ae00:·3b2f·6465·762f·6e75·6c6c·207c·2067·7265··;/dev/null·|·gre
 0003ae10:·7020·2d71·205e·696e·7374·616c·6c65·643b··p·-q·^installed;
 0003ae20:·2074·6865·6e0a·0a44·4542·4941·4e5f·4652···then..DEBIAN_FR
 0003ae30:·4f4e·5445·4e44·3d6e·6f6e·696e·7465·7261··ONTEND=nonintera
 0003ae40:·6374·6976·6520·6170·742d·6765·7420·696e··ctive·apt-get·in
 0003ae50:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003ae60:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 0003ae70:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 0003ae80:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 0003ae90:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 0003aea0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
 0003aeb0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003aec0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003aed0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003aee0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003aef0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003af00:·2223·6964·6d32·3638·3422·2074·6162·696e··"#idm2684"·tabin
 0003af10:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003af20:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003af30:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003af40:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003af50:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003afc0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation0003af60:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
 0003af70:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
 0003af80:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003af90:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003afa0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003afb0:·2269·646d·3236·3834·223e·3c74·6162·6c65··"idm2684"><table
 0003afc0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003afd0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003afe0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003aff0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b000:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003b010:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b020:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b030:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003b040:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
Max diff block lines reached; 211480/230414 bytes (91.78%) of diff not shown.
20.7 KB
html2text {}
    
Offset 113, 19 lines modifiedOffset 113, 14 lines modified
113 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3113 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
114 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)114 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
121 [[packages]] 
122 name·=·"aide" 
123 version·=·"*" 
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
129 #·Remediation·is·applicable·only·in·certain·platforms125 #·Remediation·is·applicable·only·in·certain·platforms
130 if·dpkg-query·--show·--showformat='${db:Status-Status}126 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 168, 14 lines modifiedOffset 163, 19 lines modified
168 ··-·PCI-DSSv4-11.5.2163 ··-·PCI-DSSv4-11.5.2
169 ··-·enable_strategy164 ··-·enable_strategy
170 ··-·low_complexity165 ··-·low_complexity
171 ··-·low_disruption166 ··-·low_disruption
172 ··-·medium_severity167 ··-·medium_severity
173 ··-·no_reboot_needed168 ··-·no_reboot_needed
174 ··-·package_aide_installed169 ··-·package_aide_installed
 170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 171 [[packages]]
 172 name·=·"aide"
 173 version·=·"*"
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
180 include·install_aide179 include·install_aide
  
Offset 586, 19 lines modifiedOffset 586, 14 lines modified
586 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235586 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
587 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386587 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
588 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)588 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
589 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1589 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
590 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125590 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
591 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33591 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
592 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2592 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
594 [[packages]] 
595 name·=·"sudo" 
596 version·=·"*" 
597 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
598 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low594 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
599 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low595 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
600 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false596 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
601 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable597 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
602 #·Remediation·is·applicable·only·in·certain·platforms598 #·Remediation·is·applicable·only·in·certain·platforms
603 if·dpkg-query·--show·--showformat='${db:Status-Status}599 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 639, 14 lines modifiedOffset 634, 19 lines modified
639 ··-·PCI-DSSv4-2.2.6634 ··-·PCI-DSSv4-2.2.6
640 ··-·enable_strategy635 ··-·enable_strategy
641 ··-·low_complexity636 ··-·low_complexity
642 ··-·low_disruption637 ··-·low_disruption
643 ··-·medium_severity638 ··-·medium_severity
644 ··-·no_reboot_needed639 ··-·no_reboot_needed
645 ··-·package_sudo_installed640 ··-·package_sudo_installed
 641 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 642 [[packages]]
 643 name·=·"sudo"
 644 version·=·"*"
646 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8645 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
647 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low646 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
648 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low647 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
649 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false648 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
650 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable649 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
651 include·install_sudo650 include·install_sudo
  
Offset 3221, 19 lines modifiedOffset 3221, 14 lines modified
3221 Rationale:··password·in·resisting·attempts·at·guessing·and·brute-force·attacks.·"pwquality"·enforces3221 Rationale:··password·in·resisting·attempts·at·guessing·and·brute-force·attacks.·"pwquality"·enforces
3222 ············complex·password·construction·configuration·and·has·the·ability·to·limit·brute-force3222 ············complex·password·construction·configuration·and·has·the·ability·to·limit·brute-force
3223 ············attacks·on·the·system.3223 ············attacks·on·the·system.
3224 Severity: ··medium3224 Severity: ··medium
3225 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed3225 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
3226 References:·_\x8d_\x8i_\x8s_\x8a···CCI-0003663226 References:·_\x8d_\x8i_\x8s_\x8a···CCI-000366
3227 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002253227 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00225
3228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3229 [[packages]] 
3230 name·=·"libpam-pwquality" 
3231 version·=·"*" 
3232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3233 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3229 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3234 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3230 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3235 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3231 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3236 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3232 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3237 #·Remediation·is·applicable·only·in·certain·platforms3233 #·Remediation·is·applicable·only·in·certain·platforms
3238 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-3234 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 3268, 14 lines modifiedOffset 3263, 19 lines modified
3268 ··tags:3263 ··tags:
3269 ··-·enable_strategy3264 ··-·enable_strategy
3270 ··-·low_complexity3265 ··-·low_complexity
3271 ··-·low_disruption3266 ··-·low_disruption
3272 ··-·medium_severity3267 ··-·medium_severity
3273 ··-·no_reboot_needed3268 ··-·no_reboot_needed
3274 ··-·package_pam_pwquality_installed3269 ··-·package_pam_pwquality_installed
 3270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3271 [[packages]]
 3272 name·=·"libpam-pwquality"
 3273 version·=·"*"
3275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83274 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3276 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3275 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3277 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3276 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3278 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3277 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3279 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3278 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3280 include·install_libpam-pwquality3279 include·install_libpam-pwquality
  
Offset 4666, 19 lines modifiedOffset 4666, 14 lines modified
4666 ············Control·system·will·be·available.4666 ············Control·system·will·be·available.
4667 Severity: ··medium4667 Severity: ··medium
4668 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed4668 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed
4669 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022354669 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
4670 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-4670 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-
4671 ···················OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001554671 ···················OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
4672 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R454672 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
Max diff block lines reached; 15802/21180 bytes (74.61%) of diff not shown.
246 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_bp28_high.html
    
Offset 15042, 147 lines modifiedOffset 15042, 147 lines modified
0003ac10:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003ac10:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003ac20:·743d·2223·6964·6d32·3638·3322·2074·6162··t="#idm2683"·tab0003ac20:·743d·2223·6964·6d32·3638·3322·2074·6162··t="#idm2683"·tab
0003ac30:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003ac30:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003ac40:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003ac40:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003ac50:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003ac50:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003ac60:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003ac60:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003ac70:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003ac70:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003ac80:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003ac80:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 0003ac90:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 0003aca0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003acb0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003acc0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003acd0:·6964·6d32·3638·3322·3e3c·7461·626c·6520··idm2683"><table·
 0003ace0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003acf0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003ad00:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003ad10:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003ad20:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003ad30:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003ad40:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003ad50:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003ad60:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003ad70:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003ad80:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003ad90:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003ada0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003ac90:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003aca0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003acb0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003acc0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003acd0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003ace0:·3236·3833·223e·3c70·7265·3e3c·636f·6465··2683"><pre><code 
0003acf0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003ad00:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003ad10:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003ad20:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003ad30:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ad40:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ad50:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003ad60:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003ad70:·6d32·3638·3422·2074·6162·696e·6465·783d··m2684"·tabindex= 
0003ad80:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003ad90:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003ada0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003adb0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003adc0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003add0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003ade0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
0003adf0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003ae00:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003ae10:·6170·7365·2220·6964·3d22·6964·6d32·3638··apse"·id="idm268 
0003ae20:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class= 
0003ae30:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003ae40:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003ae50:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003ae60:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003ae70:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003ae80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003ae90:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003aea0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003aeb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003aec0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003aed0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003adb0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003aee0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003aef0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003af00:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003af10:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem 
0003af20:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003af30:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003af40:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003af50:·0a69·6620·6470·6b67·2d71·7565·7279·202d··.if·dpkg-query·- 
0003af60:·2d73·686f·7720·2d2d·7368·6f77·666f·726d··-show·--showform 
0003af70:·6174·3d27·247b·6462·3a53·7461·7475·732d··at='${db:Status- 
0003af80:·5374·6174·7573·7d0a·2720·276c·696e·7578··Status}.'·'linux 
0003af90:·2d62·6173·6527·2032·2667·743b·2f64·6576··-base'·2&gt;/dev 
0003afa0:·2f6e·756c·6c20·7c20·6772·6570·202d·7120··/null·|·grep·-q· 
0003afb0:·5e69·6e73·7461·6c6c·6564·3b20·7468·656e··^installed;·then 
0003afc0:·0a0a·4445·4249·414e·5f46·524f·4e54·454e··..DEBIAN_FRONTEN 
0003afd0:·443d·6e6f·6e69·6e74·6572·6163·7469·7665··D=noninteractive 
0003afe0:·2061·7074·2d67·6574·2069·6e73·7461·6c6c···apt-get·install 
0003aff0:·202d·7920·2261·6964·6522·0a0a·656c·7365···-y·"aide"..else 
0003b000:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b010:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b020:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b030:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b040:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b050:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b060:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b070:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b080:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b090:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b0a0:·3236·3835·2220·7461·6269·6e64·6578·3d22··2685"·tabindex=" 
0003b0b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b0c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b0d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b0e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b0f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b100:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003b110:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b120:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b130:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b140:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
0003b150:·3638·3522·3e3c·7461·626c·6520·636c·6173··685"><table·clas 
0003b160:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b170:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b180:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b190:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b1a0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b1b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b1c0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b1d0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b1e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b1f0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003adc0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003add0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003ade0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003adf0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003ae00:·7466·6f72·6d73·0a69·6620·6470·6b67·2d71··tforms.if·dpkg-q
 0003ae10:·7565·7279·202d·2d73·686f·7720·2d2d·7368··uery·--show·--sh
 0003ae20:·6f77·666f·726d·6174·3d27·247b·6462·3a53··owformat='${db:S
 0003ae30:·7461·7475·732d·5374·6174·7573·7d0a·2720··tatus-Status}.'·
 0003ae40:·276c·696e·7578·2d62·6173·6527·2032·2667··'linux-base'·2&g
 0003ae50:·743b·2f64·6576·2f6e·756c·6c20·7c20·6772··t;/dev/null·|·gr
 0003ae60:·6570·202d·7120·5e69·6e73·7461·6c6c·6564··ep·-q·^installed
 0003ae70:·3b20·7468·656e·0a0a·4445·4249·414e·5f46··;·then..DEBIAN_F
 0003ae80:·524f·4e54·454e·443d·6e6f·6e69·6e74·6572··RONTEND=noninter
 0003ae90:·6163·7469·7665·2061·7074·2d67·6574·2069··active·apt-get·i
 0003aea0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
Max diff block lines reached; 211894/230828 bytes (91.80%) of diff not shown.
20.7 KB
html2text {}
    
Offset 114, 19 lines modifiedOffset 114, 14 lines modified
114 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3114 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
122 [[packages]] 
123 name·=·"aide" 
124 version·=·"*" 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
130 #·Remediation·is·applicable·only·in·certain·platforms126 #·Remediation·is·applicable·only·in·certain·platforms
131 if·dpkg-query·--show·--showformat='${db:Status-Status}127 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 169, 14 lines modifiedOffset 164, 19 lines modified
169 ··-·PCI-DSSv4-11.5.2164 ··-·PCI-DSSv4-11.5.2
170 ··-·enable_strategy165 ··-·enable_strategy
171 ··-·low_complexity166 ··-·low_complexity
172 ··-·low_disruption167 ··-·low_disruption
173 ··-·medium_severity168 ··-·medium_severity
174 ··-·no_reboot_needed169 ··-·no_reboot_needed
175 ··-·package_aide_installed170 ··-·package_aide_installed
 171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 172 [[packages]]
 173 name·=·"aide"
 174 version·=·"*"
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
181 include·install_aide180 include·install_aide
  
Offset 1313, 19 lines modifiedOffset 1313, 14 lines modified
1313 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351313 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1314 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861314 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1315 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1315 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1316 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11316 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1317 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251317 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1318 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331318 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1319 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21319 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1321 [[packages]] 
1322 name·=·"sudo" 
1323 version·=·"*" 
1324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1325 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1321 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1326 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1322 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1327 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1323 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1328 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1324 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1329 #·Remediation·is·applicable·only·in·certain·platforms1325 #·Remediation·is·applicable·only·in·certain·platforms
1330 if·dpkg-query·--show·--showformat='${db:Status-Status}1326 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1366, 14 lines modifiedOffset 1361, 19 lines modified
1366 ··-·PCI-DSSv4-2.2.61361 ··-·PCI-DSSv4-2.2.6
1367 ··-·enable_strategy1362 ··-·enable_strategy
1368 ··-·low_complexity1363 ··-·low_complexity
1369 ··-·low_disruption1364 ··-·low_disruption
1370 ··-·medium_severity1365 ··-·medium_severity
1371 ··-·no_reboot_needed1366 ··-·no_reboot_needed
1372 ··-·package_sudo_installed1367 ··-·package_sudo_installed
 1368 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1369 [[packages]]
 1370 name·=·"sudo"
 1371 version·=·"*"
1373 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81372 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1374 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1373 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1375 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1374 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1376 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1375 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1377 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1376 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1378 include·install_sudo1377 include·install_sudo
  
Offset 3948, 19 lines modifiedOffset 3948, 14 lines modified
3948 Rationale:··password·in·resisting·attempts·at·guessing·and·brute-force·attacks.·"pwquality"·enforces3948 Rationale:··password·in·resisting·attempts·at·guessing·and·brute-force·attacks.·"pwquality"·enforces
3949 ············complex·password·construction·configuration·and·has·the·ability·to·limit·brute-force3949 ············complex·password·construction·configuration·and·has·the·ability·to·limit·brute-force
3950 ············attacks·on·the·system.3950 ············attacks·on·the·system.
3951 Severity: ··medium3951 Severity: ··medium
3952 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed3952 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
3953 References:·_\x8d_\x8i_\x8s_\x8a···CCI-0003663953 References:·_\x8d_\x8i_\x8s_\x8a···CCI-000366
3954 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002253954 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00225
3955 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3956 [[packages]] 
3957 name·=·"libpam-pwquality" 
3958 version·=·"*" 
3959 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83955 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3960 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3956 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3961 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3957 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3962 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3958 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3963 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3959 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3964 #·Remediation·is·applicable·only·in·certain·platforms3960 #·Remediation·is·applicable·only·in·certain·platforms
3965 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-3961 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 3995, 14 lines modifiedOffset 3990, 19 lines modified
3995 ··tags:3990 ··tags:
3996 ··-·enable_strategy3991 ··-·enable_strategy
3997 ··-·low_complexity3992 ··-·low_complexity
3998 ··-·low_disruption3993 ··-·low_disruption
3999 ··-·medium_severity3994 ··-·medium_severity
4000 ··-·no_reboot_needed3995 ··-·no_reboot_needed
4001 ··-·package_pam_pwquality_installed3996 ··-·package_pam_pwquality_installed
 3997 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3998 [[packages]]
 3999 name·=·"libpam-pwquality"
 4000 version·=·"*"
4002 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84001 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4003 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4002 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4004 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4003 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4005 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4004 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4006 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4005 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4007 include·install_libpam-pwquality4006 include·install_libpam-pwquality
  
Offset 5393, 19 lines modifiedOffset 5393, 14 lines modified
5393 ············Control·system·will·be·available.5393 ············Control·system·will·be·available.
5394 Severity: ··medium5394 Severity: ··medium
5395 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed5395 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed
5396 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022355396 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
5397 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-5397 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-
5398 ···················OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001555398 ···················OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
5399 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R455399 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
Max diff block lines reached; 15818/21200 bytes (74.61%) of diff not shown.
104 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_bp28_intermediary.html
    
Offset 15028, 147 lines modifiedOffset 15028, 147 lines modified
0003ab30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003ab30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003ab40:·2223·6964·6d32·3638·3322·2074·6162·696e··"#idm2683"·tabin0003ab40:·2223·6964·6d32·3638·3322·2074·6162·696e··"#idm2683"·tabin
0003ab50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003ab50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003ab60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003ab60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003ab70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003ab70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003ab80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003ab80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003ab90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003ab90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003aba0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003aba0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003abb0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003abc0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003abd0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003abe0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003abf0:·6d32·3638·3322·3e3c·7461·626c·6520·636c··m2683"><table·cl
 0003ac00:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003ac10:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003ac20:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003ac30:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003ac40:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003ac50:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003ac60:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003ac70:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003ac80:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003ac90:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003aca0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003acb0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003acc0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003abb0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003abc0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003abd0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003abe0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003abf0:·6c61·7073·6522·2069·643d·2269·646d·3236··lapse"·id="idm26 
0003ac00:·3833·223e·3c70·7265·3e3c·636f·6465·3e0a··83"><pre><code>. 
0003ac10:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003ac20:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003ac30:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003ac40:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003ac50:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003ac60:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003ac70:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003ac80:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2 
0003ac90:·3638·3422·2074·6162·696e·6465·783d·2230··684"·tabindex="0 
0003aca0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003acb0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003acc0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003acd0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003ace0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003acf0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003ad00:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003ad10:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003ad20:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003ad30:·7365·2220·6964·3d22·6964·6d32·3638·3422··se"·id="idm2684" 
0003ad40:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003ad50:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003ad60:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003ad70:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003ad80:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003ad90:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003ada0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003adb0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003adc0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003add0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003ade0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003adf0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003acd0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003ae00:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003ae10:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003ae20:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003ae30:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003ae40:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003ae50:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003ae60:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003ae70:·6620·6470·6b67·2d71·7565·7279·202d·2d73··f·dpkg-query·--s 
0003ae80:·686f·7720·2d2d·7368·6f77·666f·726d·6174··how·--showformat 
0003ae90:·3d27·247b·6462·3a53·7461·7475·732d·5374··='${db:Status-St 
0003aea0:·6174·7573·7d0a·2720·276c·696e·7578·2d62··atus}.'·'linux-b 
0003aeb0:·6173·6527·2032·2667·743b·2f64·6576·2f6e··ase'·2&gt;/dev/n 
0003aec0:·756c·6c20·7c20·6772·6570·202d·7120·5e69··ull·|·grep·-q·^i 
0003aed0:·6e73·7461·6c6c·6564·3b20·7468·656e·0a0a··nstalled;·then.. 
0003aee0:·4445·4249·414e·5f46·524f·4e54·454e·443d··DEBIAN_FRONTEND= 
0003aef0:·6e6f·6e69·6e74·6572·6163·7469·7665·2061··noninteractive·a 
0003af00:·7074·2d67·6574·2069·6e73·7461·6c6c·202d··pt-get·install·- 
0003af10:·7920·2261·6964·6522·0a0a·656c·7365·0a20··y·"aide"..else.· 
0003af20:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec0003ace0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0003acf0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003ad00:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003ad10:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003ad20:·6f72·6d73·0a69·6620·6470·6b67·2d71·7565··orms.if·dpkg-que
 0003ad30:·7279·202d·2d73·686f·7720·2d2d·7368·6f77··ry·--show·--show
 0003ad40:·666f·726d·6174·3d27·247b·6462·3a53·7461··format='${db:Sta
 0003ad50:·7475·732d·5374·6174·7573·7d0a·2720·276c··tus-Status}.'·'l
 0003ad60:·696e·7578·2d62·6173·6527·2032·2667·743b··inux-base'·2&gt;
 0003ad70:·2f64·6576·2f6e·756c·6c20·7c20·6772·6570··/dev/null·|·grep
 0003ad80:·202d·7120·5e69·6e73·7461·6c6c·6564·3b20···-q·^installed;·
 0003ad90:·7468·656e·0a0a·4445·4249·414e·5f46·524f··then..DEBIAN_FRO
 0003ada0:·4e54·454e·443d·6e6f·6e69·6e74·6572·6163··NTEND=noninterac
 0003adb0:·7469·7665·2061·7074·2d67·6574·2069·6e73··tive·apt-get·ins
 0003adc0:·7461·6c6c·202d·7920·2261·6964·6522·0a0a··tall·-y·"aide"..
 0003add0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003ade0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003adf0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003ae00:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003ae10:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 0003ae20:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003ae30:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003ae40:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003ae50:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003ae60:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003ae70:·2369·646d·3236·3834·2220·7461·6269·6e64··#idm2684"·tabind
 0003ae80:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003ae90:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003aea0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003aeb0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003aec0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003af30:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·0003aed0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
 0003aee0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
 0003aef0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003af00:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003af10:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003af20:·6964·6d32·3638·3422·3e3c·7461·626c·6520··idm2684"><table·
 0003af30:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003af40:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003af50:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003af60:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003af70:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003af80:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003af90:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003afa0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003afb0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
Max diff block lines reached; 79328/98262 bytes (80.73%) of diff not shown.
7.89 KB
html2text {}
    
Offset 111, 19 lines modifiedOffset 111, 14 lines modified
111 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3111 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
112 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)112 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
116 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79116 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
119 [[packages]] 
120 name·=·"aide" 
121 version·=·"*" 
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
127 #·Remediation·is·applicable·only·in·certain·platforms123 #·Remediation·is·applicable·only·in·certain·platforms
128 if·dpkg-query·--show·--showformat='${db:Status-Status}124 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 166, 14 lines modifiedOffset 161, 19 lines modified
166 ··-·PCI-DSSv4-11.5.2161 ··-·PCI-DSSv4-11.5.2
167 ··-·enable_strategy162 ··-·enable_strategy
168 ··-·low_complexity163 ··-·low_complexity
169 ··-·low_disruption164 ··-·low_disruption
170 ··-·medium_severity165 ··-·medium_severity
171 ··-·no_reboot_needed166 ··-·no_reboot_needed
172 ··-·package_aide_installed167 ··-·package_aide_installed
 168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 169 [[packages]]
 170 name·=·"aide"
 171 version·=·"*"
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
178 include·install_aide177 include·install_aide
  
Offset 558, 19 lines modifiedOffset 558, 14 lines modified
558 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235558 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
559 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386559 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
560 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)560 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
561 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1561 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
562 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125562 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
563 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33563 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
564 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2564 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
566 [[packages]] 
567 name·=·"sudo" 
568 version·=·"*" 
569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
570 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low566 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
571 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low567 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
572 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false568 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
573 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable569 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
574 #·Remediation·is·applicable·only·in·certain·platforms570 #·Remediation·is·applicable·only·in·certain·platforms
575 if·dpkg-query·--show·--showformat='${db:Status-Status}571 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 611, 14 lines modifiedOffset 606, 19 lines modified
611 ··-·PCI-DSSv4-2.2.6606 ··-·PCI-DSSv4-2.2.6
612 ··-·enable_strategy607 ··-·enable_strategy
613 ··-·low_complexity608 ··-·low_complexity
614 ··-·low_disruption609 ··-·low_disruption
615 ··-·medium_severity610 ··-·medium_severity
616 ··-·no_reboot_needed611 ··-·no_reboot_needed
617 ··-·package_sudo_installed612 ··-·package_sudo_installed
 613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 614 [[packages]]
 615 name·=·"sudo"
 616 version·=·"*"
618 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8617 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
619 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low618 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
620 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low619 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
621 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false620 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
622 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable621 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
623 include·install_sudo622 include·install_sudo
  
Offset 3107, 19 lines modifiedOffset 3107, 14 lines modified
3107 Rationale:··password·in·resisting·attempts·at·guessing·and·brute-force·attacks.·"pwquality"·enforces3107 Rationale:··password·in·resisting·attempts·at·guessing·and·brute-force·attacks.·"pwquality"·enforces
3108 ············complex·password·construction·configuration·and·has·the·ability·to·limit·brute-force3108 ············complex·password·construction·configuration·and·has·the·ability·to·limit·brute-force
3109 ············attacks·on·the·system.3109 ············attacks·on·the·system.
3110 Severity: ··medium3110 Severity: ··medium
3111 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed3111 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
3112 References:·_\x8d_\x8i_\x8s_\x8a···CCI-0003663112 References:·_\x8d_\x8i_\x8s_\x8a···CCI-000366
3113 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002253113 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00225
3114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3115 [[packages]] 
3116 name·=·"libpam-pwquality" 
3117 version·=·"*" 
3118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3123 #·Remediation·is·applicable·only·in·certain·platforms3119 #·Remediation·is·applicable·only·in·certain·platforms
3124 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-3120 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep·-
Offset 3154, 14 lines modifiedOffset 3149, 19 lines modified
3154 ··tags:3149 ··tags:
3155 ··-·enable_strategy3150 ··-·enable_strategy
3156 ··-·low_complexity3151 ··-·low_complexity
3157 ··-·low_disruption3152 ··-·low_disruption
3158 ··-·medium_severity3153 ··-·medium_severity
3159 ··-·no_reboot_needed3154 ··-·no_reboot_needed
3160 ··-·package_pam_pwquality_installed3155 ··-·package_pam_pwquality_installed
 3156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3157 [[packages]]
 3158 name·=·"libpam-pwquality"
 3159 version·=·"*"
3161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3166 include·install_libpam-pwquality3165 include·install_libpam-pwquality
  
Offset 25330, 19 lines modifiedOffset 25330, 14 lines modified
25330 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000122-GPOS-00063,·SRG-OS-000254-GPOS-00095,·SRG-OS-000255-GPOS-00096,25330 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000122-GPOS-00063,·SRG-OS-000254-GPOS-00095,·SRG-OS-000255-GPOS-00096,
25331 ·····················SRG-OS-000337-GPOS-00129,·SRG-OS-000348-GPOS-00136,·SRG-OS-000349-GPOS-00137,25331 ·····················SRG-OS-000337-GPOS-00129,·SRG-OS-000348-GPOS-00136,·SRG-OS-000349-GPOS-00137,
25332 ·····················SRG-OS-000350-GPOS-00138,·SRG-OS-000351-GPOS-00139,·SRG-OS-000352-GPOS-00140,25332 ·····················SRG-OS-000350-GPOS-00138,·SRG-OS-000351-GPOS-00139,·SRG-OS-000352-GPOS-00140,
25333 ·····················SRG-OS-000353-GPOS-00141,·SRG-OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,25333 ·····················SRG-OS-000353-GPOS-00141,·SRG-OS-000354-GPOS-00142,·SRG-OS-000358-GPOS-00145,
25334 ·····················SRG-OS-000365-GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-0022025334 ·····················SRG-OS-000365-GPOS-00152,·SRG-OS-000392-GPOS-00172,·SRG-OS-000475-GPOS-00220
25335 ············_\x8a_\x8n_\x8s_\x8s_\x8i····R33,·R7325335 ············_\x8a_\x8n_\x8s_\x8s_\x8i····R33,·R73
25336 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··10.2.1,·10.225336 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84··10.2.1,·10.2
Max diff block lines reached; 2531/8052 bytes (31.43%) of diff not shown.
19.7 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_bp28_minimal.html
    
Offset 22804, 140 lines modifiedOffset 22804, 140 lines modified
00059130:·6574·3d22·2369·646d·3433·3730·2220·7461··et="#idm4370"·ta00059130:·6574·3d22·2369·646d·3433·3730·2220·7461··et="#idm4370"·ta
00059140:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00059140:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00059150:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00059150:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00059160:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00059160:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00059170:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00059170:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00059180:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00059180:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00059190:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00059190:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 000591a0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 000591b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 000591c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
000591a0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
000591b0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
000591c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
000591d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
000591e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
000591f0:·6d34·3337·3022·3e3c·7072·653e·3c63·6f64··m4370"><pre><cod 
00059200:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
00059210:·6e61·6d65·203d·2022·6c69·6270·616d·2d70··name·=·"libpam-p 
00059220:·7771·7561·6c69·7479·220a·7665·7273·696f··wquality".versio 
00059230:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
00059240:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
00059250:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00059260:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00059270:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat000591d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000591e0:·2269·646d·3433·3730·223e·3c74·6162·6c65··"idm4370"><table
 000591f0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00059200:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00059210:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00059220:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00059230:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00059240:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00059250:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00059260:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00059280:·612d·7461·7267·6574·3d22·2369·646d·3433··a-target="#idm43 
00059290:·3731·2220·7461·6269·6e64·6578·3d22·3022··71"·tabindex="0" 
000592a0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
000592b0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
000592c0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
000592d0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
000592e0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
000592f0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
00059300:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
00059310:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
00059320:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
00059330:·6522·2069·643d·2269·646d·3433·3731·223e··e"·id="idm4371"> 
00059340:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
00059350:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
00059360:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
00059370:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
00059380:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
00059390:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
000593a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
000593b0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
000593c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
000593d0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
000593e0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
000593f0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
00059400:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00059410:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00059420:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00059430:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
00059440:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
00059450:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
00059460:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
00059470:·2064·706b·672d·7175·6572·7920·2d2d·7368···dpkg-query·--sh 
00059480:·6f77·202d·2d73·686f·7766·6f72·6d61·743d··ow·--showformat= 
00059490:·2724·7b64·623a·5374·6174·7573·2d53·7461··'${db:Status-Sta 
000594a0:·7475·737d·5c6e·2720·276c·6962·7061·6d2d··tus}\n'·'libpam- 
000594b0:·7275·6e74·696d·6527·2032·2667·743b·2f64··runtime'·2&gt;/d 
000594c0:·6576·2f6e·756c·6c20·7c20·6772·6570·202d··ev/null·|·grep·- 
000594d0:·7120·275e·696e·7374·616c·6c65·6427·3b20··q·'^installed';· 
000594e0:·7468·656e·0a0a·4445·4249·414e·5f46·524f··then..DEBIAN_FRO 
000594f0:·4e54·454e·443d·6e6f·6e69·6e74·6572·6163··NTEND=noninterac 
00059500:·7469·7665·2061·7074·2d67·6574·2069·6e73··tive·apt-get·ins 
00059510:·7461·6c6c·202d·7920·226c·6962·7061·6d2d··tall·-y·"libpam- 
00059520:·7077·7175·616c·6974·7922·0a0a·656c·7365··pwquality"..else 
00059530:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
00059540:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
00059550:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
00059560:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
00059570:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
00059580:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
00059590:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
000595a0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
000595b0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
000595c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
000595d0:·3433·3732·2220·7461·6269·6e64·6578·3d22··4372"·tabindex=" 
000595e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
000595f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
00059600:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
00059610:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
00059620:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
00059630:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
00059640:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
00059650:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
00059660:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
00059670:·6c6c·6170·7365·2220·6964·3d22·6964·6d34··llapse"·id="idm4 
00059680:·3337·3222·3e3c·7461·626c·6520·636c·6173··372"><table·clas 
00059690:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
000596a0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
000596b0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
000596c0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
000596d0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
000596e0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00059270:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
000596f0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00059700:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<00059280:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00059290:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
00059710:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th000592a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 000592b0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
 000592c0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 000592d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 000592e0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 000592f0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 00059300:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 00059310:·6174·666f·726d·730a·6966·2064·706b·672d··atforms.if·dpkg-
 00059320:·7175·6572·7920·2d2d·7368·6f77·202d·2d73··query·--show·--s
 00059330:·686f·7766·6f72·6d61·743d·2724·7b64·623a··howformat='${db:
 00059340:·5374·6174·7573·2d53·7461·7475·737d·5c6e··Status-Status}\n
00059720:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
00059730:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
00059740:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00059750:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
00059760:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00059770:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n 
00059780:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
00059790:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
000597a0:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
Max diff block lines reached; 414/18382 bytes (2.25%) of diff not shown.
1.64 KB
html2text {}
    
Offset 1904, 19 lines modifiedOffset 1904, 14 lines modified
1904 Rationale:··effectiveness·of·a·password·in·resisting·attempts·at·guessing·and·brute-force1904 Rationale:··effectiveness·of·a·password·in·resisting·attempts·at·guessing·and·brute-force
1905 ············attacks.·"pwquality"·enforces·complex·password·construction·configuration·and·has1905 ············attacks.·"pwquality"·enforces·complex·password·construction·configuration·and·has
1906 ············the·ability·to·limit·brute-force·attacks·on·the·system.1906 ············the·ability·to·limit·brute-force·attacks·on·the·system.
1907 Severity: ··medium1907 Severity: ··medium
1908 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed1908 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pam_pwquality_installed
1909 References:·_\x8d_\x8i_\x8s_\x8a···CCI-0003661909 References:·_\x8d_\x8i_\x8s_\x8a···CCI-000366
1910 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002251910 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00225
1911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1912 [[packages]] 
1913 name·=·"libpam-pwquality" 
1914 version·=·"*" 
1915 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1916 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1912 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1917 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1913 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1918 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1914 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1919 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1915 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1920 #·Remediation·is·applicable·only·in·certain·platforms1916 #·Remediation·is·applicable·only·in·certain·platforms
1921 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep1917 if·dpkg-query·--show·--showformat='${db:Status-Status}\n'·'libpam-runtime'·2>/dev/null·|·grep
Offset 1951, 14 lines modifiedOffset 1946, 19 lines modified
1951 ··tags:1946 ··tags:
1952 ··-·enable_strategy1947 ··-·enable_strategy
1953 ··-·low_complexity1948 ··-·low_complexity
1954 ··-·low_disruption1949 ··-·low_disruption
1955 ··-·medium_severity1950 ··-·medium_severity
1956 ··-·no_reboot_needed1951 ··-·no_reboot_needed
1957 ··-·package_pam_pwquality_installed1952 ··-·package_pam_pwquality_installed
 1953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1954 [[packages]]
 1955 name·=·"libpam-pwquality"
 1956 version·=·"*"
1958 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81957 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1959 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1958 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1960 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1959 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1961 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1960 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1962 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1961 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1963 include·install_libpam-pwquality1962 include·install_libpam-pwquality
  
90.4 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_np_nt28_average.html
    
Offset 20654, 141 lines modifiedOffset 20654, 141 lines modified
00050ad0:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm1000050ad0:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm10
00050ae0:·3730·3122·2074·6162·696e·6465·783d·2230··701"·tabindex="000050ae0:·3730·3122·2074·6162·696e·6465·783d·2230··701"·tabindex="0
00050af0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00050af0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00050b00:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00050b00:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00050b10:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00050b10:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00050b20:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00050b20:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00050b30:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00050b30:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00050b40:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B00050b40:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 00050b50:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 00050b60:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00050b70:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00050b80:·7365·2220·6964·3d22·6964·6d31·3037·3031··se"·id="idm10701
 00050b90:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00050ba0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
00050b50:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
00050b60:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00050b70:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00050b80:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00050b90:·2069·643d·2269·646d·3130·3730·3122·3e3c···id="idm10701">< 
00050ba0:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
00050bb0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
00050bc0:·7379·736c·6f67·2d6e·6722·0a76·6572·7369··syslog-ng".versi 
00050bd0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
00050be0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00050bf0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00050c00:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00050c10:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00050c20:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
00050c30:·3037·3032·2220·7461·6269·6e64·6578·3d22··0702"·tabindex=" 
00050c40:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
00050c50:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
00050c60:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
00050c70:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
00050c80:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
00050c90:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
00050ca0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
00050cb0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00050cc0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00050cd0:·7073·6522·2069·643d·2269·646d·3130·3730··pse"·id="idm1070 
00050ce0:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class= 
00050cf0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
00050d00:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
00050d10:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden00050bb0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
00050d20:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
00050d30:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
00050d40:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00050d50:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00050d60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00050d70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
00050d80:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f00050bc0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00050bd0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00050be0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00050bf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00050c00:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00050c10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00050c20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00050c30:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00050c40:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00050c50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00050c60:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00050c70:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00050c80:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 00050c90:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 00050ca0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 00050cb0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00050cc0:·6966·2064·706b·672d·7175·6572·7920·2d2d··if·dpkg-query·--
 00050cd0:·7368·6f77·202d·2d73·686f·7766·6f72·6d61··show·--showforma
 00050ce0:·743d·2724·7b64·623a·5374·6174·7573·2d53··t='${db:Status-S
 00050cf0:·7461·7475·737d·0a27·2027·6c69·6e75·782d··tatus}.'·'linux-
 00050d00:·6261·7365·2720·3226·6774·3b2f·6465·762f··base'·2&gt;/dev/
 00050d10:·6e75·6c6c·207c·2067·7265·7020·2d71·205e··null·|·grep·-q·^
 00050d20:·696e·7374·616c·6c65·643b·2074·6865·6e0a··installed;·then.
 00050d30:·0a44·4542·4941·4e5f·4652·4f4e·5445·4e44··.DEBIAN_FRONTEND
 00050d40:·3d6e·6f6e·696e·7465·7261·6374·6976·6520··=noninteractive·
 00050d50:·6170·742d·6765·7420·696e·7374·616c·6c20··apt-get·install·
 00050d60:·2d79·2022·7379·736c·6f67·2d6e·6722·0a0a··-y·"syslog-ng"..
 00050d70:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 00050d80:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 00050d90:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 00050da0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 00050db0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 00050dc0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 00050dd0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 00050de0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 00050df0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 00050e00:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 00050e10:·2369·646d·3130·3730·3222·2074·6162·696e··#idm10702"·tabin
 00050e20:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00050e30:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00050e40:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00050e50:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00050e60:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00050e70:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
 00050e80:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
 00050e90:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00050ea0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00050eb0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00050ec0:·2269·646d·3130·3730·3222·3e3c·7461·626c··"idm10702"><tabl
 00050ed0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00050ee0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00050ef0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00050f00:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00050f10:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00050f20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00050f30:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00050f40:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00050f50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00050f60:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 00050f70:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 00050f80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00050f90:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
00050d90:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t00050fa0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
00050da0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
00050db0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
00050dc0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
00050dd0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem 
00050de0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
00050df0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
00050e00:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
00050e10:·0a69·6620·6470·6b67·2d71·7565·7279·202d··.if·dpkg-query·- 
00050e20:·2d73·686f·7720·2d2d·7368·6f77·666f·726d··-show·--showform 
00050e30:·6174·3d27·247b·6462·3a53·7461·7475·732d··at='${db:Status- 
00050e40:·5374·6174·7573·7d0a·2720·276c·696e·7578··Status}.'·'linux 
00050e50:·2d62·6173·6527·2032·2667·743b·2f64·6576··-base'·2&gt;/dev 
00050e60:·2f6e·756c·6c20·7c20·6772·6570·202d·7120··/null·|·grep·-q· 
00050e70:·5e69·6e73·7461·6c6c·6564·3b20·7468·656e··^installed;·then 
00050e80:·0a0a·4445·4249·414e·5f46·524f·4e54·454e··..DEBIAN_FRONTEN 
Max diff block lines reached; 66076/84182 bytes (78.49%) of diff not shown.
8.01 KB
html2text {}
    
Offset 1816, 19 lines modifiedOffset 1816, 14 lines modified
1816 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-0013121816 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312
1817 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,1817 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
1818 References:················4.4.2.41818 References:················4.4.2.4
1819 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91819 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1820 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11820 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1821 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1821 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1822 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11822 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1823 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1824 [[packages]] 
1825 name·=·"syslog-ng" 
1826 version·=·"*" 
1827 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81823 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1828 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1824 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1829 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1825 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1830 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1826 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1831 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1827 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1832 #·Remediation·is·applicable·only·in·certain·platforms1828 #·Remediation·is·applicable·only·in·certain·platforms
1833 if·dpkg-query·--show·--showformat='${db:Status-Status}1829 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1865, 14 lines modifiedOffset 1860, 19 lines modified
1865 ··-·NIST-800-53-CM-6(a)1860 ··-·NIST-800-53-CM-6(a)
1866 ··-·enable_strategy1861 ··-·enable_strategy
1867 ··-·low_complexity1862 ··-·low_complexity
1868 ··-·low_disruption1863 ··-·low_disruption
1869 ··-·medium_severity1864 ··-·medium_severity
1870 ··-·no_reboot_needed1865 ··-·no_reboot_needed
1871 ··-·package_syslogng_installed1866 ··-·package_syslogng_installed
 1867 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1868 [[packages]]
 1869 name·=·"syslog-ng"
 1870 version·=·"*"
1872 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81871 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1873 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1872 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1874 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1873 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1875 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1874 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1876 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1875 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1877 include·install_syslog-ng1876 include·install_syslog-ng
  
Offset 1900, 18 lines modifiedOffset 1900, 14 lines modified
1900 ···························4.4.2.2,·4.4.2.41900 ···························4.4.2.2,·4.4.2.4
1901 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,1901 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
1902 ···························SR·6.2,·SR·7.1,·SR·7.21902 ···························SR·6.2,·SR·7.1,·SR·7.2
1903 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,1903 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
1904 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11904 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1905 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1905 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1906 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11906 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1908 [customizations.services] 
1909 enabled·=·["syslog-ng"] 
1910 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1911 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1912 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1913 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1914 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1915 -·name:·Gather·the·package·facts1912 -·name:·Gather·the·package·facts
1916 ··package_facts:1913 ··package_facts:
Offset 1947, 14 lines modifiedOffset 1943, 18 lines modified
1947 ··-·NIST-800-53-CM-6(a)1943 ··-·NIST-800-53-CM-6(a)
1948 ··-·enable_strategy1944 ··-·enable_strategy
1949 ··-·low_complexity1945 ··-·low_complexity
1950 ··-·low_disruption1946 ··-·low_disruption
1951 ··-·medium_severity1947 ··-·medium_severity
1952 ··-·no_reboot_needed1948 ··-·no_reboot_needed
1953 ··-·service_syslogng_enabled1949 ··-·service_syslogng_enabled
 1950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1951 [customizations.services]
 1952 enabled·=·["syslog-ng"]
1954 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81953 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1955 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1954 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1956 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1955 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1957 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1956 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1958 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1957 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1959 include·enable_syslog-ng1958 include·enable_syslog-ng
  
Offset 1980, 19 lines modifiedOffset 1980, 14 lines modified
1980 References:················4.4.2.41980 References:················4.4.2.4
1981 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91981 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1982 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11982 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1983 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1983 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1984 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11984 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1985 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1985 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1986 ···························SRG-OS-000480-GPOS-002271986 ···························SRG-OS-000480-GPOS-00227
1987 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1988 [[packages]] 
1989 name·=·"rsyslog" 
1990 version·=·"*" 
1991 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81987 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1992 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1988 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1993 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1989 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1994 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1990 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1995 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1991 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1996 #·Remediation·is·applicable·only·in·certain·platforms1992 #·Remediation·is·applicable·only·in·certain·platforms
1997 if·dpkg-query·--show·--showformat='${db:Status-Status}1993 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2029, 14 lines modifiedOffset 2024, 19 lines modified
2029 ··-·NIST-800-53-CM-6(a)2024 ··-·NIST-800-53-CM-6(a)
2030 ··-·enable_strategy2025 ··-·enable_strategy
2031 ··-·low_complexity2026 ··-·low_complexity
2032 ··-·low_disruption2027 ··-·low_disruption
2033 ··-·medium_severity2028 ··-·medium_severity
2034 ··-·no_reboot_needed2029 ··-·no_reboot_needed
2035 ··-·package_rsyslog_installed2030 ··-·package_rsyslog_installed
 2031 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2032 [[packages]]
 2033 name·=·"rsyslog"
 2034 version·=·"*"
2036 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82035 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2037 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2036 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2038 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2037 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2039 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2038 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2040 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2039 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2041 include·install_rsyslog2040 include·install_rsyslog
  
Offset 2065, 18 lines modifiedOffset 2065, 14 lines modified
2065 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,2065 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
2066 ···························SR·6.2,·SR·7.1,·SR·7.22066 ···························SR·6.2,·SR·7.1,·SR·7.2
2067 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,2067 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
2068 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.12068 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
2069 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)2069 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
2070 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-12070 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
2071 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272071 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2072 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 2429/8183 bytes (29.68%) of diff not shown.
170 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_np_nt28_high.html
    
Offset 21244, 141 lines modifiedOffset 21244, 141 lines modified
00052fb0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00052fb0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00052fc0:·2369·646d·3130·3730·3122·2074·6162·696e··#idm10701"·tabin00052fc0:·2369·646d·3130·3730·3122·2074·6162·696e··#idm10701"·tabin
00052fd0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00052fd0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00052fe0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00052fe0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00052ff0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00052ff0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00053000:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00053000:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00053010:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00053010:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00053020:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB00053020:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
00053030:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
00053040:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00053050:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00053060:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00053070:·6c61·7073·6522·2069·643d·2269·646d·3130··lapse"·id="idm1000053030:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 00053040:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00053050:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00053060:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00053070:·6d31·3037·3031·223e·3c74·6162·6c65·2063··m10701"><table·c
 00053080:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 00053090:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 000530a0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 000530b0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 000530c0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 000530d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 000530e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 000530f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 00053100:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00053110:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 00053120:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 00053130:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 00053140:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 00053150:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
00053080:·3730·3122·3e3c·7072·653e·3c63·6f64·653e··701"><pre><code>00053160:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
00053090:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
000530a0:·6d65·203d·2022·7379·736c·6f67·2d6e·6722··me·=·"syslog-ng" 
000530b0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
000530c0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
000530d0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
000530e0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
000530f0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00053100:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
00053110:·2223·6964·6d31·3037·3032·2220·7461·6269··"#idm10702"·tabi 
00053120:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00053130:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00053140:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00053150:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00053160:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00053170:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh00053170:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
00053180:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
00053190:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
000531a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
000531b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
000531c0:·646d·3130·3730·3222·3e3c·7461·626c·6520··dm10702"><table· 
000531d0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
000531e0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
000531f0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
00053200:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
00053210:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
00053220:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00053230:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00053240:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00053250:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00053260:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
00053270:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
00053280:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00053290:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en00053180:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 00053190:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 000531a0:·666f·726d·730a·6966·2064·706b·672d·7175··forms.if·dpkg-qu
 000531b0:·6572·7920·2d2d·7368·6f77·202d·2d73·686f··ery·--show·--sho
 000531c0:·7766·6f72·6d61·743d·2724·7b64·623a·5374··wformat='${db:St
 000531d0:·6174·7573·2d53·7461·7475·737d·0a27·2027··atus-Status}.'·'
 000531e0:·6c69·6e75·782d·6261·7365·2720·3226·6774··linux-base'·2&gt
 000531f0:·3b2f·6465·762f·6e75·6c6c·207c·2067·7265··;/dev/null·|·gre
 00053200:·7020·2d71·205e·696e·7374·616c·6c65·643b··p·-q·^installed;
 00053210:·2074·6865·6e0a·0a44·4542·4941·4e5f·4652···then..DEBIAN_FR
 00053220:·4f4e·5445·4e44·3d6e·6f6e·696e·7465·7261··ONTEND=nonintera
 00053230:·6374·6976·6520·6170·742d·6765·7420·696e··ctive·apt-get·in
 00053240:·7374·616c·6c20·2d79·2022·7379·736c·6f67··stall·-y·"syslog
 00053250:·2d6e·6722·0a0a·656c·7365·0a20·2020·2026··-ng"..else.····&
 00053260:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 00053270:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 00053280:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 00053290:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 000532a0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
 000532b0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 000532c0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 000532d0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 000532e0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 000532f0:·7267·6574·3d22·2369·646d·3130·3730·3222··rget="#idm10702"
 00053300:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00053310:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00053320:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00053330:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00053340:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00053350:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00053360:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 00053370:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00053380:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00053390:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 000533a0:·6522·2069·643d·2269·646d·3130·3730·3222··e"·id="idm10702"
 000533b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 000533c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 000533d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 000533e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 000533f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 00053400:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 00053410:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00053420:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 00053430:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00053440:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 00053450:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
000532a0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></00053460:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
000532b0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
000532c0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
000532d0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
000532e0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
000532f0:·7466·6f72·6d73·0a69·6620·6470·6b67·2d71··tforms.if·dpkg-q 
00053300:·7565·7279·202d·2d73·686f·7720·2d2d·7368··uery·--show·--sh 
00053310:·6f77·666f·726d·6174·3d27·247b·6462·3a53··owformat='${db:S 
00053320:·7461·7475·732d·5374·6174·7573·7d0a·2720··tatus-Status}.'· 
00053330:·276c·696e·7578·2d62·6173·6527·2032·2667··'linux-base'·2&g 
00053340:·743b·2f64·6576·2f6e·756c·6c20·7c20·6772··t;/dev/null·|·gr 
00053350:·6570·202d·7120·5e69·6e73·7461·6c6c·6564··ep·-q·^installed 
00053360:·3b20·7468·656e·0a0a·4445·4249·414e·5f46··;·then..DEBIAN_F 
00053370:·524f·4e54·454e·443d·6e6f·6e69·6e74·6572··RONTEND=noninter 
00053380:·6163·7469·7665·2061·7074·2d67·6574·2069··active·apt-get·i 
00053390:·6e73·7461·6c6c·202d·7920·2273·7973·6c6f··nstall·-y·"syslo 
000533a0:·672d·6e67·220a·0a65·6c73·650a·2020·2020··g-ng"..else.···· 
Max diff block lines reached; 141812/159918 bytes (88.68%) of diff not shown.
14.1 KB
html2text {}
    
Offset 2008, 19 lines modifiedOffset 2008, 14 lines modified
2008 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-0013122008 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312
2009 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,2009 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
2010 References:················4.4.2.42010 References:················4.4.2.4
2011 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.92011 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
2012 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.12012 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
2013 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)2013 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
2014 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-12014 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
2015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2016 [[packages]] 
2017 name·=·"syslog-ng" 
2018 version·=·"*" 
2019 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2020 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2016 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2021 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2017 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2022 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2018 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2023 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2019 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2024 #·Remediation·is·applicable·only·in·certain·platforms2020 #·Remediation·is·applicable·only·in·certain·platforms
2025 if·dpkg-query·--show·--showformat='${db:Status-Status}2021 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2057, 14 lines modifiedOffset 2052, 19 lines modified
2057 ··-·NIST-800-53-CM-6(a)2052 ··-·NIST-800-53-CM-6(a)
2058 ··-·enable_strategy2053 ··-·enable_strategy
2059 ··-·low_complexity2054 ··-·low_complexity
2060 ··-·low_disruption2055 ··-·low_disruption
2061 ··-·medium_severity2056 ··-·medium_severity
2062 ··-·no_reboot_needed2057 ··-·no_reboot_needed
2063 ··-·package_syslogng_installed2058 ··-·package_syslogng_installed
 2059 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2060 [[packages]]
 2061 name·=·"syslog-ng"
 2062 version·=·"*"
2064 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82063 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2065 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2064 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2066 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2065 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2067 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2066 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2068 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2067 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2069 include·install_syslog-ng2068 include·install_syslog-ng
  
Offset 2092, 18 lines modifiedOffset 2092, 14 lines modified
2092 ···························4.4.2.2,·4.4.2.42092 ···························4.4.2.2,·4.4.2.4
2093 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,2093 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
2094 ···························SR·6.2,·SR·7.1,·SR·7.22094 ···························SR·6.2,·SR·7.1,·SR·7.2
2095 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,2095 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
2096 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.12096 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
2097 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)2097 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
2098 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-12098 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
2099 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2100 [customizations.services] 
2101 enabled·=·["syslog-ng"] 
2102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82099 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2103 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2100 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2104 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2101 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2105 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2102 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2106 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2103 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2107 -·name:·Gather·the·package·facts2104 -·name:·Gather·the·package·facts
2108 ··package_facts:2105 ··package_facts:
Offset 2139, 14 lines modifiedOffset 2135, 18 lines modified
2139 ··-·NIST-800-53-CM-6(a)2135 ··-·NIST-800-53-CM-6(a)
2140 ··-·enable_strategy2136 ··-·enable_strategy
2141 ··-·low_complexity2137 ··-·low_complexity
2142 ··-·low_disruption2138 ··-·low_disruption
2143 ··-·medium_severity2139 ··-·medium_severity
2144 ··-·no_reboot_needed2140 ··-·no_reboot_needed
2145 ··-·service_syslogng_enabled2141 ··-·service_syslogng_enabled
 2142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2143 [customizations.services]
 2144 enabled·=·["syslog-ng"]
2146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2151 include·enable_syslog-ng2150 include·enable_syslog-ng
  
Offset 2172, 19 lines modifiedOffset 2172, 14 lines modified
2172 References:················4.4.2.42172 References:················4.4.2.4
2173 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.92173 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
2174 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.12174 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
2175 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)2175 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
2176 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-12176 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
2177 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,2177 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
2178 ···························SRG-OS-000480-GPOS-002272178 ···························SRG-OS-000480-GPOS-00227
2179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2180 [[packages]] 
2181 name·=·"rsyslog" 
2182 version·=·"*" 
2183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2188 #·Remediation·is·applicable·only·in·certain·platforms2184 #·Remediation·is·applicable·only·in·certain·platforms
2189 if·dpkg-query·--show·--showformat='${db:Status-Status}2185 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2221, 14 lines modifiedOffset 2216, 19 lines modified
2221 ··-·NIST-800-53-CM-6(a)2216 ··-·NIST-800-53-CM-6(a)
2222 ··-·enable_strategy2217 ··-·enable_strategy
2223 ··-·low_complexity2218 ··-·low_complexity
2224 ··-·low_disruption2219 ··-·low_disruption
2225 ··-·medium_severity2220 ··-·medium_severity
2226 ··-·no_reboot_needed2221 ··-·no_reboot_needed
2227 ··-·package_rsyslog_installed2222 ··-·package_rsyslog_installed
 2223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2224 [[packages]]
 2225 name·=·"rsyslog"
 2226 version·=·"*"
2228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2229 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2230 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2231 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2230 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2232 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2231 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2233 include·install_rsyslog2232 include·install_rsyslog
  
Offset 2257, 18 lines modifiedOffset 2257, 14 lines modified
2257 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,2257 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
2258 ···························SR·6.2,·SR·7.1,·SR·7.22258 ···························SR·6.2,·SR·7.1,·SR·7.2
2259 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,2259 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
2260 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.12260 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
2261 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)2261 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
2262 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-12262 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
2263 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272263 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2264 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 8664/14418 bytes (60.09%) of diff not shown.
70.1 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_np_nt28_minimal.html
    
Offset 15652, 140 lines modifiedOffset 15652, 140 lines modified
0003d230:·6574·3d22·2369·646d·3130·3730·3122·2074··et="#idm10701"·t0003d230:·6574·3d22·2369·646d·3130·3730·3122·2074··et="#idm10701"·t
0003d240:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003d240:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003d250:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003d250:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003d260:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003d260:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003d270:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003d270:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003d280:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003d280:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003d290:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003d290:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003d2a0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri0003d2a0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003d2b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003d2c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003d2d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003d2e0:·3d22·6964·6d31·3037·3031·223e·3c74·6162··="idm10701"><tab
 0003d2f0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003d300:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003d310:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003d320:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003d330:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003d340:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003d350:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003d360:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003d370:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003d380:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003d390:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003d3a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003d3b0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003d3c0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003d3d0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003d3e0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 0003d3f0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 0003d400:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 0003d410:·706c·6174·666f·726d·730a·6966·2064·706b··platforms.if·dpk
 0003d420:·672d·7175·6572·7920·2d2d·7368·6f77·202d··g-query·--show·-
 0003d430:·2d73·686f·7766·6f72·6d61·743d·2724·7b64··-showformat='${d
 0003d440:·623a·5374·6174·7573·2d53·7461·7475·737d··b:Status-Status}
 0003d450:·0a27·2027·6c69·6e75·782d·6261·7365·2720··.'·'linux-base'·
 0003d460:·3226·6774·3b2f·6465·762f·6e75·6c6c·207c··2&gt;/dev/null·|
 0003d470:·2067·7265·7020·2d71·205e·696e·7374·616c···grep·-q·^instal
 0003d480:·6c65·643b·2074·6865·6e0a·0a44·4542·4941··led;·then..DEBIA
 0003d490:·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e·696e··N_FRONTEND=nonin
 0003d4a0:·7465·7261·6374·6976·6520·6170·742d·6765··teractive·apt-ge
 0003d4b0:·7420·696e·7374·616c·6c20·2d79·2022·7379··t·install·-y·"sy
 0003d4c0:·736c·6f67·2d6e·6722·0a0a·656c·7365·0a20··slog-ng"..else.·
 0003d4d0:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003d4e0:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0003d4f0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 0003d500:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 0003d510:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
 0003d520:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003d530:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003d540:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003d550:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003d560:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm10
 0003d570:·3730·3222·2074·6162·696e·6465·783d·2230··702"·tabindex="0
 0003d580:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003d590:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003d5a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003d5b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003d5c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003d5d0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
0003d2b0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</0003d5e0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0003d2c0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003d5f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003d2d0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003d600:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003d2e0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003d610:·6c61·7073·6522·2069·643d·2269·646d·3130··lapse"·id="idm10
0003d2f0:·646d·3130·3730·3122·3e3c·7072·653e·3c63··dm10701"><pre><c 
0003d300:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
0003d310:·5d0a·6e61·6d65·203d·2022·7379·736c·6f67··].name·=·"syslog 
0003d320:·2d6e·6722·0a76·6572·7369·6f6e·203d·2022··-ng".version·=·"0003d620:·3730·3222·3e3c·7461·626c·6520·636c·6173··702"><table·clas
 0003d630:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003d640:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003d650:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003d660:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003d670:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003d680:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003d690:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003d6a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003d6b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003d6c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003d6d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003d6e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003d6f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003d700:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003d710:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
 0003d720:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the·
 0003d730:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.··
 0003d740:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.·
 0003d750:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto
 0003d760:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS
 0003d770:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
 0003d780:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra
 0003d790:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com
 0003d7a0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_
 0003d7b0:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m
 0003d7c0:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.·
 0003d7d0:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee
 0003d7e0:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_
 0003d7f0:·7379·736c·6f67·6e67·5f69·6e73·7461·6c6c··syslogng_install
 0003d800:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu
 0003d810:·7265·2073·7973·6c6f·672d·6e67·2069·7320··re·syslog-ng·is·
 0003d820:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack
 0003d830:·6167·653a·0a20·2020·206e·616d·653a·2073··age:.····name:·s
 0003d840:·7973·6c6f·672d·6e67·0a20·2020·2073·7461··yslog-ng.····sta
 0003d850:·7465·3a20·7072·6573·656e·740a·2020·7768··te:·present.··wh
 0003d860:·656e·3a20·2722·6c69·6e75·782d·6261·7365··en:·'"linux-base
 0003d870:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 0003d880:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t
 0003d890:·6167·733a·0a20·202d·204e·4953·542d·3830··ags:.··-·NIST-80
 0003d8a0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
 0003d8b0:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy
 0003d8c0:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex
 0003d8d0:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr
 0003d8e0:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu
 0003d8f0:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n
 0003d900:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed.
 0003d910:·2020·2d20·7061·636b·6167·655f·7379·736c····-·package_sysl
 0003d920:·6f67·6e67·5f69·6e73·7461·6c6c·6564·0a3c··ogng_installed.<
0003d330:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre>0003d930:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003d340:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003d940:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003d350:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003d950:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003d360:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003d960:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003d370:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003d970:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003d380:·6765·743d·2223·6964·6d31·3037·3032·2220··get="#idm10702"·0003d980:·2223·6964·6d31·3037·3033·2220·7461·6269··"#idm10703"·tabi
0003d390:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003d990:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003d3a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003d9a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003d3b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003d9b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003d3c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003d9c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003d3d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003d9d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003d3e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003d9e0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS
Max diff block lines reached; 47142/65110 bytes (72.40%) of diff not shown.
6.42 KB
html2text {}
    
Offset 276, 19 lines modifiedOffset 276, 14 lines modified
276 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312276 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312
277 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,277 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
278 References:················4.4.2.4278 References:················4.4.2.4
279 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9279 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
280 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1280 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
281 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)281 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
282 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1282 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
284 [[packages]] 
285 name·=·"syslog-ng" 
286 version·=·"*" 
287 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
288 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low284 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
289 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low285 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
290 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false286 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
291 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable287 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
292 #·Remediation·is·applicable·only·in·certain·platforms288 #·Remediation·is·applicable·only·in·certain·platforms
293 if·dpkg-query·--show·--showformat='${db:Status-Status}289 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 325, 14 lines modifiedOffset 320, 19 lines modified
325 ··-·NIST-800-53-CM-6(a)320 ··-·NIST-800-53-CM-6(a)
326 ··-·enable_strategy321 ··-·enable_strategy
327 ··-·low_complexity322 ··-·low_complexity
328 ··-·low_disruption323 ··-·low_disruption
329 ··-·medium_severity324 ··-·medium_severity
330 ··-·no_reboot_needed325 ··-·no_reboot_needed
331 ··-·package_syslogng_installed326 ··-·package_syslogng_installed
 327 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 328 [[packages]]
 329 name·=·"syslog-ng"
 330 version·=·"*"
332 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8331 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
333 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low332 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
334 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low333 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
335 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false334 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
336 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable335 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
337 include·install_syslog-ng336 include·install_syslog-ng
  
Offset 360, 18 lines modifiedOffset 360, 14 lines modified
360 ···························4.4.2.2,·4.4.2.4360 ···························4.4.2.2,·4.4.2.4
361 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,361 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
362 ···························SR·6.2,·SR·7.1,·SR·7.2362 ···························SR·6.2,·SR·7.1,·SR·7.2
363 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,363 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
364 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1364 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
365 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)365 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
366 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1366 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
368 [customizations.services] 
369 enabled·=·["syslog-ng"] 
370 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8367 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
371 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low368 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
372 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low369 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
373 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false370 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
374 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable371 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
375 -·name:·Gather·the·package·facts372 -·name:·Gather·the·package·facts
376 ··package_facts:373 ··package_facts:
Offset 407, 14 lines modifiedOffset 403, 18 lines modified
407 ··-·NIST-800-53-CM-6(a)403 ··-·NIST-800-53-CM-6(a)
408 ··-·enable_strategy404 ··-·enable_strategy
409 ··-·low_complexity405 ··-·low_complexity
410 ··-·low_disruption406 ··-·low_disruption
411 ··-·medium_severity407 ··-·medium_severity
412 ··-·no_reboot_needed408 ··-·no_reboot_needed
413 ··-·service_syslogng_enabled409 ··-·service_syslogng_enabled
 410 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 411 [customizations.services]
 412 enabled·=·["syslog-ng"]
414 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
415 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low414 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
416 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low415 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
417 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false416 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
418 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable417 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
419 include·enable_syslog-ng418 include·enable_syslog-ng
  
Offset 440, 19 lines modifiedOffset 440, 14 lines modified
440 References:················4.4.2.4440 References:················4.4.2.4
441 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9441 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
442 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1442 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
443 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)443 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
444 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1444 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
445 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,445 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
446 ···························SRG-OS-000480-GPOS-00227446 ···························SRG-OS-000480-GPOS-00227
447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
448 [[packages]] 
449 name·=·"rsyslog" 
450 version·=·"*" 
451 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
452 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low448 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
453 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low449 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
454 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false450 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
455 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable451 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
456 #·Remediation·is·applicable·only·in·certain·platforms452 #·Remediation·is·applicable·only·in·certain·platforms
457 if·dpkg-query·--show·--showformat='${db:Status-Status}453 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 489, 14 lines modifiedOffset 484, 19 lines modified
489 ··-·NIST-800-53-CM-6(a)484 ··-·NIST-800-53-CM-6(a)
490 ··-·enable_strategy485 ··-·enable_strategy
491 ··-·low_complexity486 ··-·low_complexity
492 ··-·low_disruption487 ··-·low_disruption
493 ··-·medium_severity488 ··-·medium_severity
494 ··-·no_reboot_needed489 ··-·no_reboot_needed
495 ··-·package_rsyslog_installed490 ··-·package_rsyslog_installed
 491 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 492 [[packages]]
 493 name·=·"rsyslog"
 494 version·=·"*"
496 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8495 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
497 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low496 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
498 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low497 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
499 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false498 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
500 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable499 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
501 include·install_rsyslog500 include·install_rsyslog
  
Offset 525, 18 lines modifiedOffset 525, 14 lines modified
525 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,525 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
526 ···························SR·6.2,·SR·7.1,·SR·7.2526 ···························SR·6.2,·SR·7.1,·SR·7.2
527 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,527 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
528 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1528 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
529 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)529 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
530 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1530 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
531 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227531 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
532 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 813/6553 bytes (12.41%) of diff not shown.
170 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-anssi_np_nt28_restrictive.html
    
Offset 20665, 141 lines modifiedOffset 20665, 141 lines modified
00050b80:·7267·6574·3d22·2369·646d·3130·3730·3122··rget="#idm10701"00050b80:·7267·6574·3d22·2369·646d·3130·3730·3122··rget="#idm10701"
00050b90:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00050b90:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00050ba0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00050ba0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00050bb0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00050bb0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00050bc0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00050bc0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00050bd0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00050bd0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00050be0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00050be0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00050bf0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 00050c00:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00050c10:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00050bf0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
00050c00:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
00050c10:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00050c20:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00050c30:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00050c40:·2269·646d·3130·3730·3122·3e3c·7072·653e··"idm10701"><pre> 
00050c50:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
00050c60:·735d·5d0a·6e61·6d65·203d·2022·7379·736c··s]].name·=·"sysl 
00050c70:·6f67·2d6e·6722·0a76·6572·7369·6f6e·203d··og-ng".version·= 
00050c80:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
00050c90:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
00050ca0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
00050cb0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
00050cc0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
00050cd0:·6172·6765·743d·2223·6964·6d31·3037·3032··arget="#idm10702 
00050ce0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
00050cf0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
00050d00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
00050d10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
00050d20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
00050d30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
00050d40:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
00050d50:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00050d60:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00050d70:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00050d80:·2069·643d·2269·646d·3130·3730·3222·3e3c···id="idm10702">< 
00050d90:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
00050da0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
00050db0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
00050dc0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
00050dd0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
00050de0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
00050df0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00050e00:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
00050e10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00050e20:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
00050e30:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
00050e40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00050e50:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
00050e60:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
00050e70:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
00050e80:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
00050e90:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
00050ea0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
00050eb0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
00050ec0:·6470·6b67·2d71·7565·7279·202d·2d73·686f··dpkg-query·--sho 
00050ed0:·7720·2d2d·7368·6f77·666f·726d·6174·3d27··w·--showformat=' 
00050ee0:·247b·6462·3a53·7461·7475·732d·5374·6174··${db:Status-Stat 
00050ef0:·7573·7d0a·2720·276c·696e·7578·2d62·6173··us}.'·'linux-bas 
00050f00:·6527·2032·2667·743b·2f64·6576·2f6e·756c··e'·2&gt;/dev/nul 
00050f10:·6c20·7c20·6772·6570·202d·7120·5e69·6e73··l·|·grep·-q·^ins 
00050f20:·7461·6c6c·6564·3b20·7468·656e·0a0a·4445··talled;·then..DE 
00050f30:·4249·414e·5f46·524f·4e54·454e·443d·6e6f··BIAN_FRONTEND=no 
00050f40:·6e69·6e74·6572·6163·7469·7665·2061·7074··ninteractive·apt 
00050f50:·2d67·6574·2069·6e73·7461·6c6c·202d·7920··-get·install·-y· 
00050f60:·2273·7973·6c6f·672d·6e67·220a·0a65·6c73··"syslog-ng"..els 
00050f70:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
00050f80:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
00050f90:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
00050fa0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
00050fb0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
00050fc0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
00050fd0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
00050fe0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
00050ff0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·00050c20:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00051000:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
00051010:·6d31·3037·3033·2220·7461·6269·6e64·6578··m10703"·tabindex 
00051020:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00051030:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00051040:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00051050:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
00051060:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
00051070:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl00050c30:·6964·3d22·6964·6d31·3037·3031·223e·3c74··id="idm10701"><t
 00050c40:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00050c50:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00050c60:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00050c70:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00050c80:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 00050c90:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00050ca0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00050cb0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00050cc0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00050cd0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00050ce0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 00050cf0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00050d00:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00050d10:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00050d20:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00050d30:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 00050d40:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 00050d50:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 00050d60:·6e20·706c·6174·666f·726d·730a·6966·2064··n·platforms.if·d
 00050d70:·706b·672d·7175·6572·7920·2d2d·7368·6f77··pkg-query·--show
 00050d80:·202d·2d73·686f·7766·6f72·6d61·743d·2724···--showformat='$
 00050d90:·7b64·623a·5374·6174·7573·2d53·7461·7475··{db:Status-Statu
 00050da0:·737d·0a27·2027·6c69·6e75·782d·6261·7365··s}.'·'linux-base
 00050db0:·2720·3226·6774·3b2f·6465·762f·6e75·6c6c··'·2&gt;/dev/null
 00050dc0:·207c·2067·7265·7020·2d71·205e·696e·7374···|·grep·-q·^inst
 00050dd0:·616c·6c65·643b·2074·6865·6e0a·0a44·4542··alled;·then..DEB
 00050de0:·4941·4e5f·4652·4f4e·5445·4e44·3d6e·6f6e··IAN_FRONTEND=non
 00050df0:·696e·7465·7261·6374·6976·6520·6170·742d··interactive·apt-
 00050e00:·6765·7420·696e·7374·616c·6c20·2d79·2022··get·install·-y·"
 00050e10:·7379·736c·6f67·2d6e·6722·0a0a·656c·7365··syslog-ng"..else
 00050e20:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 00050e30:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 00050e40:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 00050e50:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 00050e60:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
 00050e70:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 00050e80:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 00050e90:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 00050ea0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 00050eb0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 00050ec0:·3130·3730·3222·2074·6162·696e·6465·783d··10702"·tabindex=
 00050ed0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 00050ee0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 00050ef0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
Max diff block lines reached; 141536/159642 bytes (88.66%) of diff not shown.
14.1 KB
html2text {}
    
Offset 1818, 19 lines modifiedOffset 1818, 14 lines modified
1818 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-0013121818 ············_\x8d_\x8i_\x8s_\x8a···········CCI-001311,·CCI-001312
1819 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,1819 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,
1820 References:················4.4.2.41820 References:················4.4.2.4
1821 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91821 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1822 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11822 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1823 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1823 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1824 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11824 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1825 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1826 [[packages]] 
1827 name·=·"syslog-ng" 
1828 version·=·"*" 
1829 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81825 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1830 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1826 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1831 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1827 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1832 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1828 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1833 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1829 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1834 #·Remediation·is·applicable·only·in·certain·platforms1830 #·Remediation·is·applicable·only·in·certain·platforms
1835 if·dpkg-query·--show·--showformat='${db:Status-Status}1831 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1867, 14 lines modifiedOffset 1862, 19 lines modified
1867 ··-·NIST-800-53-CM-6(a)1862 ··-·NIST-800-53-CM-6(a)
1868 ··-·enable_strategy1863 ··-·enable_strategy
1869 ··-·low_complexity1864 ··-·low_complexity
1870 ··-·low_disruption1865 ··-·low_disruption
1871 ··-·medium_severity1866 ··-·medium_severity
1872 ··-·no_reboot_needed1867 ··-·no_reboot_needed
1873 ··-·package_syslogng_installed1868 ··-·package_syslogng_installed
 1869 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1870 [[packages]]
 1871 name·=·"syslog-ng"
 1872 version·=·"*"
1874 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81873 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1875 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1874 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1876 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1875 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1877 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1876 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1878 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1877 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1879 include·install_syslog-ng1878 include·install_syslog-ng
  
Offset 1902, 18 lines modifiedOffset 1902, 14 lines modified
1902 ···························4.4.2.2,·4.4.2.41902 ···························4.4.2.2,·4.4.2.4
1903 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,1903 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
1904 ···························SR·6.2,·SR·7.1,·SR·7.21904 ···························SR·6.2,·SR·7.1,·SR·7.2
1905 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,1905 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
1906 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11906 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1907 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1907 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1908 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11908 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1909 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1910 [customizations.services] 
1911 enabled·=·["syslog-ng"] 
1912 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81909 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1913 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1910 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1914 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1911 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1915 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1912 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1916 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1913 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1917 -·name:·Gather·the·package·facts1914 -·name:·Gather·the·package·facts
1918 ··package_facts:1915 ··package_facts:
Offset 1949, 14 lines modifiedOffset 1945, 18 lines modified
1949 ··-·NIST-800-53-CM-6(a)1945 ··-·NIST-800-53-CM-6(a)
1950 ··-·enable_strategy1946 ··-·enable_strategy
1951 ··-·low_complexity1947 ··-·low_complexity
1952 ··-·low_disruption1948 ··-·low_disruption
1953 ··-·medium_severity1949 ··-·medium_severity
1954 ··-·no_reboot_needed1950 ··-·no_reboot_needed
1955 ··-·service_syslogng_enabled1951 ··-·service_syslogng_enabled
 1952 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1953 [customizations.services]
 1954 enabled·=·["syslog-ng"]
1956 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81955 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1957 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1956 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1958 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1957 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1959 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1958 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1960 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1959 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1961 include·enable_syslog-ng1960 include·enable_syslog-ng
  
Offset 1982, 19 lines modifiedOffset 1982, 14 lines modified
1982 References:················4.4.2.41982 References:················4.4.2.4
1983 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91983 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1984 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11984 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1985 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1985 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1986 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11986 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1987 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1987 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1988 ···························SRG-OS-000480-GPOS-002271988 ···························SRG-OS-000480-GPOS-00227
1989 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1990 [[packages]] 
1991 name·=·"rsyslog" 
1992 version·=·"*" 
1993 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81989 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1994 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1990 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1995 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1991 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1996 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1992 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1997 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1993 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1998 #·Remediation·is·applicable·only·in·certain·platforms1994 #·Remediation·is·applicable·only·in·certain·platforms
1999 if·dpkg-query·--show·--showformat='${db:Status-Status}1995 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 2031, 14 lines modifiedOffset 2026, 19 lines modified
2031 ··-·NIST-800-53-CM-6(a)2026 ··-·NIST-800-53-CM-6(a)
2032 ··-·enable_strategy2027 ··-·enable_strategy
2033 ··-·low_complexity2028 ··-·low_complexity
2034 ··-·low_disruption2029 ··-·low_disruption
2035 ··-·medium_severity2030 ··-·medium_severity
2036 ··-·no_reboot_needed2031 ··-·no_reboot_needed
2037 ··-·package_rsyslog_installed2032 ··-·package_rsyslog_installed
 2033 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2034 [[packages]]
 2035 name·=·"rsyslog"
 2036 version·=·"*"
2038 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82037 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2039 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2038 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2040 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2039 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2041 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2040 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2042 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2041 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2043 include·install_rsyslog2042 include·install_rsyslog
  
Offset 2067, 18 lines modifiedOffset 2067, 14 lines modified
2067 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,2067 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
2068 ···························SR·6.2,·SR·7.1,·SR·7.22068 ···························SR·6.2,·SR·7.1,·SR·7.2
2069 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,2069 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
2070 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.12070 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
2071 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)2071 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
2072 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-12072 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
2073 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002272073 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
2074 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 8664/14418 bytes (60.09%) of diff not shown.
150 KB
./usr/share/doc/ssg-debian/ssg-debian12-guide-standard.html
    
Offset 19788, 140 lines modifiedOffset 19788, 140 lines modified
0004d4b0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0004d4b0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0004d4c0:·6964·6d31·3031·3134·2220·7461·6269·6e64··idm10114"·tabind0004d4c0:·6964·6d31·3031·3134·2220·7461·6269·6e64··idm10114"·tabind
0004d4d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0004d4d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0004d4e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0004d4e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0004d4f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0004d4f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0004d500:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0004d500:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0004d510:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0004d510:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0004d520:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0004d520:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0004d530:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0004d540:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0004d550:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0004d560:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0004d570:·3130·3131·3422·3e3c·7461·626c·6520·636c··10114"><table·cl
 0004d580:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0004d590:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0004d530:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0004d540:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0004d550:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0004d560:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0004d570:·6170·7365·2220·6964·3d22·6964·6d31·3031··apse"·id="idm101 
0004d580:·3134·223e·3c70·7265·3e3c·636f·6465·3e0a··14"><pre><code>. 
0004d590:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0004d5a0:·6520·3d20·2272·7379·736c·6f67·220a·7665··e·=·"rsyslog".ve 
0004d5b0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0004d5c0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0004d5d0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0004d5e0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0004d5f0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0004d600:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0004d610:·646d·3130·3131·3522·2074·6162·696e·6465··dm10115"·tabinde 
0004d620:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0004d630:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0004d640:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0004d650:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0004d660:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0004d670:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0004d680:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0004d690:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0004d6a0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0004d6b0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0004d6c0:·3031·3135·223e·3c74·6162·6c65·2063·6c61··0115"><table·cla 
0004d6d0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0004d6e0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0004d5a0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0004d5b0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0004d5c0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0004d5d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0004d5e0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0004d5f0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0004d6f0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0004d700:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0004d710:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0004d720:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0004d730:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0004d740:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0004d750:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0004d760:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0004d770:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0004d780:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0004d790:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0004d7a0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0004d600:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0004d7b0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0004d7c0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0004d7d0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0004d7e0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0004d7f0:·726d·730a·6966·2064·706b·672d·7175·6572··rms.if·dpkg-quer 
0004d800:·7920·2d2d·7368·6f77·202d·2d73·686f·7766··y·--show·--showf 
0004d810:·6f72·6d61·743d·2724·7b64·623a·5374·6174··ormat='${db:Stat 
0004d820:·7573·2d53·7461·7475·737d·0a27·2027·6c69··us-Status}.'·'li 
0004d830:·6e75·782d·6261·7365·2720·3226·6774·3b2f··nux-base'·2&gt;/ 
0004d840:·6465·762f·6e75·6c6c·207c·2067·7265·7020··dev/null·|·grep·0004d610:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0004d620:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0004d630:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0004d640:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0004d650:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 0004d660:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0004d670:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0004d680:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0004d690:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0004d6a0:·6f72·6d73·0a69·6620·6470·6b67·2d71·7565··orms.if·dpkg-que
 0004d6b0:·7279·202d·2d73·686f·7720·2d2d·7368·6f77··ry·--show·--show
 0004d6c0:·666f·726d·6174·3d27·247b·6462·3a53·7461··format='${db:Sta
 0004d6d0:·7475·732d·5374·6174·7573·7d0a·2720·276c··tus-Status}.'·'l
 0004d6e0:·696e·7578·2d62·6173·6527·2032·2667·743b··inux-base'·2&gt;
 0004d6f0:·2f64·6576·2f6e·756c·6c20·7c20·6772·6570··/dev/null·|·grep
0004d850:·2d71·205e·696e·7374·616c·6c65·643b·2074··-q·^installed;·t0004d700:·202d·7120·5e69·6e73·7461·6c6c·6564·3b20···-q·^installed;·
0004d860:·6865·6e0a·0a44·4542·4941·4e5f·4652·4f4e··hen..DEBIAN_FRON 
0004d870:·5445·4e44·3d6e·6f6e·696e·7465·7261·6374··TEND=noninteract 
0004d880:·6976·6520·6170·742d·6765·7420·696e·7374··ive·apt-get·inst 
0004d890:·616c·6c20·2d79·2022·7273·7973·6c6f·6722··all·-y·"rsyslog" 
0004d8a0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0004d8b0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0004d8c0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0004d8d0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0004d8e0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.0004d710:·7468·656e·0a0a·4445·4249·414e·5f46·524f··then..DEBIAN_FRO
 0004d720:·4e54·454e·443d·6e6f·6e69·6e74·6572·6163··NTEND=noninterac
 0004d730:·7469·7665·2061·7074·2d67·6574·2069·6e73··tive·apt-get·ins
 0004d740:·7461·6c6c·202d·7920·2272·7379·736c·6f67··tall·-y·"rsyslog
 0004d750:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt;
 0004d760:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0004d770:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0004d780:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0004d790:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
 0004d7a0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0004d7b0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0004d7c0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0004d7d0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0004d7e0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0004d7f0:·743d·2223·6964·6d31·3031·3135·2220·7461··t="#idm10115"·ta
 0004d800:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0004d810:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0004d820:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0004d830:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0004d840:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0004d850:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0004d860:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
 0004d870:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0004d880:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0004d890:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0004d8a0:·6964·3d22·6964·6d31·3031·3135·223e·3c74··id="idm10115"><t
 0004d8b0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0004d8c0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0004d8d0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0004d8e0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0004d8f0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0004d900:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0004d910:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0004d920:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
Max diff block lines reached; 122464/140432 bytes (87.21%) of diff not shown.
12.4 KB
html2text {}
    
Offset 1631, 19 lines modifiedOffset 1631, 14 lines modified
1631 References:················4.4.2.41631 References:················4.4.2.4
1632 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91632 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1633 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11633 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1634 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1634 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1635 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11635 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1636 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,1636 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,
1637 ···························SRG-OS-000480-GPOS-002271637 ···························SRG-OS-000480-GPOS-00227
1638 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1639 [[packages]] 
1640 name·=·"rsyslog" 
1641 version·=·"*" 
1642 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81638 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1643 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1639 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1644 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1640 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1645 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1641 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1646 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1642 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1647 #·Remediation·is·applicable·only·in·certain·platforms1643 #·Remediation·is·applicable·only·in·certain·platforms
1648 if·dpkg-query·--show·--showformat='${db:Status-Status}1644 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 1680, 14 lines modifiedOffset 1675, 19 lines modified
1680 ··-·NIST-800-53-CM-6(a)1675 ··-·NIST-800-53-CM-6(a)
1681 ··-·enable_strategy1676 ··-·enable_strategy
1682 ··-·low_complexity1677 ··-·low_complexity
1683 ··-·low_disruption1678 ··-·low_disruption
1684 ··-·medium_severity1679 ··-·medium_severity
1685 ··-·no_reboot_needed1680 ··-·no_reboot_needed
1686 ··-·package_rsyslog_installed1681 ··-·package_rsyslog_installed
 1682 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1683 [[packages]]
 1684 name·=·"rsyslog"
 1685 version·=·"*"
1687 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81686 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1688 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1687 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1689 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1688 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1690 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1689 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1691 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1690 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1692 include·install_rsyslog1691 include·install_rsyslog
  
Offset 1716, 18 lines modifiedOffset 1716, 14 lines modified
1716 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,1716 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,
1717 ···························SR·6.2,·SR·7.1,·SR·7.21717 ···························SR·6.2,·SR·7.1,·SR·7.2
1718 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,1718 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,
1719 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.11719 ···························A.12.7.1,·A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
1720 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)1720 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
1721 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-11721 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
1722 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002271722 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
1723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1724 [customizations.services] 
1725 enabled·=·["rsyslog"] 
1726 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1727 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1724 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1728 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1725 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1729 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1726 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1730 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1727 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1731 -·name:·Gather·the·package·facts1728 -·name:·Gather·the·package·facts
1732 ··package_facts:1729 ··package_facts:
Offset 1763, 14 lines modifiedOffset 1759, 18 lines modified
1763 ··-·NIST-800-53-CM-6(a)1759 ··-·NIST-800-53-CM-6(a)
1764 ··-·enable_strategy1760 ··-·enable_strategy
1765 ··-·low_complexity1761 ··-·low_complexity
1766 ··-·low_disruption1762 ··-·low_disruption
1767 ··-·medium_severity1763 ··-·medium_severity
1768 ··-·no_reboot_needed1764 ··-·no_reboot_needed
1769 ··-·service_rsyslog_enabled1765 ··-·service_rsyslog_enabled
 1766 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1767 [customizations.services]
 1768 enabled·=·["rsyslog"]
1770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81769 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1771 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1770 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1772 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1771 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1773 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1772 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1774 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1773 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1775 include·enable_rsyslog1774 include·enable_rsyslog
  
Offset 3561, 19 lines modifiedOffset 3561, 14 lines modified
3561 ···························SR·2.7,·SR·7.63561 ···························SR·2.7,·SR·7.6
3562 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3562 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3563 ···························A.14.2.4,·A.9.1.23563 ···························A.14.2.4,·A.9.1.2
3564 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3564 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3565 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33565 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3566 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002273566 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
3567 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.23567 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
3568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3569 [[packages]] 
3570 name·=·"cron" 
3571 version·=·"*" 
3572 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3573 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3574 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3575 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3576 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3577 #·Remediation·is·applicable·only·in·certain·platforms3573 #·Remediation·is·applicable·only·in·certain·platforms
3578 if·dpkg-query·--show·--showformat='${db:Status-Status}3574 if·dpkg-query·--show·--showformat='${db:Status-Status}
Offset 3614, 14 lines modifiedOffset 3609, 19 lines modified
3614 ··-·PCI-DSSv4-2.2.63609 ··-·PCI-DSSv4-2.2.6
3615 ··-·enable_strategy3610 ··-·enable_strategy
3616 ··-·low_complexity3611 ··-·low_complexity
3617 ··-·low_disruption3612 ··-·low_disruption
3618 ··-·medium_severity3613 ··-·medium_severity
3619 ··-·no_reboot_needed3614 ··-·no_reboot_needed
3620 ··-·package_cron_installed3615 ··-·package_cron_installed
 3616 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3617 [[packages]]
 3618 name·=·"cron"
 3619 version·=·"*"
3621 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83620 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3622 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3621 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3623 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3622 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3624 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3623 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3625 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3624 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3626 include·install_cron3625 include·install_cron
  
Offset 3655, 18 lines modifiedOffset 3655, 14 lines modified
3655 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR3655 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR
3656 ···························1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,3656 ···························1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,
3657 ···························SR·2.7,·SR·7.63657 ···························SR·2.7,·SR·7.6
3658 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,3658 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,
3659 ···························A.14.2.4,·A.9.1.23659 ···························A.14.2.4,·A.9.1.2
3660 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3660 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3661 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-33661 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
3662 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 7109/12699 bytes (55.98%) of diff not shown.
796 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
796 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ds.xml
Max HTML report size reached
693 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
693 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-ocil.xml
Max HTML report size reached
65.9 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
65.8 KB
./usr/share/xml/scap/ssg/content/ssg-debian11-xccdf.xml
Ordering differences only
    
Offset 72, 63 lines modifiedOffset 72, 71 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="package_net-snmp">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_net-snmp:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
82 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
 89 ····<cpe-lang:platform·id="not_aarch64_arch">
 90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 92 ······</cpe-lang:logical-test>
 93 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="machine">94 ····<cpe-lang:platform·id="package_systemd">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
87 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">99 ····<cpe-lang:platform·id="package_postfix">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
93 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="system_with_kernel">104 ····<cpe-lang:platform·id="package_shadow-utils">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
98 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="package_systemd">109 ····<cpe-lang:platform·id="package_rsyslog">
101 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
103 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">114 ····<cpe-lang:platform·id="system_with_kernel">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
110 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
111 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
112 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">119 ····<cpe-lang:platform·id="package_chrony">
113 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
114 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
115 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
116 ········</cpe-lang:logical-test> 
117 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
118 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
119 ········</cpe-lang:logical-test> 
120 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
121 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
122 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">124 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
123 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
126 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
127 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
 130 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 131 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 134 ······</cpe-lang:logical-test>
 135 ····</cpe-lang:platform>
128 ····<cpe-lang:platform·id="x86_64_arch">136 ····<cpe-lang:platform·id="x86_64_arch">
129 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
131 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
132 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
133 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">141 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
134 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 137, 116 lines modifiedOffset 145, 108 lines modified
137 ········</cpe-lang:logical-test>145 ········</cpe-lang:logical-test>
138 ········<cpe-lang:logical-test·operator="AND"·negate="true">146 ········<cpe-lang:logical-test·operator="AND"·negate="true">
139 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>147 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
140 ········</cpe-lang:logical-test>148 ········</cpe-lang:logical-test>
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
142 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">152 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
148 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="package_rsh-server">158 ····<cpe-lang:platform·id="package_rsh-server">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
153 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="package_pam">163 ····<cpe-lang:platform·id="package_net-snmp">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_net-snmp:def:1"/>
158 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="aarch64_arch">168 ····<cpe-lang:platform·id="package_iptables">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
163 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="package_audit">173 ····<cpe-lang:platform·id="not_bootc_and_not_container">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 175 ········<cpe-lang:logical-test·operator="AND"·negate="true">
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>176 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 177 ········</cpe-lang:logical-test>
 178 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 179 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 180 ········</cpe-lang:logical-test>
168 ······</cpe-lang:logical-test>181 ······</cpe-lang:logical-test>
169 ····</cpe-lang:platform>182 ····</cpe-lang:platform>
170 ····<cpe-lang:platform·id="package_ntp">183 ····<cpe-lang:platform·id="machine">
171 ······<cpe-lang:logical-test·operator="AND"·negate="false">184 ······<cpe-lang:logical-test·operator="AND"·negate="false">
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/>185 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
173 ······</cpe-lang:logical-test>186 ······</cpe-lang:logical-test>
174 ····</cpe-lang:platform>187 ····</cpe-lang:platform>
175 ····<cpe-lang:platform·id="package_gdm">188 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">
176 ······<cpe-lang:logical-test·operator="AND"·negate="false">189 ······<cpe-lang:logical-test·operator="AND"·negate="false">
177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>190 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
 191 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian11-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
Max diff block lines reached; 54194/67270 bytes (80.56%) of diff not shown.
1.28 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
1.28 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ds.xml
Max HTML report size reached
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-debian12-ocil.xml
Max HTML report size reached
90.2 KB
./usr/share/xml/scap/ssg/content/ssg-debian12-xccdf.xml
90.1 KB
./usr/share/xml/scap/ssg/content/ssg-debian12-xccdf.xml
Ordering differences only
    
Offset 71, 282 lines modifiedOffset 71, 282 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
 78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
78 ····<cpe-lang:platform·id="package_net-snmp"> 
79 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_net-snmp:def:1"/> 
81 ······</cpe-lang:logical-test> 
82 ····</cpe-lang:platform> 
83 ····<cpe-lang:platform·id="machine"> 
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 85 ········</cpe-lang:logical-test>
86 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="not_bootc">88 ····<cpe-lang:platform·id="not_aarch64_arch">
89 ······<cpe-lang:logical-test·operator="AND"·negate="true">89 ······<cpe-lang:logical-test·operator="AND"·negate="true">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
91 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">93 ····<cpe-lang:platform·id="ipv6_enabled">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
97 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="system_with_kernel">98 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
102 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="selinux">104 ····<cpe-lang:platform·id="package_systemd">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="package_systemd">109 ····<cpe-lang:platform·id="package_postfix">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">114 ····<cpe-lang:platform·id="package_shadow-utils">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
119 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
121 ····<cpe-lang:platform·id="uefi">119 ····<cpe-lang:platform·id="mount_var">
122 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
124 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
125 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
126 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">124 ····<cpe-lang:platform·id="package_rsyslog">
127 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
128 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
129 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
130 ········</cpe-lang:logical-test> 
131 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
132 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
133 ········</cpe-lang:logical-test> 
134 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="mount_home">129 ····<cpe-lang:platform·id="system_with_kernel">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
139 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="mount_var-tmp">134 ····<cpe-lang:platform·id="package_chrony">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
144 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="mount_var-log">139 ····<cpe-lang:platform·id="mount_tmp">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
149 ······</cpe-lang:logical-test>142 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>143 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">144 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">145 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
155 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
 150 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 151 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 154 ······</cpe-lang:logical-test>
 155 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="x86_64_arch">156 ····<cpe-lang:platform·id="x86_64_arch">
158 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
160 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">161 ····<cpe-lang:platform·id="selinux">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/>
 164 ······</cpe-lang:logical-test>
 165 ····</cpe-lang:platform>
 166 ····<cpe-lang:platform·id="package_libreswan">
 167 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_libreswan:def:1"/>
165 ······</cpe-lang:logical-test>169 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>170 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">171 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">172 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:logical-test·operator="AND"·negate="true">173 ········<cpe-lang:logical-test·operator="AND"·negate="true">
170 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>174 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
171 ········</cpe-lang:logical-test>175 ········</cpe-lang:logical-test>
172 ········<cpe-lang:logical-test·operator="AND"·negate="true">176 ········<cpe-lang:logical-test·operator="AND"·negate="true">
173 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>177 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
174 ········</cpe-lang:logical-test>178 ········</cpe-lang:logical-test>
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-debian12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
176 ······</cpe-lang:logical-test>180 ······</cpe-lang:logical-test>
177 ····</cpe-lang:platform>181 ····</cpe-lang:platform>
178 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">182 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
179 ······<cpe-lang:logical-test·operator="AND"·negate="false">183 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 78255/92117 bytes (84.95%) of diff not shown.
544 MB
ssg-nondebian_0.1.76-1_all.deb
452 B
file list
    
Offset 1, 3 lines modifiedOffset 1, 3 lines modified
1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary1 -rw-r--r--···0········0········0········4·2025-03-01·08:08:00.000000·debian-binary
2 -rw-r--r--···0········0········0····18188·2025-03-01·08:08:00.000000·control.tar.xz2 -rw-r--r--···0········0········0····18196·2025-03-01·08:08:00.000000·control.tar.xz
3 -rw-r--r--···0········0········0·37078996·2025-03-01·08:08:00.000000·data.tar.xz3 -rw-r--r--···0········0········0·37073992·2025-03-01·08:08:00.000000·data.tar.xz
98.0 B
control.tar.xz
70.0 B
control.tar
48.0 B
./md5sums
30.0 B
./md5sums
Files differ
544 MB
data.tar.xz
544 MB
data.tar
774 KB
./usr/share/doc/ssg-nondebian/ssg-al2023-guide-cis.html
    
Offset 15111, 213 lines modifiedOffset 15111, 213 lines modified
0003b060:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b060:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b070:·2369·646d·3133·3339·2220·7461·6269·6e64··#idm1339"·tabind0003b070:·2369·646d·3133·3339·2220·7461·6269·6e64··#idm1339"·tabind
0003b080:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b080:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b090:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b090:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b0a0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b0a0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b0b0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b0b0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b0c0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b0c0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b0d0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0003b0d0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003b0e0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003b0f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b100:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b110:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b120:·3133·3339·223e·3c74·6162·6c65·2063·6c61··1339"><table·cla
 0003b130:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b140:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b150:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b160:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b170:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b180:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b190:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b1a0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b1b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b1c0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003b1d0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b1e0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b1f0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003b0e0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003b0f0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003b100:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b110:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b120:·6170·7365·2220·6964·3d22·6964·6d31·3333··apse"·id="idm133 
0003b130:·3922·3e3c·7072·653e·3c63·6f64·653e·0a5b··9"><pre><code>.[ 
0003b140:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0003b150:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio 
0003b160:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
0003b170:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b180:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b190:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b1a0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b1b0:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm13 
0003b1c0:·3430·2220·7461·6269·6e64·6578·3d22·3022··40"·tabindex="0" 
0003b1d0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b1e0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b1f0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b200:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b210:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b220:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003b230:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
0003b240:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b250:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b260:·6522·2069·643d·2269·646d·3133·3430·223e··e"·id="idm1340"> 
0003b270:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b280:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b290:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b2a0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b2b0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b2c0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b2d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b2e0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b2f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b300:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b310:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b320:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003b200:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003b210:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0003b220:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003b230:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003b240:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003b250:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 0003b260:·6574·202d·7120·6b65·726e·656c·3b20·7468··et·-q·kernel;·th
 0003b270:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 0003b280:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 0003b290:·2074·6865·6e0a·2020·2020·646e·6620·696e···then.····dnf·in
 0003b2a0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003b2b0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 0003b2c0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003b2d0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003b2e0:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003b2f0:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
 0003b300:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
 0003b310:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003b320:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003b330:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003b340:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003b350:·6574·3d22·2369·646d·3133·3430·2220·7461··et="#idm1340"·ta
 0003b360:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003b370:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003b380:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003b390:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003b3a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003b3b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b3c0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
0003b330:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b340:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b350:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b360:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003b370:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003b380:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003b390:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003b3a0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003b3b0:·6b65·726e·656c·3b20·7468·656e·0a0a·6966··kernel;·then..if 
0003b3c0:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003b3d0:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then. 
0003b3e0:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install· 
0003b3f0:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el 
0003b400:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003b410:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003b420:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003b430:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003b440:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003b450:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b460:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b470:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b480:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b490:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b4a0:·646d·3133·3431·2220·7461·6269·6e64·6578··dm1341"·tabindex 
0003b4b0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b4c0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b4d0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b4e0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b4f0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b500:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl 
0003b510:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a 
0003b520:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b530:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b540:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b550:·6d31·3334·3122·3e3c·7461·626c·6520·636c··m1341"><table·cl 
0003b560:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
Max diff block lines reached; 691220/719262 bytes (96.10%) of diff not shown.
71.7 KB
html2text {}
    
Offset 123, 19 lines modifiedOffset 123, 14 lines modified
123 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)123 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
124 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3124 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
128 ············_\x8c_\x8i_\x8s············1.3.1128 ············_\x8c_\x8i_\x8s············1.3.1
129 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2129 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
131 [[packages]] 
132 name·=·"aide" 
133 version·=·"*" 
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
139 #·Remediation·is·applicable·only·in·certain·platforms135 #·Remediation·is·applicable·only·in·certain·platforms
140 if·rpm·--quiet·-q·kernel;·then136 if·rpm·--quiet·-q·kernel;·then
Offset 179, 33 lines modifiedOffset 174, 38 lines modified
179 ··-·PCI-DSSv4-11.5.2174 ··-·PCI-DSSv4-11.5.2
180 ··-·enable_strategy175 ··-·enable_strategy
181 ··-·low_complexity176 ··-·low_complexity
182 ··-·low_disruption177 ··-·low_disruption
183 ··-·medium_severity178 ··-·medium_severity
184 ··-·no_reboot_needed179 ··-·no_reboot_needed
185 ··-·package_aide_installed180 ··-·package_aide_installed
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 186 package·--add=aide
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 188 [[packages]]
 189 name·=·"aide"
 190 version·=·"*"
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
191 include·install_aide196 include·install_aide
  
192 class·install_aide·{197 class·install_aide·{
193 ··package·{·'aide':198 ··package·{·'aide':
194 ····ensure·=>·'installed',199 ····ensure·=>·'installed',
195 ··}200 ··}
196 }201 }
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
202 package·--add=aide 
203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
204 Run·the·following·command·to·generate·a·new·database:203 Run·the·following·command·to·generate·a·new·database:
205 $·sudo·/usr/sbin/aide·--init204 $·sudo·/usr/sbin/aide·--init
206 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,205 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,
207 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a206 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a
208 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The207 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The
209 newly-generated·database·can·be·installed·as·follows:208 newly-generated·database·can·be·installed·as·follows:
Offset 880, 19 lines modifiedOffset 880, 14 lines modified
880 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386880 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
881 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)881 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
882 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1882 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
883 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125883 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
884 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33884 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
885 ············_\x8c_\x8i_\x8s·····4.3.1885 ············_\x8c_\x8i_\x8s·····4.3.1
886 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2886 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
887 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
888 [[packages]] 
889 name·=·"sudo" 
890 version·=·"*" 
891 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8887 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
892 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low888 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
893 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low889 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
894 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false890 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
895 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable891 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
896 #·Remediation·is·applicable·only·in·certain·platforms892 #·Remediation·is·applicable·only·in·certain·platforms
897 if·rpm·--quiet·-q·kernel;·then893 if·rpm·--quiet·-q·kernel;·then
Offset 934, 33 lines modifiedOffset 929, 38 lines modified
934 ··-·PCI-DSSv4-2.2.6929 ··-·PCI-DSSv4-2.2.6
935 ··-·enable_strategy930 ··-·enable_strategy
936 ··-·low_complexity931 ··-·low_complexity
937 ··-·low_disruption932 ··-·low_disruption
938 ··-·medium_severity933 ··-·medium_severity
939 ··-·no_reboot_needed934 ··-·no_reboot_needed
940 ··-·package_sudo_installed935 ··-·package_sudo_installed
 936 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 937 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 938 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 939 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 940 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 941 package·--add=sudo
 942 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 943 [[packages]]
 944 name·=·"sudo"
 945 version·=·"*"
941 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8946 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
942 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low947 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
943 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low948 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
944 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false949 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
945 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable950 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
946 include·install_sudo951 include·install_sudo
  
947 class·install_sudo·{952 class·install_sudo·{
948 ··package·{·'sudo':953 ··package·{·'sudo':
949 ····ensure·=>·'installed',954 ····ensure·=>·'installed',
950 ··}955 ··}
951 }956 }
952 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
953 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
954 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
955 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
956 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
957 package·--add=sudo 
958 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*957 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
959 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.958 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.
960 This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any959 This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any
Max diff block lines reached; 68196/73433 bytes (92.87%) of diff not shown.
512 KB
./usr/share/doc/ssg-nondebian/ssg-al2023-guide-cis_server_l1.html
    
Offset 15077, 213 lines modifiedOffset 15077, 213 lines modified
0003ae40:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003ae40:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003ae50:·6964·6d31·3333·3922·2074·6162·696e·6465··idm1339"·tabinde0003ae50:·6964·6d31·3333·3922·2074·6162·696e·6465··idm1339"·tabinde
0003ae60:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003ae60:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003ae70:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003ae70:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003ae80:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003ae80:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003ae90:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003ae90:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003aea0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003aea0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003aeb0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003aeb0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0003aec0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003aed0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003aee0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003aef0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003af00:·7073·6522·2069·643d·2269·646d·3133·3339··pse"·id="idm13390003aec0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003aed0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003aee0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003aef0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 0003af00:·3333·3922·3e3c·7461·626c·6520·636c·6173··339"><table·clas
 0003af10:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003af20:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003af30:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003af40:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003af50:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003af60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003af70:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003af80:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003af90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003afa0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003afb0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003afc0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003afd0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003afe0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003af10:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[0003aff0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 0003b000:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003b010:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003b020:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003b030:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 0003b040:·7420·2d71·206b·6572·6e65·6c3b·2074·6865··t·-q·kernel;·the
 0003b050:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·-
 0003b060:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;·
 0003b070:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins
 0003b080:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f
 0003b090:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 0003b0a0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003b0b0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003b0c0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003b0d0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
 0003b0e0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003af20:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003af30:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003af40:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003af50:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003af60:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003af70:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003af80:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003af90:·2d74·6172·6765·743d·2223·6964·6d31·3334··-target="#idm134 
0003afa0:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"· 
0003afb0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003afc0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003afd0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003afe0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003aff0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b000:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b010:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b020:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b030:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b040:·2220·6964·3d22·6964·6d31·3334·3022·3e3c··"·id="idm1340">< 
0003b050:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b060:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b070:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b080:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b090:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b0a0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b0b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b0c0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b0d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b0e0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b0f0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b100:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b110:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b120:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b130:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b140:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003b150:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003b160:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b170:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b180:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003b190:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if· 
0003b1a0:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003b1b0:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003b1c0:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
0003b1d0:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003b1e0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b1f0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b200:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b210:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b220:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b230:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b240:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b250:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b260:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b270:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b280:·6d31·3334·3122·2074·6162·696e·6465·783d··m1341"·tabindex= 
0003b290:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b2a0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b2b0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b2c0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b2d0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b2e0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b2f0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b300:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b0f0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003b100:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003b110:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003b120:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003b130:·743d·2223·6964·6d31·3334·3022·2074·6162··t="#idm1340"·tab
 0003b140:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003b150:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003b160:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003b170:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003b180:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003b190:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
 0003b1a0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
0003b310:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b320:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b330:·3133·3431·223e·3c74·6162·6c65·2063·6c61··1341"><table·cla 
0003b340:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b350:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b360:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
Max diff block lines reached; 443250/471292 bytes (94.05%) of diff not shown.
52.0 KB
html2text {}
    
Offset 118, 19 lines modifiedOffset 118, 14 lines modified
118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
123 ············_\x8c_\x8i_\x8s············1.3.1123 ············_\x8c_\x8i_\x8s············1.3.1
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
126 [[packages]] 
127 name·=·"aide" 
128 version·=·"*" 
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
134 #·Remediation·is·applicable·only·in·certain·platforms130 #·Remediation·is·applicable·only·in·certain·platforms
135 if·rpm·--quiet·-q·kernel;·then131 if·rpm·--quiet·-q·kernel;·then
Offset 174, 33 lines modifiedOffset 169, 38 lines modified
174 ··-·PCI-DSSv4-11.5.2169 ··-·PCI-DSSv4-11.5.2
175 ··-·enable_strategy170 ··-·enable_strategy
176 ··-·low_complexity171 ··-·low_complexity
177 ··-·low_disruption172 ··-·low_disruption
178 ··-·medium_severity173 ··-·medium_severity
179 ··-·no_reboot_needed174 ··-·no_reboot_needed
180 ··-·package_aide_installed175 ··-·package_aide_installed
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 181 package·--add=aide
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
186 include·install_aide191 include·install_aide
  
187 class·install_aide·{192 class·install_aide·{
188 ··package·{·'aide':193 ··package·{·'aide':
189 ····ensure·=>·'installed',194 ····ensure·=>·'installed',
190 ··}195 ··}
191 }196 }
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·--add=aide 
198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
199 Run·the·following·command·to·generate·a·new·database:198 Run·the·following·command·to·generate·a·new·database:
200 $·sudo·/usr/sbin/aide·--init199 $·sudo·/usr/sbin/aide·--init
201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,
202 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a201 the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a
203 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The202 secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The
204 newly-generated·database·can·be·installed·as·follows:203 newly-generated·database·can·be·installed·as·follows:
Offset 743, 19 lines modifiedOffset 743, 14 lines modified
743 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386743 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
744 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)744 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
745 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1745 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
746 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125746 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
747 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33747 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
748 ············_\x8c_\x8i_\x8s·····4.3.1748 ············_\x8c_\x8i_\x8s·····4.3.1
749 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2749 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
751 [[packages]] 
752 name·=·"sudo" 
753 version·=·"*" 
754 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
755 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low751 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
756 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low752 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
757 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false753 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
758 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable754 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
759 #·Remediation·is·applicable·only·in·certain·platforms755 #·Remediation·is·applicable·only·in·certain·platforms
760 if·rpm·--quiet·-q·kernel;·then756 if·rpm·--quiet·-q·kernel;·then
Offset 797, 33 lines modifiedOffset 792, 38 lines modified
797 ··-·PCI-DSSv4-2.2.6792 ··-·PCI-DSSv4-2.2.6
798 ··-·enable_strategy793 ··-·enable_strategy
799 ··-·low_complexity794 ··-·low_complexity
800 ··-·low_disruption795 ··-·low_disruption
801 ··-·medium_severity796 ··-·medium_severity
802 ··-·no_reboot_needed797 ··-·no_reboot_needed
803 ··-·package_sudo_installed798 ··-·package_sudo_installed
 799 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 800 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 801 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 802 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 803 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 804 package·--add=sudo
 805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 806 [[packages]]
 807 name·=·"sudo"
 808 version·=·"*"
804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8809 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
805 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low810 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
806 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low811 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
807 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false812 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
808 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable813 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
809 include·install_sudo814 include·install_sudo
  
810 class·install_sudo·{815 class·install_sudo·{
811 ··package·{·'sudo':816 ··package·{·'sudo':
812 ····ensure·=>·'installed',817 ····ensure·=>·'installed',
813 ··}818 ··}
814 }819 }
815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
816 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
817 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
818 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
819 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
820 package·--add=sudo 
821 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*820 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
822 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.821 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.
823 This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any822 This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any
Max diff block lines reached; 47990/53227 bytes (90.16%) of diff not shown.
234 KB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-pci-dss.html
    
Offset 15467, 95 lines modifiedOffset 15467, 95 lines modified
0003c6a0:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm120003c6a0:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm12
0003c6b0:·3134·2220·7461·6269·6e64·6578·3d22·3022··14"·tabindex="0"0003c6b0:·3134·2220·7461·6269·6e64·6578·3d22·3022··14"·tabindex="0"
0003c6c0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003c6c0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003c6d0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003c6d0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003c6e0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003c6e0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003c6f0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003c6f0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003c700:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003c700:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c710:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
 0003c720:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003c730:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003c740:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003c750:·6170·7365·2220·6964·3d22·6964·6d31·3231··apse"·id="idm121
 0003c760:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class=
 0003c770:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003c780:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003c790:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003c7a0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003c7b0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003c7c0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003c7d0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003c7e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c7f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003c800:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003c810:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003c820:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003c830:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003c840:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003c850:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
 0003c860:·653a·2047·6174·6865·7220·7468·6520·7061··e:·Gather·the·pa
 0003c870:·636b·6167·6520·6661·6374·730a·2020·7061··ckage·facts.··pa
 0003c880:·636b·6167·655f·6661·6374·733a·0a20·2020··ckage_facts:.···
 0003c890:·206d·616e·6167·6572·3a20·6175·746f·0a20···manager:·auto.·
0003c710:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003c720:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003c730:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003c740:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003c750:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003c760:·6964·3d22·6964·6d31·3231·3422·3e3c·7072··id="idm1214"><pr 
0003c770:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003c780:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003c790:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003c7a0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003c7b0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003c7c0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003c7d0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003c7e0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003c7f0:·6574·3d22·2369·646d·3132·3135·2220·7461··et="#idm1215"·ta 
0003c800:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003c810:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003c820:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003c830:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c840:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c850:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c860:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003c870:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003c880:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003c890:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003c8a0:·6964·3d22·6964·6d31·3231·3522·3e3c·7461··id="idm1215"><ta 
0003c8b0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003c8c0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003c8d0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003c8e0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003c8f0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003c900:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003c910:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c920:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003c930:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c940:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003c950:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003c960:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c970:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003c980:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003c990:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003c9a0:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat 
0003c9b0:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package· 
0003c9c0:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_ 
0003c9d0:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag 
0003c9e0:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags: 
0003c9f0:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1 
0003ca00:·2e33·0a20·202d·204e·4953·542d·3830·302d··.3.··-·NIST-800- 
0003ca10:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
0003ca20:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
0003ca30:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
0003ca40:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
0003ca50:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
0003ca60:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
0003ca70:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
0003ca80:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
0003ca90:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
0003caa0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
0003cab0:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
0003cac0:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu 
0003cad0:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
0003cae0:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
0003caf0:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
0003cb00:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
0003cb10:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern 
0003cb20:·656c·2220·696e·2061·6e73·6962·6c65·5f66··el"·in·ansible_f 
0003cb30:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
0003cb40:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-0003c8a0:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-
0003cb50:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS0003c8b0:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS
0003cb60:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)0003c8c0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
0003cb70:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req0003c8d0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
0003cb80:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS0003c8e0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
0003cb90:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e0003c8f0:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e
0003cba0:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.·0003c900:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.·
0003cbb0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit0003c910:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
0003cbc0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup0003c920:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup
0003cbd0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_0003c930:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
0003cbe0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_0003c940:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
0003cbf0:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··0003c950:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
0003cc00:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i0003c960:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i
0003cc10:·6e73·7461·6c6c·6564·0a3c·2f63·6f64·653e··nstalled.</code>0003c970:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name
 0003c980:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is
 0003c990:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac
 0003c9a0:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:·
 0003c9b0:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:·
 0003c9c0:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:·
 0003c9d0:·2722·6b65·726e·656c·2220·696e·2061·6e73··'"kernel"·in·ans
 0003c9e0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
 0003c9f0:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-
 0003ca00:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.·
 0003ca10:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
 0003ca20:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D
 0003ca30:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·
 0003ca40:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2
 0003ca50:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra
Max diff block lines reached; 207813/219569 bytes (94.65%) of diff not shown.
19.9 KB
html2text {}
    
Offset 160, 19 lines modifiedOffset 160, 14 lines modified
160 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3160 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
161 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)161 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
162 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3162 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
163 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5163 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
164 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199164 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
165 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79165 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
166 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2166 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
168 [[packages]] 
169 name·=·"aide" 
170 version·=·"*" 
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
176 -·name:·Gather·the·package·facts172 -·name:·Gather·the·package·facts
177 ··package_facts:173 ··package_facts:
Offset 201, 14 lines modifiedOffset 196, 19 lines modified
201 ··-·PCI-DSSv4-11.5.2196 ··-·PCI-DSSv4-11.5.2
202 ··-·enable_strategy197 ··-·enable_strategy
203 ··-·low_complexity198 ··-·low_complexity
204 ··-·low_disruption199 ··-·low_disruption
205 ··-·medium_severity200 ··-·medium_severity
206 ··-·no_reboot_needed201 ··-·no_reboot_needed
207 ··-·package_aide_installed202 ··-·package_aide_installed
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 204 [[packages]]
 205 name·=·"aide"
 206 version·=·"*"
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
213 include·install_aide212 include·install_aide
  
Offset 4957, 19 lines modifiedOffset 4957, 14 lines modified
4957 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94957 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4958 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14958 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4959 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)4959 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
4960 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14960 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4961 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.74961 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.7
4962 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R714962 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
4963 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.54963 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.5
4964 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4965 [[packages]] 
4966 name·=·"logrotate" 
4967 version·=·"*" 
4968 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84964 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4969 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4965 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4970 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4966 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4971 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4967 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4972 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4968 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4973 -·name:·Gather·the·package·facts4969 -·name:·Gather·the·package·facts
4974 ··package_facts:4970 ··package_facts:
Offset 4998, 14 lines modifiedOffset 4993, 19 lines modified
4998 ··-·PCI-DSSv4-10.5.14993 ··-·PCI-DSSv4-10.5.1
4999 ··-·enable_strategy4994 ··-·enable_strategy
5000 ··-·low_complexity4995 ··-·low_complexity
5001 ··-·low_disruption4996 ··-·low_disruption
5002 ··-·medium_severity4997 ··-·medium_severity
5003 ··-·no_reboot_needed4998 ··-·no_reboot_needed
5004 ··-·package_logrotate_installed4999 ··-·package_logrotate_installed
 5000 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5001 [[packages]]
 5002 name·=·"logrotate"
 5003 version·=·"*"
5005 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85004 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5006 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5005 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5007 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5006 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5008 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5007 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5009 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5008 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5010 include·install_logrotate5009 include·install_logrotate
  
Offset 5120, 19 lines modifiedOffset 5120, 14 lines modified
5120 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed5120 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed
5121 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023225121 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
5122 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)5122 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
5123 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.15123 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
5124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,5124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,
5125 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-002325125 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
5126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.25126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
5127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5128 [[packages]] 
5129 name·=·"firewalld" 
5130 version·=·"*" 
5131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5136 -·name:·Gather·the·package·facts5132 -·name:·Gather·the·package·facts
5137 ··package_facts:5133 ··package_facts:
Offset 5159, 14 lines modifiedOffset 5154, 19 lines modified
5159 ··-·PCI-DSSv4-1.2.15154 ··-·PCI-DSSv4-1.2.1
5160 ··-·enable_strategy5155 ··-·enable_strategy
5161 ··-·low_complexity5156 ··-·low_complexity
5162 ··-·low_disruption5157 ··-·low_disruption
5163 ··-·medium_severity5158 ··-·medium_severity
5164 ··-·no_reboot_needed5159 ··-·no_reboot_needed
5165 ··-·package_firewalld_installed5160 ··-·package_firewalld_installed
 5161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5162 [[packages]]
 5163 name·=·"firewalld"
 5164 version·=·"*"
5166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5171 include·install_firewalld5170 include·install_firewalld
  
Offset 5194, 18 lines modifiedOffset 5194, 14 lines modified
5194 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)5194 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)
5195 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-15195 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
5196 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.15196 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
5197 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-5197 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-
5198 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-002325198 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
5199 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A215199 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
5200 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.25200 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
Max diff block lines reached; 14973/20385 bytes (73.45%) of diff not shown.
216 KB
./usr/share/doc/ssg-nondebian/ssg-alinux2-guide-standard.html
    
Offset 19864, 132 lines modifiedOffset 19864, 132 lines modified
0004d970:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0004d970:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0004d980:·3639·3237·2220·7461·6269·6e64·6578·3d22··6927"·tabindex="0004d980:·3639·3237·2220·7461·6269·6e64·6578·3d22··6927"·tabindex="
0004d990:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0004d990:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0004d9a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0004d9a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0004d9b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0004d9b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0004d9c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0004d9c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0004d9d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0004d9d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0004d9e0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·0004d9e0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
 0004d9f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 0004da00:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0004da10:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0004da20:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
 0004da30:·3932·3722·3e3c·7461·626c·6520·636c·6173··927"><table·clas
 0004da40:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0004da50:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0004da60:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0004da70:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0004da80:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0004da90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0004daa0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0004dab0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0004dac0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0004dad0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0004dae0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0004daf0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0004db00:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0004d9f0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0004da00:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0004da10:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0004da20:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0004da30:·2220·6964·3d22·6964·6d36·3932·3722·3e3c··"·id="idm6927">< 
0004da40:·7072·653e·3c63·6f64·653e·0a5b·6375·7374··pre><code>.[cust 
0004da50:·6f6d·697a·6174·696f·6e73·2e73·6572·7669··omizations.servi 
0004da60:·6365·735d·0a65·6e61·626c·6564·203d·205b··ces].enabled·=·[ 
0004da70:·2266·6972·6577·616c·6c64·225d·0a3c·2f63··"firewalld"].</c 
0004da80:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0004da90:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0004daa0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0004dab0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0004dac0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0004dad0:·6964·6d36·3932·3822·2074·6162·696e·6465··idm6928"·tabinde 
0004dae0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0004daf0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0004db00:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0004db10:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0004db20:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0004db30:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib 
0004db40:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0004db50:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0004db60:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0004db70:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0004db80:·646d·3639·3238·223e·3c74·6162·6c65·2063··dm6928"><table·c 
0004db90:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0004dba0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0004dbb0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0004dbc0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0004dbd0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0004dbe0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0004dbf0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0004dc00:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0004dc10:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0004db10:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0004db20:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
 0004db30:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the·
 0004db40:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.··
 0004db50:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.·
 0004db60:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto
 0004db70:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS
 0004db80:·542d·3830·302d·3137·312d·332e·312e·330a··T-800-171-3.1.3.
0004dc20:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0004dc30:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0004dc40:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0004dc50:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0004dc60:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0004dc70:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0004dc80:·2d20·6e61·6d65·3a20·4761·7468·6572·2074··-·name:·Gather·t 
0004dc90:·6865·2070·6163·6b61·6765·2066·6163·7473··he·package·facts 
0004dca0:·0a20·2070·6163·6b61·6765·5f66·6163·7473··.··package_facts 
0004dcb0:·3a0a·2020·2020·6d61·6e61·6765·723a·2061··:.····manager:·a 
0004dcc0:·7574·6f0a·2020·7461·6773·3a0a·2020·2d20··uto.··tags:.··-· 
0004dcd0:·4e49·5354·2d38·3030·2d31·3731·2d33·2e31··NIST-800-171-3.10004db90:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171
0004dce0:·2e33·0a20·202d·204e·4953·542d·3830·302d··.3.··-·NIST-800- 
0004dcf0:·3137·312d·332e·342e·370a·2020·2d20·4e49··171-3.4.7.··-·NI 
0004dd00:·5354·2d38·3030·2d35·332d·4143·2d34·0a20··ST-800-53-AC-4.· 
0004dd10:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0004dd20:·412d·3328·3529·0a20·202d·204e·4953·542d··A-3(5).··-·NIST-0004dba0:·2d33·2e34·2e37·0a20·202d·204e·4953·542d··-3.4.7.··-·NIST-
0004dd30:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
0004dd40:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0004dd50:·4d2d·3728·6229·0a20·202d·204e·4953·542d··M-7(b).··-·NIST- 
0004dd60:·3830·302d·3533·2d53·432d·3728·3231·290a··800-53-SC-7(21). 
0004dd70:·2020·2d20·5043·492d·4453·5376·342d·312e····-·PCI-DSSv4-1. 
0004dd80:·320a·2020·2d20·5043·492d·4453·5376·342d··2.··-·PCI-DSSv4- 
0004dd90:·312e·322e·310a·2020·2d20·656e·6162·6c65··1.2.1.··-·enable 
0004dda0:·5f73·7472·6174·6567·790a·2020·2d20·6c6f··_strategy.··-·lo 
0004ddb0:·775f·636f·6d70·6c65·7869·7479·0a20·202d··w_complexity.··- 
0004ddc0:·206c·6f77·5f64·6973·7275·7074·696f·6e0a···low_disruption. 
0004ddd0:·2020·2d20·6d65·6469·756d·5f73·6576·6572····-·medium_sever 
0004dde0:·6974·790a·2020·2d20·6e6f·5f72·6562·6f6f··ity.··-·no_reboo 
0004ddf0:·745f·6e65·6564·6564·0a20·202d·2073·6572··t_needed.··-·ser0004dbb0:·3830·302d·3533·2d41·432d·340a·2020·2d20··800-53-AC-4.··-·
 0004dbc0:·4e49·5354·2d38·3030·2d35·332d·4341·2d33··NIST-800-53-CA-3
 0004dbd0:·2835·290a·2020·2d20·4e49·5354·2d38·3030··(5).··-·NIST-800
 0004dbe0:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-·
 0004dbf0:·4e49·5354·2d38·3030·2d35·332d·434d·2d37··NIST-800-53-CM-7
 0004dc00:·2862·290a·2020·2d20·4e49·5354·2d38·3030··(b).··-·NIST-800
 0004dc10:·2d35·332d·5343·2d37·2832·3129·0a20·202d··-53-SC-7(21).··-
 0004dc20:·2050·4349·2d44·5353·7634·2d31·2e32·0a20···PCI-DSSv4-1.2.·
 0004dc30:·202d·2050·4349·2d44·5353·7634·2d31·2e32···-·PCI-DSSv4-1.2
 0004dc40:·2e31·0a20·202d·2065·6e61·626c·655f·7374··.1.··-·enable_st
 0004dc50:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c
 0004dc60:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo
 0004dc70:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-
 0004dc80:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity
 0004dc90:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n
 0004dca0:·6565·6465·640a·2020·2d20·7365·7276·6963··eeded.··-·servic
 0004dcb0:·655f·6669·7265·7761·6c6c·645f·656e·6162··e_firewalld_enab
 0004dcc0:·6c65·640a·0a2d·206e·616d·653a·2056·6572··led..-·name:·Ver
 0004dcd0:·6966·7920·6669·7265·7761·6c6c·6420·456e··ify·firewalld·En
 0004dce0:·6162·6c65·6420·2d20·456e·6162·6c65·2073··abled·-·Enable·s
0004de00:·7669·6365·5f66·6972·6577·616c·6c64·5f65··vice_firewalld_e0004dcf0:·6572·7669·6365·2066·6972·6577·616c·6c64··ervice·firewalld
0004de10:·6e61·626c·6564·0a0a·2d20·6e61·6d65·3a20··nabled..-·name:·0004dd00:·0a20·2062·6c6f·636b·3a0a·0a20·202d·206e··.··block:..··-·n
 0004dd10:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the·
 0004dd20:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.··
 0004dd30:·2020·7061·636b·6167·655f·6661·6374·733a····package_facts:
 0004dd40:·0a20·2020·2020·206d·616e·6167·6572·3a20··.······manager:·
 0004dd50:·6175·746f·0a0a·2020·2d20·6e61·6d65·3a20··auto..··-·name:·
0004de20:·5665·7269·6679·2066·6972·6577·616c·6c64··Verify·firewalld0004dd60:·5665·7269·6679·2066·6972·6577·616c·6c64··Verify·firewalld
0004de30:·2045·6e61·626c·6564·202d·2045·6e61·626c···Enabled·-·Enabl0004dd70:·2045·6e61·626c·6564·202d·2045·6e61·626c···Enabled·-·Enabl
0004de40:·6520·7365·7276·6963·6520·6669·7265·7761··e·service·firewa0004dd80:·6520·5365·7276·6963·6520·6669·7265·7761··e·Service·firewa
Max diff block lines reached; 191464/208328 bytes (91.91%) of diff not shown.
12.6 KB
html2text {}
    
Offset 1115, 18 lines modifiedOffset 1115, 14 lines modified
1115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-11115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
1116 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.11116 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
1117 ···························SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-1117 ···························SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-
1118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-1118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-
1119 ···························GPOS-002321119 ···························GPOS-00232
1120 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A211120 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
1121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.21121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
1122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1123 [customizations.services] 
1124 enabled·=·["firewalld"] 
1125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1130 -·name:·Gather·the·package·facts1127 -·name:·Gather·the·package·facts
1131 ··package_facts:1128 ··package_facts:
Offset 1178, 14 lines modifiedOffset 1174, 18 lines modified
1178 ··-·PCI-DSSv4-1.2.11174 ··-·PCI-DSSv4-1.2.1
1179 ··-·enable_strategy1175 ··-·enable_strategy
1180 ··-·low_complexity1176 ··-·low_complexity
1181 ··-·low_disruption1177 ··-·low_disruption
1182 ··-·medium_severity1178 ··-·medium_severity
1183 ··-·no_reboot_needed1179 ··-·no_reboot_needed
1184 ··-·service_firewalld_enabled1180 ··-·service_firewalld_enabled
 1181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1182 [customizations.services]
 1183 enabled·=·["firewalld"]
1185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1190 include·enable_firewalld1189 include·enable_firewalld
  
Offset 1305, 18 lines modifiedOffset 1305, 14 lines modified
1305 ···························A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,1305 ···························A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,
1306 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,1306 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,
1307 ···························A.9.3.1,·A.9.4.2,·A.9.4.31307 ···························A.9.3.1,·A.9.4.2,·A.9.4.3
1308 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-71308 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1309 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-71309 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
1310 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-1310 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-
1311 ···························000480-GPOS-002271311 ···························000480-GPOS-00227
1312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1313 [customizations.services] 
1314 masked·=·["autofs"] 
1315 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81312 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1316 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1313 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1317 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1314 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1318 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1315 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1319 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1316 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1320 -·name:·Gather·the·package·facts1317 -·name:·Gather·the·package·facts
1321 ··package_facts:1318 ··package_facts:
Offset 1415, 14 lines modifiedOffset 1411, 18 lines modified
1415 ··-·NIST-800-53-MP-71411 ··-·NIST-800-53-MP-7
1416 ··-·disable_strategy1412 ··-·disable_strategy
1417 ··-·low_complexity1413 ··-·low_complexity
1418 ··-·low_disruption1414 ··-·low_disruption
1419 ··-·medium_severity1415 ··-·medium_severity
1420 ··-·no_reboot_needed1416 ··-·no_reboot_needed
1421 ··-·service_autofs_disabled1417 ··-·service_autofs_disabled
 1418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1419 [customizations.services]
 1420 masked·=·["autofs"]
1422 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81421 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1423 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1422 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1424 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1423 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1425 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1424 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1426 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1425 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1427 include·disable_autofs1426 include·disable_autofs
  
Offset 1501, 18 lines modifiedOffset 1501, 14 lines modified
1501 ···························SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR1501 ···························SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR
1502 ···························7.61502 ···························7.6
1503 ···························A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,1503 ···························A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,
1504 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,1504 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,
1505 ···························A.9.1.21505 ···························A.9.1.2
1506 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-6(a)1506 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-6(a)
1507 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41507 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1508 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1509 [customizations.services] 
1510 masked·=·["abrtd"] 
1511 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81508 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1512 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1509 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1513 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1510 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1514 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1511 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1515 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1512 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1516 -·name:·Gather·the·package·facts1513 -·name:·Gather·the·package·facts
1517 ··package_facts:1514 ··package_facts:
Offset 1595, 14 lines modifiedOffset 1591, 18 lines modified
1595 ··-·NIST-800-53-CM-7(a)1591 ··-·NIST-800-53-CM-7(a)
1596 ··-·disable_strategy1592 ··-·disable_strategy
1597 ··-·low_complexity1593 ··-·low_complexity
1598 ··-·low_disruption1594 ··-·low_disruption
1599 ··-·medium_severity1595 ··-·medium_severity
1600 ··-·no_reboot_needed1596 ··-·no_reboot_needed
1601 ··-·service_abrtd_disabled1597 ··-·service_abrtd_disabled
 1598 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1599 [customizations.services]
 1600 masked·=·["abrtd"]
1602 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81601 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1603 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1602 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1604 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1603 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1605 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1604 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1606 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1605 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1607 include·disable_abrtd1606 include·disable_abrtd
  
Offset 1639, 18 lines modifiedOffset 1639, 14 lines modified
1639 ···························SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR1639 ···························SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR
1640 ···························7.61640 ···························7.6
1641 ···························A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,1641 ···························A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,
1642 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,1642 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,
1643 ···························A.9.1.21643 ···························A.9.1.2
1644 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)1644 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
1645 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41645 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1646 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1647 [customizations.services] 
1648 masked·=·["ntpdate"] 
1649 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81646 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1650 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1647 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Max diff block lines reached; 7279/12894 bytes (56.45%) of diff not shown.
260 KB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-pci-dss.html
    
Offset 15823, 95 lines modifiedOffset 15823, 95 lines modified
0003dce0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003dce0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003dcf0:·6964·6d31·3330·3822·2074·6162·696e·6465··idm1308"·tabinde0003dcf0:·6964·6d31·3330·3822·2074·6162·696e·6465··idm1308"·tabinde
0003dd00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003dd00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003dd10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003dd10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003dd20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003dd20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003dd30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003dd30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003dd40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003dd40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003dd50:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003dd50:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib
 0003dd60:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</
 0003dd70:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003dd80:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003dd90:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003dda0:·646d·3133·3038·223e·3c74·6162·6c65·2063··dm1308"><table·c
 0003ddb0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003ddc0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003ddd0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003dde0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003ddf0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003de00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003de10:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003de20:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003de30:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003de40:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003de50:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003de60:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003de70:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003dd60:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003dd70:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003dd80:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003dd90:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003dda0:·7073·6522·2069·643d·2269·646d·3133·3038··pse"·id="idm1308 
0003ddb0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003ddc0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003ddd0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003dde0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003ddf0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003de00:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003de10:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003de20:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003de30:·2d74·6172·6765·743d·2223·6964·6d31·3330··-target="#idm130 
0003de40:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"· 
0003de50:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003de60:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003de70:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003de80:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003de90:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003dea0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003deb0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003dec0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003ded0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003dee0:·7073·6522·2069·643d·2269·646d·3133·3039··pse"·id="idm1309 
0003def0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003df00:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003df10:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003df20:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003df30:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003df40:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003df50:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003df60:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003df70:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003df80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003df90:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003dfa0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003de80:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003de90:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003dea0:·2d20·6e61·6d65·3a20·4761·7468·6572·2074··-·name:·Gather·t
 0003deb0:·6865·2070·6163·6b61·6765·2066·6163·7473··he·package·facts
 0003dec0:·0a20·2070·6163·6b61·6765·5f66·6163·7473··.··package_facts
 0003ded0:·3a0a·2020·2020·6d61·6e61·6765·723a·2061··:.····manager:·a
0003dfb0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003dfc0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003dfd0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003dfe0:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name 
0003dff0:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac 
0003e000:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac 
0003e010:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.···· 
0003e020:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.·· 
0003e030:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5 
0003e040:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST 
0003e050:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a). 
0003e060:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req- 
0003e070:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS 
0003e080:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en 
0003e090:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.·· 
0003e0a0:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity 
0003e0b0:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt 
0003e0c0:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s 
0003e0d0:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r 
0003e0e0:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··- 
0003e0f0:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in 
0003e100:·7374·616c·6c65·640a·0a2d·206e·616d·653a··stalled..-·name: 
0003e110:·2045·6e73·7572·6520·6169·6465·2069·7320···Ensure·aide·is· 
0003e120:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack 
0003e130:·6167·653a·0a20·2020·206e·616d·653a·2061··age:.····name:·a 
0003e140:·6964·650a·2020·2020·7374·6174·653a·2070··ide.····state:·p 
0003e150:·7265·7365·6e74·0a20·2077·6865·6e3a·2027··resent.··when:·' 
0003e160:·226b·6572·6e65·6c22·2069·6e20·616e·7369··"kernel"·in·ansi 
0003e170:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag 
0003e180:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·0003dee0:·7574·6f0a·2020·7461·6773·3a0a·2020·2d20··uto.··tags:.··-·
0003e190:·434a·4953·2d35·2e31·302e·312e·330a·2020··CJIS-5.10.1.3.··0003def0:·434a·4953·2d35·2e31·302e·312e·330a·2020··CJIS-5.10.1.3.··
0003e1a0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003df00:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
0003e1b0:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS0003df10:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
0003e1c0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P0003df20:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
0003e1d0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.0003df30:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
0003e1e0:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat0003df40:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
0003e1f0:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp0003df50:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp
0003e200:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d0003df60:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
0003e210:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me0003df70:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
0003e220:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··0003df80:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
0003e230:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need0003df90:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
0003e240:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a0003dfa0:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a
0003e250:·6964·655f·696e·7374·616c·6c65·640a·3c2f··ide_installed.</0003dfb0:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..-
 0003dfc0:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai
 0003dfd0:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed.
 0003dfe0:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n
 0003dff0:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st
 0003e000:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w
 0003e010:·6865·6e3a·2027·226b·6572·6e65·6c22·2069··hen:·'"kernel"·i
 0003e020:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts.
 0003e030:·7061·636b·6167·6573·270a·2020·7461·6773··packages'.··tags
 0003e040:·3a0a·2020·2d20·434a·4953·2d35·2e31·302e··:.··-·CJIS-5.10.
 0003e050:·312e·330a·2020·2d20·4e49·5354·2d38·3030··1.3.··-·NIST-800
 0003e060:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-·
 0003e070:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.5
 0003e080:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1
 0003e090:·312e·352e·320a·2020·2d20·656e·6162·6c65··1.5.2.··-·enable
 0003e0a0:·5f73·7472·6174·6567·790a·2020·2d20·6c6f··_strategy.··-·lo
 0003e0b0:·775f·636f·6d70·6c65·7869·7479·0a20·202d··w_complexity.··-
Max diff block lines reached; 232955/244711 bytes (95.20%) of diff not shown.
21.1 KB
html2text {}
    
Offset 202, 19 lines modifiedOffset 202, 14 lines modified
202 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3202 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
203 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)203 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
204 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3204 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
205 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5205 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
206 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199206 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
207 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79207 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
208 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2208 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
210 [[packages]] 
211 name·=·"aide" 
212 version·=·"*" 
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
218 -·name:·Gather·the·package·facts214 -·name:·Gather·the·package·facts
219 ··package_facts:215 ··package_facts:
Offset 243, 14 lines modifiedOffset 238, 19 lines modified
243 ··-·PCI-DSSv4-11.5.2238 ··-·PCI-DSSv4-11.5.2
244 ··-·enable_strategy239 ··-·enable_strategy
245 ··-·low_complexity240 ··-·low_complexity
246 ··-·low_disruption241 ··-·low_disruption
247 ··-·medium_severity242 ··-·medium_severity
248 ··-·no_reboot_needed243 ··-·no_reboot_needed
249 ··-·package_aide_installed244 ··-·package_aide_installed
 245 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 246 [[packages]]
 247 name·=·"aide"
 248 version·=·"*"
250 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8249 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
251 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low250 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
252 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low251 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
253 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false252 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
254 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable253 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
255 include·install_aide254 include·install_aide
  
Offset 616, 19 lines modifiedOffset 616, 14 lines modified
616 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235616 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
617 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386617 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
618 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)618 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
619 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1619 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
620 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125620 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
621 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33621 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
622 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2622 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
624 [[packages]] 
625 name·=·"sudo" 
626 version·=·"*" 
627 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
628 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low624 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
629 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low625 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
630 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false626 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
631 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable627 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
632 -·name:·Gather·the·package·facts628 -·name:·Gather·the·package·facts
633 ··package_facts:629 ··package_facts:
Offset 655, 14 lines modifiedOffset 650, 19 lines modified
655 ··-·PCI-DSSv4-2.2.6650 ··-·PCI-DSSv4-2.2.6
656 ··-·enable_strategy651 ··-·enable_strategy
657 ··-·low_complexity652 ··-·low_complexity
658 ··-·low_disruption653 ··-·low_disruption
659 ··-·medium_severity654 ··-·medium_severity
660 ··-·no_reboot_needed655 ··-·no_reboot_needed
661 ··-·package_sudo_installed656 ··-·package_sudo_installed
 657 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 658 [[packages]]
 659 name·=·"sudo"
 660 version·=·"*"
662 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8661 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
663 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low662 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
664 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low663 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
665 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false664 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
666 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable665 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
667 include·install_sudo666 include·install_sudo
  
Offset 4672, 19 lines modifiedOffset 4672, 14 lines modified
4672 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94672 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4673 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14673 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4674 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)4674 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
4675 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14675 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4676 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.74676 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.7
4677 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R714677 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
4678 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.54678 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.5
4679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4680 [[packages]] 
4681 name·=·"logrotate" 
4682 version·=·"*" 
4683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4684 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4680 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4685 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4681 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4686 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4682 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4687 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4683 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4688 -·name:·Gather·the·package·facts4684 -·name:·Gather·the·package·facts
4689 ··package_facts:4685 ··package_facts:
Offset 4713, 14 lines modifiedOffset 4708, 19 lines modified
4713 ··-·PCI-DSSv4-10.5.14708 ··-·PCI-DSSv4-10.5.1
4714 ··-·enable_strategy4709 ··-·enable_strategy
4715 ··-·low_complexity4710 ··-·low_complexity
4716 ··-·low_disruption4711 ··-·low_disruption
4717 ··-·medium_severity4712 ··-·medium_severity
4718 ··-·no_reboot_needed4713 ··-·no_reboot_needed
4719 ··-·package_logrotate_installed4714 ··-·package_logrotate_installed
 4715 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4716 [[packages]]
 4717 name·=·"logrotate"
 4718 version·=·"*"
4720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84719 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4721 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4720 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4722 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4721 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4723 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4722 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4724 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4723 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4725 include·install_logrotate4724 include·install_logrotate
  
Offset 4835, 19 lines modifiedOffset 4835, 14 lines modified
4835 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed4835 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed
4836 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023224836 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
4837 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)4837 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
4838 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.14838 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
4839 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,4839 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,
4840 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-002324840 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
4841 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.24841 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
Max diff block lines reached; 16403/21602 bytes (75.93%) of diff not shown.
197 KB
./usr/share/doc/ssg-nondebian/ssg-alinux3-guide-standard.html
    
Offset 20025, 224 lines modifiedOffset 20025, 224 lines modified
0004e380:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0004e380:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0004e390:·6d31·3135·3130·2220·7461·6269·6e64·6578··m11510"·tabindex0004e390:·6d31·3135·3130·2220·7461·6269·6e64·6578··m11510"·tabindex
0004e3a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0004e3a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0004e3b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0004e3b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0004e3c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0004e3c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0004e3d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0004e3d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0004e3e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0004e3e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0004e3f0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0004e3f0:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl
 0004e400:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a
 0004e410:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0004e420:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0004e430:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0004e440:·6d31·3135·3130·223e·3c74·6162·6c65·2063··m11510"><table·c
 0004e450:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0004e400:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0004e410:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0004e420:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0004e430:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0004e440:·7365·2220·6964·3d22·6964·6d31·3135·3130··se"·id="idm11510 
0004e450:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b63··"><pre><code>.[c 
0004e460:·7573·746f·6d69·7a61·7469·6f6e·732e·7365··ustomizations.se 
0004e470:·7276·6963·6573·5d0a·6d61·736b·6564·203d··rvices].masked·= 
0004e480:·205b·2261·7574·6f66·7322·5d0a·3c2f·636f···["autofs"].</co 
0004e490:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0004e4a0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0004e4b0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0004e4c0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0004e4d0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0004e4e0:·646d·3131·3531·3122·2074·6162·696e·6465··dm11511"·tabinde 
0004e4f0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0004e500:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0004e510:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0004e520:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0004e530:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0004e540:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib 
0004e550:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0004e560:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0004e570:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0004e580:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0004e590:·646d·3131·3531·3122·3e3c·7461·626c·6520··dm11511"><table· 
0004e5a0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0004e5b0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0004e5c0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0004e460:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0004e5d0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0004e5e0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0004e5f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0004e600:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0004e610:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0004e620:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0004e630:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0004e640:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0004e650:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0004e660:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di 
0004e670:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr>< 
0004e680:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0004e690:·653e·2d20·6e61·6d65·3a20·4761·7468·6572··e>-·name:·Gather 
0004e6a0:·2074·6865·2070·6163·6b61·6765·2066·6163···the·package·fac 
0004e6b0:·7473·0a20·2070·6163·6b61·6765·5f66·6163··ts.··package_fac 
0004e6c0:·7473·3a0a·2020·2020·6d61·6e61·6765·723a··ts:.····manager: 
0004e6d0:·2061·7574·6f0a·2020·7461·6773·3a0a·2020···auto.··tags:.··0004e470:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0004e480:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0004e490:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0004e4a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0004e4b0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0004e4c0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0004e4d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0004e4e0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0004e4f0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0004e500:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0004e510:·6567·793a·3c2f·7468·3e3c·7464·3e64·6973··egy:</th><td>dis
 0004e520:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0004e530:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0004e540:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather·
 0004e550:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact
 0004e560:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact
 0004e570:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:·
 0004e580:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··-
 0004e590:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.
 0004e5a0:·342e·360a·2020·2d20·4e49·5354·2d38·3030··4.6.··-·NIST-800
 0004e5b0:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-·
 0004e5c0:·4e49·5354·2d38·3030·2d35·332d·434d·2d37··NIST-800-53-CM-7
 0004e5d0:·2861·290a·2020·2d20·4e49·5354·2d38·3030··(a).··-·NIST-800
 0004e5e0:·2d35·332d·434d·2d37·2862·290a·2020·2d20··-53-CM-7(b).··-·
 0004e5f0:·4e49·5354·2d38·3030·2d35·332d·4d50·2d37··NIST-800-53-MP-7
 0004e600:·0a20·202d·2064·6973·6162·6c65·5f73·7472··.··-·disable_str
 0004e610:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co
 0004e620:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low
 0004e630:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
 0004e640:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.
 0004e650:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
 0004e660:·6564·6564·0a20·202d·2073·6572·7669·6365··eded.··-·service
 0004e670:·5f61·7574·6f66·735f·6469·7361·626c·6564··_autofs_disabled
 0004e680:·0a0a·2d20·6e61·6d65·3a20·4469·7361·626c··..-·name:·Disabl
 0004e690:·6520·7468·6520·4175·746f·6d6f·756e·7465··e·the·Automounte
 0004e6a0:·7220·2d20·436f·6c6c·6563·7420·7379·7374··r·-·Collect·syst
 0004e6b0:·656d·6420·5365·7276·6963·6573·2050·7265··emd·Services·Pre
 0004e6c0:·7365·6e74·2069·6e20·7468·6520·5379·7374··sent·in·the·Syst
 0004e6d0:·656d·0a20·2061·6e73·6962·6c65·2e62·7569··em.··ansible.bui
 0004e6e0:·6c74·696e·2e63·6f6d·6d61·6e64·3a20·7379··ltin.command:·sy
 0004e6f0:·7374·656d·6374·6c20·2d71·206c·6973·742d··stemctl·-q·list-
 0004e700:·756e·6974·2d66·696c·6573·202d·2d74·7970··unit-files·--typ
 0004e710:·6520·7365·7276·6963·650a·2020·7265·6769··e·service.··regi
 0004e720:·7374·6572·3a20·7365·7276·6963·655f·6578··ster:·service_ex
 0004e730:·6973·7473·0a20·2063·6861·6e67·6564·5f77··ists.··changed_w
 0004e740:·6865·6e3a·2066·616c·7365·0a20·2066·6169··hen:·false.··fai
 0004e750:·6c65·645f·7768·656e·3a20·7365·7276·6963··led_when:·servic
 0004e760:·655f·6578·6973·7473·2e72·6320·6e6f·7420··e_exists.rc·not·
 0004e770:·696e·205b·302c·2031·5d0a·2020·6368·6563··in·[0,·1].··chec
 0004e780:·6b5f·6d6f·6465·3a20·6661·6c73·650a·2020··k_mode:·false.··
 0004e790:·7768·656e·3a20·2820·2261·7574·6f66·7322··when:·(·"autofs"
 0004e7a0:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 0004e7b0:·732e·7061·636b·6167·6573·2061·6e64·2022··s.packages·and·"
 0004e7c0:·6b65·726e·656c·2220·696e·2061·6e73·6962··kernel"·in·ansib
 0004e7d0:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package
 0004e7e0:·730a·2020·2020·290a·2020·7461·6773·3a0a··s.····).··tags:.
0004e6e0:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-30004e7f0:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171
0004e6f0:·2e34·2e36·0a20·202d·204e·4953·542d·3830··.4.6.··-·NIST-800004e800:·2d33·2e34·2e36·0a20·202d·204e·4953·542d··-3.4.6.··-·NIST-
0004e700:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-0004e810:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).·
0004e710:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-0004e820:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
0004e720:·3728·6129·0a20·202d·204e·4953·542d·3830··7(a).··-·NIST-800004e830:·4d2d·3728·6129·0a20·202d·204e·4953·542d··M-7(a).··-·NIST-
0004e730:·302d·3533·2d43·4d2d·3728·6229·0a20·202d··0-53-CM-7(b).··-0004e840:·3830·302d·3533·2d43·4d2d·3728·6229·0a20··800-53-CM-7(b).·
0004e740:·204e·4953·542d·3830·302d·3533·2d4d·502d···NIST-800-53-MP-0004e850:·202d·204e·4953·542d·3830·302d·3533·2d4d···-·NIST-800-53-M
0004e750:·370a·2020·2d20·6469·7361·626c·655f·7374··7.··-·disable_st0004e860:·502d·370a·2020·2d20·6469·7361·626c·655f··P-7.··-·disable_
0004e760:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c0004e870:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
0004e770:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo0004e880:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
0004e780:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-0004e890:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
0004e790:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity0004e8a0:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
Max diff block lines reached; 160938/190498 bytes (84.48%) of diff not shown.
11.1 KB
html2text {}
    
Offset 1057, 18 lines modifiedOffset 1057, 14 lines modified
1057 ···························A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,1057 ···························A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,
1058 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,1058 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,
1059 ···························A.9.3.1,·A.9.4.2,·A.9.4.31059 ···························A.9.3.1,·A.9.4.2,·A.9.4.3
1060 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-71060 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1061 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-71061 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
1062 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-1062 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-
1063 ···························000480-GPOS-002271063 ···························000480-GPOS-00227
1064 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1065 [customizations.services] 
1066 masked·=·["autofs"] 
1067 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81064 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1068 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1065 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1069 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1066 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1070 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1067 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1071 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1068 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1072 -·name:·Gather·the·package·facts1069 -·name:·Gather·the·package·facts
1073 ··package_facts:1070 ··package_facts:
Offset 1167, 14 lines modifiedOffset 1163, 18 lines modified
1167 ··-·NIST-800-53-MP-71163 ··-·NIST-800-53-MP-7
1168 ··-·disable_strategy1164 ··-·disable_strategy
1169 ··-·low_complexity1165 ··-·low_complexity
1170 ··-·low_disruption1166 ··-·low_disruption
1171 ··-·medium_severity1167 ··-·medium_severity
1172 ··-·no_reboot_needed1168 ··-·no_reboot_needed
1173 ··-·service_autofs_disabled1169 ··-·service_autofs_disabled
 1170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1171 [customizations.services]
 1172 masked·=·["autofs"]
1174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1179 include·disable_autofs1178 include·disable_autofs
  
Offset 1227, 18 lines modifiedOffset 1227, 14 lines modified
1227 ···························SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR1227 ···························SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR
1228 ···························7.61228 ···························7.6
1229 ···························A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,1229 ···························A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,
1230 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,1230 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,
1231 ···························A.9.1.21231 ···························A.9.1.2
1232 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-6(a)1232 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-6(a)
1233 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41233 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1235 [customizations.services] 
1236 masked·=·["abrtd"] 
1237 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1238 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1239 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1240 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1241 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1242 -·name:·Gather·the·package·facts1239 -·name:·Gather·the·package·facts
1243 ··package_facts:1240 ··package_facts:
Offset 1321, 14 lines modifiedOffset 1317, 18 lines modified
1321 ··-·NIST-800-53-CM-7(a)1317 ··-·NIST-800-53-CM-7(a)
1322 ··-·disable_strategy1318 ··-·disable_strategy
1323 ··-·low_complexity1319 ··-·low_complexity
1324 ··-·low_disruption1320 ··-·low_disruption
1325 ··-·medium_severity1321 ··-·medium_severity
1326 ··-·no_reboot_needed1322 ··-·no_reboot_needed
1327 ··-·service_abrtd_disabled1323 ··-·service_abrtd_disabled
 1324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1325 [customizations.services]
 1326 masked·=·["abrtd"]
1328 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81327 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1329 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1328 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1330 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1329 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1331 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1330 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1332 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1331 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1333 include·disable_abrtd1332 include·disable_abrtd
  
Offset 1365, 18 lines modifiedOffset 1365, 14 lines modified
1365 ···························SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR1365 ···························SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR
1366 ···························7.61366 ···························7.6
1367 ···························A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,1367 ···························A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,
1368 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,1368 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,
1369 ···························A.9.1.21369 ···························A.9.1.2
1370 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)1370 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
1371 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41371 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1372 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1373 [customizations.services] 
1374 masked·=·["ntpdate"] 
1375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81372 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1376 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1373 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1377 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1374 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1378 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1375 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1379 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1376 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1380 -·name:·Gather·the·package·facts1377 -·name:·Gather·the·package·facts
1381 ··package_facts:1378 ··package_facts:
Offset 1464, 14 lines modifiedOffset 1460, 18 lines modified
1464 ··-·NIST-800-53-CM-7(b)1460 ··-·NIST-800-53-CM-7(b)
1465 ··-·disable_strategy1461 ··-·disable_strategy
1466 ··-·low_complexity1462 ··-·low_complexity
1467 ··-·low_disruption1463 ··-·low_disruption
1468 ··-·low_severity1464 ··-·low_severity
1469 ··-·no_reboot_needed1465 ··-·no_reboot_needed
1470 ··-·service_ntpdate_disabled1466 ··-·service_ntpdate_disabled
 1467 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1468 [customizations.services]
 1469 masked·=·["ntpdate"]
1471 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81470 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1472 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1471 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1473 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1472 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1474 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1473 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1475 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1474 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1476 include·disable_ntpdate1475 include·disable_ntpdate
  
Offset 1505, 18 lines modifiedOffset 1505, 14 lines modified
1505 ···························SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,1505 ···························SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,
1506 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR1506 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR
1507 ···························2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·7.61507 ···························2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·7.6
1508 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,1508 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
1509 ···························A.9.1.21509 ···························A.9.1.2
1510 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)1510 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
1511 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-31511 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
1512 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1513 [customizations.services] 
1514 masked·=·["oddjobd"] 
1515 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81512 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1516 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1513 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
Max diff block lines reached; 5625/11351 bytes (49.56%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-cis.html
    
Offset 15111, 213 lines modifiedOffset 15111, 213 lines modified
0003b060:·2d74·6172·6765·743d·2223·6964·6d33·3138··-target="#idm3180003b060:·2d74·6172·6765·743d·2223·6964·6d33·3138··-target="#idm318
0003b070:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·0003b070:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·
0003b080:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b080:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b090:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b090:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b0a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b0a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b0b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b0b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b0c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b0c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b0d0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003b0e0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b0f0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b100:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b110:·2220·6964·3d22·6964·6d33·3138·3722·3e3c··"·id="idm3187"><
 0003b120:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b130:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b140:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b150:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b160:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003b170:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003b180:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b190:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003b1a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b1b0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003b1c0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003b1d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b1e0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003b0d0:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003b0e0:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003b0f0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b100:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b110:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b120:·643d·2269·646d·3331·3837·223e·3c70·7265··d="idm3187"><pre 
0003b130:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003b140:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003b150:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003b160:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b170:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b180:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b190:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b1a0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b1b0:·743d·2223·6964·6d33·3138·3822·2074·6162··t="#idm3188"·tab 
0003b1c0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b1d0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b1e0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b1f0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b200:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b210:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003b220:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003b230:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b240:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b250:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b260:·6964·6d33·3138·3822·3e3c·7461·626c·6520··idm3188"><table· 
0003b270:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b280:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b290:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b2a0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b2b0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b2c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b2d0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003b2e0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003b2f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b300:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003b310:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b1f0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003b200:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b210:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003b220:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003b230:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003b240:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003b250:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k
 0003b260:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if·
 0003b270:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003b280:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 0003b290:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·-
 0003b2a0:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 0003b2b0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003b2c0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003b2d0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003b2e0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003b2f0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 0003b300:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b310:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b320:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b330:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b340:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b350:·6d33·3138·3822·2074·6162·696e·6465·783d··m3188"·tabindex=
 0003b360:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b370:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b380:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b390:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b3a0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b3b0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
0003b320:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b330:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003b340:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003b350:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003b360:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003b370:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003b380:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003b390:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·-- 
0003b3a0:·7175·6965·7420·2d71·206b·6572·6e65·6c3b··quiet·-q·kernel; 
0003b3b0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003b3c0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
0003b3d0:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf 
0003b3e0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003b3f0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
0003b400:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003b410:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003b420:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003b430:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003b440:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
0003b450:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b460:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b470:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b480:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b490:·6172·6765·743d·2223·6964·6d33·3138·3922··arget="#idm3189" 
0003b4a0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b4b0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b4c0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b4d0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b4e0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b4f0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b500:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003b510:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b520:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b530:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b540:·6522·2069·643d·2269·646d·3331·3839·223e··e"·id="idm3189"> 
0003b550:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b560:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
Max diff block lines reached; 967922/995964 bytes (97.18%) of diff not shown.
95.8 KB
html2text {}
    
Offset 119, 19 lines modifiedOffset 119, 14 lines modified
119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
123 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79123 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
124 ············_\x8c_\x8i_\x8s············6.1.1124 ············_\x8c_\x8i_\x8s············6.1.1
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
127 [[packages]] 
128 name·=·"aide" 
129 version·=·"*" 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
135 #·Remediation·is·applicable·only·in·certain·platforms131 #·Remediation·is·applicable·only·in·certain·platforms
136 if·rpm·--quiet·-q·kernel;·then132 if·rpm·--quiet·-q·kernel;·then
Offset 175, 33 lines modifiedOffset 170, 38 lines modified
175 ··-·PCI-DSSv4-11.5.2170 ··-·PCI-DSSv4-11.5.2
176 ··-·enable_strategy171 ··-·enable_strategy
177 ··-·low_complexity172 ··-·low_complexity
178 ··-·low_disruption173 ··-·low_disruption
179 ··-·medium_severity174 ··-·medium_severity
180 ··-·no_reboot_needed175 ··-·no_reboot_needed
181 ··-·package_aide_installed176 ··-·package_aide_installed
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·--add=aide
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 184 [[packages]]
 185 name·=·"aide"
 186 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
187 include·install_aide192 include·install_aide
  
188 class·install_aide·{193 class·install_aide·{
189 ··package·{·'aide':194 ··package·{·'aide':
190 ····ensure·=>·'installed',195 ····ensure·=>·'installed',
191 ··}196 ··}
192 }197 }
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
198 package·--add=aide 
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
200 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
201 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration
203 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only202 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only
204 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:203 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
205 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1547, 33 lines modifiedOffset 1547, 33 lines modified
1547 ··-·NIST-800-53-CM-7(b)1547 ··-·NIST-800-53-CM-7(b)
1548 ··-·disable_strategy1548 ··-·disable_strategy
1549 ··-·low_complexity1549 ··-·low_complexity
1550 ··-·low_disruption1550 ··-·low_disruption
1551 ··-·medium_severity1551 ··-·medium_severity
1552 ··-·no_reboot_needed1552 ··-·no_reboot_needed
1553 ··-·package_gdm_removed1553 ··-·package_gdm_removed
 1554 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1555 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1556 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1557 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1558 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1559 package·--remove=gdm
1554 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81560 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1555 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1561 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1556 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1562 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1557 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1563 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1558 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1564 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1559 include·remove_gdm1565 include·remove_gdm
  
1560 class·remove_gdm·{1566 class·remove_gdm·{
1561 ··package·{·'gdm':1567 ··package·{·'gdm':
1562 ····ensure·=>·'purged',1568 ····ensure·=>·'purged',
1563 ··}1569 ··}
1564 }1570 }
1565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1566 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1567 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1568 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1569 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
1570 package·--remove=gdm 
1571 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1571 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1572 By·default,·DConf·uses·a·binary·database·as·a·data·backend.·The·system-level·database·is·compiled·from·keyfiles·in·the·/etc/1572 By·default,·DConf·uses·a·binary·database·as·a·data·backend.·The·system-level·database·is·compiled·from·keyfiles·in·the·/etc/
1573 dconf/db/·directory·by·the1573 dconf/db/·directory·by·the
1574 dconf·update1574 dconf·update
1575 command.·More·specifically,·content·present·in·the·following·directories:1575 command.·More·specifically,·content·present·in·the·following·directories:
1576 /etc/dconf/db/gdm.d1576 /etc/dconf/db/gdm.d
1577 /etc/dconf/db/local.d1577 /etc/dconf/db/local.d
Offset 1650, 19 lines modifiedOffset 1650, 14 lines modified
1650 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861650 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1651 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1651 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1652 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11652 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1653 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251653 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1654 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331654 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1655 ············_\x8c_\x8i_\x8s·····5.2.11655 ············_\x8c_\x8i_\x8s·····5.2.1
1656 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21656 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1657 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1658 [[packages]] 
1659 name·=·"sudo" 
1660 version·=·"*" 
1661 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81657 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1662 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1658 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1663 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1659 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1664 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1660 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1665 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1661 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1666 #·Remediation·is·applicable·only·in·certain·platforms1662 #·Remediation·is·applicable·only·in·certain·platforms
1667 if·rpm·--quiet·-q·kernel;·then1663 if·rpm·--quiet·-q·kernel;·then
Offset 1704, 33 lines modifiedOffset 1699, 38 lines modified
Max diff block lines reached; 92816/98047 bytes (94.66%) of diff not shown.
881 KB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-cis_server_l1.html
    
Offset 15073, 213 lines modifiedOffset 15073, 213 lines modified
0003ae00:·6574·3d22·2369·646d·3331·3837·2220·7461··et="#idm3187"·ta0003ae00:·6574·3d22·2369·646d·3331·3837·2220·7461··et="#idm3187"·ta
0003ae10:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003ae10:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003ae20:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003ae20:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003ae30:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003ae30:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003ae40:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003ae40:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003ae50:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003ae50:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003ae60:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003ae60:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003ae70:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003ae80:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003ae90:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003aea0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003aeb0:·2269·646d·3331·3837·223e·3c74·6162·6c65··"idm3187"><table
 0003aec0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003aed0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003aee0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003aef0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003af00:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003af10:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003af20:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003af30:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003af40:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003af50:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003af60:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003af70:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003af80:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003ae70:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003ae80:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003ae90:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003aea0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003aeb0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003aec0:·6d33·3138·3722·3e3c·7072·653e·3c63·6f64··m3187"><pre><cod 
0003aed0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003aee0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003aef0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003af00:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003af10:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003af20:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003af30:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003af40:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003af50:·646d·3331·3838·2220·7461·6269·6e64·6578··dm3188"·tabindex 
0003af60:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003af70:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003af80:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003af90:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003afa0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003afb0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003afc0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003afd0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003afe0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003aff0:·6c61·7073·6522·2069·643d·2269·646d·3331··lapse"·id="idm31 
0003b000:·3838·223e·3c74·6162·6c65·2063·6c61·7373··88"><table·class 
0003b010:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b020:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b030:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b040:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b050:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b060:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b070:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b080:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b090:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b0a0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b0b0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003af90:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003afa0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003afb0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
 0003afc0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on
 0003afd0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl
 0003afe0:·6174·666f·726d·730a·6966·2072·706d·202d··atforms.if·rpm·-
 0003aff0:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel
 0003b000:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 0003b010:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid
 0003b020:·6522·203b·2074·6865·6e0a·2020·2020·646e··e"·;·then.····dn
 0003b030:·6620·696e·7374·616c·6c20·2d79·2022·6169··f·install·-y·"ai
 0003b040:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.···
 0003b050:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo
0003b0c0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b0d0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b0e0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b0f0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
0003b100:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b110:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b120:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b130:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
0003b140:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
0003b150:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b160:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b170:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
0003b180:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b190:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b1a0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b1b0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b1c0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b1d0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b1e0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b1f0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b200:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b210:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b220:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b230:·3d22·2369·646d·3331·3839·2220·7461·6269··="#idm3189"·tabi 
0003b240:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b250:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b260:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b270:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b280:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b290:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b060:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is
 0003b070:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable,
 0003b080:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don
 0003b090:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p
 0003b0a0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003b0b0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003b0c0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003b0d0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003b0e0:·7461·7267·6574·3d22·2369·646d·3331·3838··target="#idm3188
 0003b0f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003b100:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003b110:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003b120:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003b130:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003b140:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b150:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip
0003b2a0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b2b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b2c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b2d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b2e0:·3d22·6964·6d33·3138·3922·3e3c·7461·626c··="idm3189"><tabl 
0003b2f0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b300:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b310:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
Max diff block lines reached; 794500/822542 bytes (96.59%) of diff not shown.
77.2 KB
html2text {}
    
Offset 113, 19 lines modifiedOffset 113, 14 lines modified
113 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)113 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
114 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3114 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
118 ············_\x8c_\x8i_\x8s············6.1.1118 ············_\x8c_\x8i_\x8s············6.1.1
119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
121 [[packages]] 
122 name·=·"aide" 
123 version·=·"*" 
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
129 #·Remediation·is·applicable·only·in·certain·platforms125 #·Remediation·is·applicable·only·in·certain·platforms
130 if·rpm·--quiet·-q·kernel;·then126 if·rpm·--quiet·-q·kernel;·then
Offset 169, 33 lines modifiedOffset 164, 38 lines modified
169 ··-·PCI-DSSv4-11.5.2164 ··-·PCI-DSSv4-11.5.2
170 ··-·enable_strategy165 ··-·enable_strategy
171 ··-·low_complexity166 ··-·low_complexity
172 ··-·low_disruption167 ··-·low_disruption
173 ··-·medium_severity168 ··-·medium_severity
174 ··-·no_reboot_needed169 ··-·no_reboot_needed
175 ··-·package_aide_installed170 ··-·package_aide_installed
 171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 176 package·--add=aide
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 178 [[packages]]
 179 name·=·"aide"
 180 version·=·"*"
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
181 include·install_aide186 include·install_aide
  
182 class·install_aide·{187 class·install_aide·{
183 ··package·{·'aide':188 ··package·{·'aide':
184 ····ensure·=>·'installed',189 ····ensure·=>·'installed',
185 ··}190 ··}
186 }191 }
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
192 package·--add=aide 
193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
194 Run·the·following·command·to·generate·a·new·database:193 Run·the·following·command·to·generate·a·new·database:
195 $·sudo·/usr/sbin/aide·--init194 $·sudo·/usr/sbin/aide·--init
196 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration195 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration
197 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only196 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only
198 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:197 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
199 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz198 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1432, 19 lines modifiedOffset 1432, 14 lines modified
1432 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861432 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1433 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1433 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1434 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11434 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1435 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251435 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1436 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331436 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1437 ············_\x8c_\x8i_\x8s·····5.2.11437 ············_\x8c_\x8i_\x8s·····5.2.1
1438 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21438 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1440 [[packages]] 
1441 name·=·"sudo" 
1442 version·=·"*" 
1443 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1444 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1445 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1446 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1447 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1448 #·Remediation·is·applicable·only·in·certain·platforms1444 #·Remediation·is·applicable·only·in·certain·platforms
1449 if·rpm·--quiet·-q·kernel;·then1445 if·rpm·--quiet·-q·kernel;·then
Offset 1486, 33 lines modifiedOffset 1481, 38 lines modified
1486 ··-·PCI-DSSv4-2.2.61481 ··-·PCI-DSSv4-2.2.6
1487 ··-·enable_strategy1482 ··-·enable_strategy
1488 ··-·low_complexity1483 ··-·low_complexity
1489 ··-·low_disruption1484 ··-·low_disruption
1490 ··-·medium_severity1485 ··-·medium_severity
1491 ··-·no_reboot_needed1486 ··-·no_reboot_needed
1492 ··-·package_sudo_installed1487 ··-·package_sudo_installed
 1488 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1489 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1490 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1491 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1492 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1493 package·--add=sudo
 1494 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1495 [[packages]]
 1496 name·=·"sudo"
 1497 version·=·"*"
1493 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81498 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1494 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1499 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1495 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1500 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1496 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1501 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1497 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1502 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1498 include·install_sudo1503 include·install_sudo
  
1499 class·install_sudo·{1504 class·install_sudo·{
1500 ··package·{·'sudo':1505 ··package·{·'sudo':
1501 ····ensure·=>·'installed',1506 ····ensure·=>·'installed',
1502 ··}1507 ··}
1503 }1508 }
1504 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1505 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1506 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1507 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1508 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1509 package·--add=sudo 
1510 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1509 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1511 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be1510 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be
1512 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/1511 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/
Max diff block lines reached; 73715/79021 bytes (93.29%) of diff not shown.
697 KB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-cis_workstation_l1.html
    
Offset 15064, 213 lines modifiedOffset 15064, 213 lines modified
0003ad70:·612d·7461·7267·6574·3d22·2369·646d·3331··a-target="#idm310003ad70:·612d·7461·7267·6574·3d22·2369·646d·3331··a-target="#idm31
0003ad80:·3837·2220·7461·6269·6e64·6578·3d22·3022··87"·tabindex="0"0003ad80:·3837·2220·7461·6269·6e64·6578·3d22·3022··87"·tabindex="0"
0003ad90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003ad90:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003ada0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003ada0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003adb0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003adb0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003adc0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003adc0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003add0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003add0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003ade0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003adf0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003ae00:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003ae10:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003ae20:·6522·2069·643d·2269·646d·3331·3837·223e··e"·id="idm3187">
 0003ae30:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003ae40:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003ade0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003adf0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003ae00:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003ae10:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003ae20:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003ae30:·6964·3d22·6964·6d33·3138·3722·3e3c·7072··id="idm3187"><pr 
0003ae40:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003ae50:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003ae60:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003ae70:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003ae80:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003ae90:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003aea0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003aeb0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003aec0:·6574·3d22·2369·646d·3331·3838·2220·7461··et="#idm3188"·ta 
0003aed0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003aee0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003aef0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003af00:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003af10:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003af20:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003af30:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
0003af40:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003af50:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003af60:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003af70:·2269·646d·3331·3838·223e·3c74·6162·6c65··"idm3188"><table 
0003af80:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003af90:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003afa0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003afb0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003afc0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003afd0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003afe0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003aff0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b000:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b010:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b020:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b030:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b040:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b050:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b060:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b070:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b080:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b090:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b0a0:·6174·666f·726d·730a·6966·2072·706d·202d··atforms.if·rpm·- 
0003b0b0:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel 
0003b0c0:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm 
0003b0d0:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid 
0003b0e0:·6522·203b·2074·6865·6e0a·2020·2020·646e··e"·;·then.····dn 
0003b0f0:·6620·696e·7374·616c·6c20·2d79·2022·6169··f·install·-y·"ai 
0003b100:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.··· 
0003b110:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003b120:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003b130:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003b140:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003b150:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003b160:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b170:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b180:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b190:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b1a0:·7461·7267·6574·3d22·2369·646d·3331·3839··target="#idm3189 
0003b1b0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b1c0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b1d0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b1e0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b1f0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b200:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b210:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003b220:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b230:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b240:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b250:·7365·2220·6964·3d22·6964·6d33·3138·3922··se"·id="idm3189" 
0003b260:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003b270:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b280:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b290:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003ae50:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003ae60:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003ae70:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003ae80:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003ae90:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003aea0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003aeb0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003aec0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003aed0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003aee0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003aef0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003af00:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003af10:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003af20:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003af30:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003af40:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003af50:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003af60:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 0003af70:·6b65·726e·656c·3b20·7468·656e·0a0a·6966··kernel;·then..if
 0003af80:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003af90:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then.
 0003afa0:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install·
 0003afb0:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el
 0003afc0:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0003afd0:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0003afe0:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0003aff0:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0003b000:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
 0003b010:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003b020:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b030:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003b040:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003b050:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003b060:·646d·3331·3838·2220·7461·6269·6e64·6578··dm3188"·tabindex
 0003b070:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003b080:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003b090:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003b0a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
Max diff block lines reached; 615230/643272 bytes (95.64%) of diff not shown.
68.6 KB
html2text {}
    
Offset 112, 19 lines modifiedOffset 112, 14 lines modified
112 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)112 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3113 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5114 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
116 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79116 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
117 ············_\x8c_\x8i_\x8s············6.1.1117 ············_\x8c_\x8i_\x8s············6.1.1
118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
120 [[packages]] 
121 name·=·"aide" 
122 version·=·"*" 
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
128 #·Remediation·is·applicable·only·in·certain·platforms124 #·Remediation·is·applicable·only·in·certain·platforms
129 if·rpm·--quiet·-q·kernel;·then125 if·rpm·--quiet·-q·kernel;·then
Offset 168, 33 lines modifiedOffset 163, 38 lines modified
168 ··-·PCI-DSSv4-11.5.2163 ··-·PCI-DSSv4-11.5.2
169 ··-·enable_strategy164 ··-·enable_strategy
170 ··-·low_complexity165 ··-·low_complexity
171 ··-·low_disruption166 ··-·low_disruption
172 ··-·medium_severity167 ··-·medium_severity
173 ··-·no_reboot_needed168 ··-·no_reboot_needed
174 ··-·package_aide_installed169 ··-·package_aide_installed
 170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 175 package·--add=aide
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 177 [[packages]]
 178 name·=·"aide"
 179 version·=·"*"
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
180 include·install_aide185 include·install_aide
  
181 class·install_aide·{186 class·install_aide·{
182 ··package·{·'aide':187 ··package·{·'aide':
183 ····ensure·=>·'installed',188 ····ensure·=>·'installed',
184 ··}189 ··}
185 }190 }
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
191 package·--add=aide 
192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*191 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
193 Run·the·following·command·to·generate·a·new·database:192 Run·the·following·command·to·generate·a·new·database:
194 $·sudo·/usr/sbin/aide·--init193 $·sudo·/usr/sbin/aide·--init
195 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration194 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration
196 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only195 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only
197 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:196 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
198 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz197 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1258, 19 lines modifiedOffset 1258, 14 lines modified
1258 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861258 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1259 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1259 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1260 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11260 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1261 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251261 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1262 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331262 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1263 ············_\x8c_\x8i_\x8s·····5.2.11263 ············_\x8c_\x8i_\x8s·····5.2.1
1264 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21264 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1265 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1266 [[packages]] 
1267 name·=·"sudo" 
1268 version·=·"*" 
1269 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81265 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1270 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1266 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1271 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1267 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1272 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1268 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1273 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1269 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1274 #·Remediation·is·applicable·only·in·certain·platforms1270 #·Remediation·is·applicable·only·in·certain·platforms
1275 if·rpm·--quiet·-q·kernel;·then1271 if·rpm·--quiet·-q·kernel;·then
Offset 1312, 33 lines modifiedOffset 1307, 38 lines modified
1312 ··-·PCI-DSSv4-2.2.61307 ··-·PCI-DSSv4-2.2.6
1313 ··-·enable_strategy1308 ··-·enable_strategy
1314 ··-·low_complexity1309 ··-·low_complexity
1315 ··-·low_disruption1310 ··-·low_disruption
1316 ··-·medium_severity1311 ··-·medium_severity
1317 ··-·no_reboot_needed1312 ··-·no_reboot_needed
1318 ··-·package_sudo_installed1313 ··-·package_sudo_installed
 1314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1315 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1316 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1317 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1318 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1319 package·--add=sudo
 1320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1321 [[packages]]
 1322 name·=·"sudo"
 1323 version·=·"*"
1319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1320 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1325 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1321 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1326 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1322 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1327 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1323 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1328 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1324 include·install_sudo1329 include·install_sudo
  
1325 class·install_sudo·{1330 class·install_sudo·{
1326 ··package·{·'sudo':1331 ··package·{·'sudo':
1327 ····ensure·=>·'installed',1332 ····ensure·=>·'installed',
1328 ··}1333 ··}
1329 }1334 }
1330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1335 package·--add=sudo 
1336 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1335 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1337 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be1336 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be
1338 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/1337 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/
Max diff block lines reached; 64879/70185 bytes (92.44%) of diff not shown.
995 KB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-cis_workstation_l2.html
    
Offset 15103, 213 lines modifiedOffset 15103, 213 lines modified
0003afe0:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm30003afe0:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm3
0003aff0:·3138·3722·2074·6162·696e·6465·783d·2230··187"·tabindex="00003aff0:·3138·3722·2074·6162·696e·6465·783d·2230··187"·tabindex="0
0003b000:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b000:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b010:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b010:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b020:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b020:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b030:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b030:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b040:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b040:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b050:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B0003b050:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 0003b060:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003b070:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b080:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b090:·7365·2220·6964·3d22·6964·6d33·3138·3722··se"·id="idm3187"
 0003b0a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003b0b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003b060:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
0003b070:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b080:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b090:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b0a0:·2069·643d·2269·646d·3331·3837·223e·3c70···id="idm3187"><p 
0003b0b0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
0003b0c0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a 
0003b0d0:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·" 
0003b0e0:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
0003b0f0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b100:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b110:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b120:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b130:·6765·743d·2223·6964·6d33·3138·3822·2074··get="#idm3188"·t 
0003b140:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b150:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b160:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b170:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b180:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b190:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b1a0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003b1b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b1c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b1d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b1e0:·3d22·6964·6d33·3138·3822·3e3c·7461·626c··="idm3188"><tabl 
0003b1f0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b200:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b210:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b220:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b230:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b240:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b250:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b260:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b270:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b280:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b290:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b2a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b2b0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b2c0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b2d0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b2e0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003b2f0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003b300:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003b310:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm· 
0003b320:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003b330:·6c3b·2074·6865·6e0a·0a69·6620·2120·7270··l;·then..if·!·rp 
0003b340:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003b350:·6465·2220·3b20·7468·656e·0a20·2020·2064··de"·;·then.····d 
0003b360:·6e66·2069·6e73·7461·6c6c·202d·7920·2261··nf·install·-y·"a 
0003b370:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003b380:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003b390:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003b3a0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003b3b0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003b3c0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003b3d0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b3e0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b3f0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b400:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b410:·2d74·6172·6765·743d·2223·6964·6d33·3138··-target="#idm318 
0003b420:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"· 
0003b430:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b440:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b450:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b460:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b470:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b480:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003b490:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b4a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b4b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b4c0:·7073·6522·2069·643d·2269·646d·3331·3839··pse"·id="idm3189 
0003b4d0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b4e0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b4f0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b500:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b0c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003b0d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003b0e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003b0f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003b100:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b110:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 0003b120:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b130:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003b140:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 0003b150:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 0003b160:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 0003b170:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 0003b180:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003b190:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 0003b1a0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 0003b1b0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 0003b1c0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 0003b1d0:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q
 0003b1e0:·206b·6572·6e65·6c3b·2074·6865·6e0a·0a69···kernel;·then..i
 0003b1f0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
 0003b200:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then
 0003b210:·0a20·2020·2064·6e66·2069·6e73·7461·6c6c··.····dnf·install
 0003b220:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e
 0003b230:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp
 0003b240:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia
 0003b250:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl
 0003b260:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·
 0003b270:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c
 0003b280:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b290:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b2a0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b2b0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b2c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b2d0:·6964·6d33·3138·3822·2074·6162·696e·6465··idm3188"·tabinde
 0003b2e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b2f0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b300:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b310:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b320:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
Max diff block lines reached; 900052/928094 bytes (96.98%) of diff not shown.
89.0 KB
html2text {}
    
Offset 118, 19 lines modifiedOffset 118, 14 lines modified
118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
123 ············_\x8c_\x8i_\x8s············6.1.1123 ············_\x8c_\x8i_\x8s············6.1.1
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
126 [[packages]] 
127 name·=·"aide" 
128 version·=·"*" 
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
134 #·Remediation·is·applicable·only·in·certain·platforms130 #·Remediation·is·applicable·only·in·certain·platforms
135 if·rpm·--quiet·-q·kernel;·then131 if·rpm·--quiet·-q·kernel;·then
Offset 174, 33 lines modifiedOffset 169, 38 lines modified
174 ··-·PCI-DSSv4-11.5.2169 ··-·PCI-DSSv4-11.5.2
175 ··-·enable_strategy170 ··-·enable_strategy
176 ··-·low_complexity171 ··-·low_complexity
177 ··-·low_disruption172 ··-·low_disruption
178 ··-·medium_severity173 ··-·medium_severity
179 ··-·no_reboot_needed174 ··-·no_reboot_needed
180 ··-·package_aide_installed175 ··-·package_aide_installed
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 181 package·--add=aide
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
186 include·install_aide191 include·install_aide
  
187 class·install_aide·{192 class·install_aide·{
188 ··package·{·'aide':193 ··package·{·'aide':
189 ····ensure·=>·'installed',194 ····ensure·=>·'installed',
190 ··}195 ··}
191 }196 }
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·--add=aide 
198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
199 Run·the·following·command·to·generate·a·new·database:198 Run·the·following·command·to·generate·a·new·database:
200 $·sudo·/usr/sbin/aide·--init199 $·sudo·/usr/sbin/aide·--init
201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration
202 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only201 file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only
203 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:202 media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz203 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1562, 19 lines modifiedOffset 1562, 14 lines modified
1562 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861562 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1563 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1563 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1564 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11564 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1565 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251565 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1566 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331566 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1567 ············_\x8c_\x8i_\x8s·····5.2.11567 ············_\x8c_\x8i_\x8s·····5.2.1
1568 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21568 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1570 [[packages]] 
1571 name·=·"sudo" 
1572 version·=·"*" 
1573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1574 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1570 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1575 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1571 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1576 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1572 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1577 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1573 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1578 #·Remediation·is·applicable·only·in·certain·platforms1574 #·Remediation·is·applicable·only·in·certain·platforms
1579 if·rpm·--quiet·-q·kernel;·then1575 if·rpm·--quiet·-q·kernel;·then
Offset 1616, 33 lines modifiedOffset 1611, 38 lines modified
1616 ··-·PCI-DSSv4-2.2.61611 ··-·PCI-DSSv4-2.2.6
1617 ··-·enable_strategy1612 ··-·enable_strategy
1618 ··-·low_complexity1613 ··-·low_complexity
1619 ··-·low_disruption1614 ··-·low_disruption
1620 ··-·medium_severity1615 ··-·medium_severity
1621 ··-·no_reboot_needed1616 ··-·no_reboot_needed
1622 ··-·package_sudo_installed1617 ··-·package_sudo_installed
 1618 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1619 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1620 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1621 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1622 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1623 package·--add=sudo
 1624 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1625 [[packages]]
 1626 name·=·"sudo"
 1627 version·=·"*"
1623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81628 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1624 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1629 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1625 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1630 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1626 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1631 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1627 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1632 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1628 include·install_sudo1633 include·install_sudo
  
1629 class·install_sudo·{1634 class·install_sudo·{
1630 ··package·{·'sudo':1635 ··package·{·'sudo':
1631 ····ensure·=>·'installed',1636 ····ensure·=>·'installed',
1632 ··}1637 ··}
1633 }1638 }
1634 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1635 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1636 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1637 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1638 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1639 package·--add=sudo 
1640 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1639 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1641 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be1640 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be
1642 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/1641 enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/
Max diff block lines reached; 85783/91089 bytes (94.17%) of diff not shown.
338 KB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-hipaa.html
    
Offset 20328, 290 lines modifiedOffset 20328, 290 lines modified
0004f670:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0004f670:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0004f680:·2369·646d·3735·3038·2220·7461·6269·6e64··#idm7508"·tabind0004f680:·2369·646d·3735·3038·2220·7461·6269·6e64··#idm7508"·tabind
0004f690:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0004f690:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0004f6a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0004f6a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0004f6b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0004f6b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0004f6c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0004f6c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0004f6d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0004f6d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0004f6e0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0004f6e0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
0004f6f0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0004f700:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0004f710:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0004f720:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0004f730:·6170·7365·2220·6964·3d22·6964·6d37·3530··apse"·id="idm750 
0004f740:·3822·3e3c·7072·653e·3c63·6f64·653e·0a5b··8"><pre><code>.[ 
0004f750:·6375·7374·6f6d·697a·6174·696f·6e73·2e73··customizations.s 
0004f760:·6572·7669·6365·735d·0a6d·6173·6b65·6420··ervices].masked· 
0004f770:·3d20·5b22·6465·6275·672d·7368·656c·6c22··=·["debug-shell" 
0004f780:·5d0a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··].</code></pre>< 
0004f790:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0004f7a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0004f7b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0004f7c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0004f7d0:·6574·3d22·2369·646d·3735·3039·2220·7461··et="#idm7509"·ta 
0004f7e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0004f7f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0004f800:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0004f810:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0004f820:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0004f830:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0004f840:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...0004f6f0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
0004f850:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0004f700:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0004f860:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0004f710:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0004f870:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0004f720:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0004f880:·2269·646d·3735·3039·223e·3c74·6162·6c65··"idm7509"><table0004f730:·3735·3038·223e·3c74·6162·6c65·2063·6c61··7508"><table·cla
0004f890:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0004f740:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0004f8a0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0004f750:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0004f8b0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0004f760:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0004f8c0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0004f770:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0004f8d0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0004f780:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0004f8e0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0004f790:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0004f8f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0004f7a0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0004f900:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0004f910:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0004f920:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0004f930:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0004f940:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0004f950:·6174·6567·793a·3c2f·7468·3e3c·7464·3e64··ategy:</th><td>d 
0004f960:·6973·6162·6c65·3c2f·7464·3e3c·2f74·723e··isable</td></tr> 
0004f970:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0004f980:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0004f990:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0004f9a0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0004f9b0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm· 
0004f9c0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0004f9d0:·6c3b·2074·6865·6e0a·0a53·5953·5445·4d43··l;·then..SYSTEMC 
0004f9e0:·544c·5f45·5845·433d·272f·7573·722f·6269··TL_EXEC='/usr/bi 
0004f9f0:·6e2f·7379·7374·656d·6374·6c27·0a69·6620··n/systemctl'.if· 
0004fa00:·5b5b·2024·2822·2453·5953·5445·4d43·544c··[[·$("$SYSTEMCTL 
0004fa10:·5f45·5845·4322·2069·732d·7379·7374·656d··_EXEC"·is-system 
0004fa20:·2d72·756e·6e69·6e67·2920·213d·2022·6f66··-running)·!=·"of 
0004fa30:·666c·696e·6522·205d·5d3b·2074·6865·6e0a··fline"·]];·then. 
0004fa40:·2020·2224·5359·5354·454d·4354·4c5f·4558····"$SYSTEMCTL_EX 
0004fa50:·4543·2220·7374·6f70·2027·6465·6275·672d··EC"·stop·'debug- 
0004fa60:·7368·656c·6c2e·7365·7276·6963·6527·0a66··shell.service'.f 
0004fa70:·690a·2224·5359·5354·454d·4354·4c5f·4558··i."$SYSTEMCTL_EX 
0004fa80:·4543·2220·6469·7361·626c·6520·2764·6562··EC"·disable·'deb 
0004fa90:·7567·2d73·6865·6c6c·2e73·6572·7669·6365··ug-shell.service 
0004faa0:·270a·2224·5359·5354·454d·4354·4c5f·4558··'."$SYSTEMCTL_EX 
0004fab0:·4543·2220·6d61·736b·2027·6465·6275·672d··EC"·mask·'debug- 
0004fac0:·7368·656c·6c2e·7365·7276·6963·6527·0a23··shell.service'.# 
0004fad0:·2044·6973·6162·6c65·2073·6f63·6b65·7420···Disable·socket· 
0004fae0:·6163·7469·7661·7469·6f6e·2069·6620·7765··activation·if·we 
0004faf0:·2068·6176·6520·6120·756e·6974·2066·696c···have·a·unit·fil 
0004fb00:·6520·666f·7220·6974·0a69·6620·2224·5359··e·for·it.if·"$SY 
0004fb10:·5354·454d·4354·4c5f·4558·4543·2220·2d71··STEMCTL_EXEC"·-q 
0004fb20:·206c·6973·742d·756e·6974·2d66·696c·6573···list-unit-files 
0004fb30:·2064·6562·7567·2d73·6865·6c6c·2e73·6f63···debug-shell.soc 
0004fb40:·6b65·743b·2074·6865·6e0a·2020·2020·6966··ket;·then.····if 
0004fb50:·205b·5b20·2428·2224·5359·5354·454d·4354···[[·$("$SYSTEMCT 
0004fb60:·4c5f·4558·4543·2220·6973·2d73·7973·7465··L_EXEC"·is-syste 
0004fb70:·6d2d·7275·6e6e·696e·6729·2021·3d20·226f··m-running)·!=·"o 
0004fb80:·6666·6c69·6e65·2220·5d5d·3b20·7468·656e··ffline"·]];·then 
0004fb90:·0a20·2020·2020·2022·2453·5953·5445·4d43··.······"$SYSTEMC 
0004fba0:·544c·5f45·5845·4322·2073·746f·7020·2764··TL_EXEC"·stop·'d 
0004fbb0:·6562·7567·2d73·6865·6c6c·2e73·6f63·6b65··ebug-shell.socke 
0004fbc0:·7427·0a20·2020·2066·690a·2020·2020·2224··t'.····fi.····"$ 
0004fbd0:·5359·5354·454d·4354·4c5f·4558·4543·2220··SYSTEMCTL_EXEC"· 
0004fbe0:·6d61·736b·2027·6465·6275·672d·7368·656c··mask·'debug-shel 
0004fbf0:·6c2e·736f·636b·6574·270a·6669·0a23·2054··l.socket'.fi.#·T 
0004fc00:·6865·2073·6572·7669·6365·206d·6179·206e··he·service·may·n 
0004fc10:·6f74·2062·6520·7275·6e6e·696e·6720·6265··ot·be·running·be 
0004fc20:·6361·7573·6520·6974·2068·6173·2062·6565··cause·it·has·bee 
0004fc30:·6e20·7374·6172·7465·6420·616e·6420·6661··n·started·and·fa 
0004fc40:·696c·6564·2c0a·2320·736f·206c·6574·2773··iled,.#·so·let's 
0004fc50:·2072·6573·6574·2074·6865·2073·7461·7465···reset·the·state 
0004fc60:·2073·6f20·4f56·414c·2063·6865·636b·7320···so·OVAL·checks· 
0004fc70:·7061·7373·2e0a·2320·5365·7276·6963·6520··pass..#·Service· 
0004fc80:·7368·6f75·6c64·2062·6520·2769·6e61·6374··should·be·'inact 
0004fc90:·6976·6527·2c20·6e6f·7420·2766·6169·6c65··ive',·not·'faile 
0004fca0:·6427·2061·6674·6572·2072·6562·6f6f·7420··d'·after·reboot· 
0004fcb0:·7468·6f75·6768·2e0a·2224·5359·5354·454d··though.."$SYSTEM 
0004fcc0:·4354·4c5f·4558·4543·2220·7265·7365·742d··CTL_EXEC"·reset- 
0004fcd0:·6661·696c·6564·2027·6465·6275·672d·7368··failed·'debug-sh 
0004fce0:·656c·6c2e·7365·7276·6963·6527·207c·7c20··ell.service'·||· 
0004fcf0:·7472·7565·0a0a·656c·7365·0a20·2020·2026··true..else.····& 
0004fd00:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0004fd10:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0004fd20:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0004fd30:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0004fd40:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0004fd50:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0004fd60:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0004fd70:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0004fd80:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0004fd90:·7267·6574·3d22·2369·646d·3735·3130·2220··rget="#idm7510"· 
0004fda0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0004fdb0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0004fdc0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0004fdd0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0004fde0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0004fdf0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0004fe00:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0004fe10:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0004fe20:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0004fe30:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0004fe40:·2220·6964·3d22·6964·6d37·3531·3022·3e3c··"·id="idm7510">< 
0004fe50:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
Max diff block lines reached; 283618/322286 bytes (88.00%) of diff not shown.
23.5 KB
html2text {}
    
Offset 1103, 18 lines modifiedOffset 1103, 14 lines modified
1103 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-0022351103 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
1104 ···················164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)1104 ···················164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)
1105 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),1105 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),
1106 ···················164.310(d)(2)(iii)1106 ···················164.310(d)(2)(iii)
1107 ············_\x8n_\x8i_\x8s_\x8t···CM-61107 ············_\x8n_\x8i_\x8s_\x8t···CM-6
1108 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.11108 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
1109 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271109 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1111 [customizations.services] 
1112 masked·=·["debug-shell"] 
1113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1118 #·Remediation·is·applicable·only·in·certain·platforms1115 #·Remediation·is·applicable·only·in·certain·platforms
1119 if·rpm·--quiet·-q·kernel;·then1116 if·rpm·--quiet·-q·kernel;·then
Offset 1226, 14 lines modifiedOffset 1222, 18 lines modified
1226 ··-·NIST-800-53-CM-61222 ··-·NIST-800-53-CM-6
1227 ··-·disable_strategy1223 ··-·disable_strategy
1228 ··-·low_complexity1224 ··-·low_complexity
1229 ··-·low_disruption1225 ··-·low_disruption
1230 ··-·medium_severity1226 ··-·medium_severity
1231 ··-·no_reboot_needed1227 ··-·no_reboot_needed
1232 ··-·service_debug-shell_disabled1228 ··-·service_debug-shell_disabled
 1229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1230 [customizations.services]
 1231 masked·=·["debug-shell"]
1233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1233 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1234 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1235 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1236 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1238 include·disable_debug-shell1237 include·disable_debug-shell
  
Offset 2558, 18 lines modifiedOffset 2558, 14 lines modified
2558 ···························1.9,·SR·2.1,·SR·2.62558 ···························1.9,·SR·2.1,·SR·2.6
2559 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,2559 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,
2560 ···························A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32560 ···························A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2561 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72561 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2562 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72562 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2563 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272563 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2564 ············_\x8c_\x8i_\x8s············2.1.12564 ············_\x8c_\x8i_\x8s············2.1.1
2565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2566 [customizations.services] 
2567 masked·=·["autofs"] 
2568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2566 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2567 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2568 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2569 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2573 #·Remediation·is·applicable·only·in·certain·platforms2570 #·Remediation·is·applicable·only·in·certain·platforms
2574 if·(·rpm·--quiet·-q·autofs·&&·rpm·--quiet·-q·kernel·);·then2571 if·(·rpm·--quiet·-q·autofs·&&·rpm·--quiet·-q·kernel·);·then
Offset 2697, 14 lines modifiedOffset 2693, 18 lines modified
2697 ··-·NIST-800-53-MP-72693 ··-·NIST-800-53-MP-7
2698 ··-·disable_strategy2694 ··-·disable_strategy
2699 ··-·low_complexity2695 ··-·low_complexity
2700 ··-·low_disruption2696 ··-·low_disruption
2701 ··-·medium_severity2697 ··-·medium_severity
2702 ··-·no_reboot_needed2698 ··-·no_reboot_needed
2703 ··-·service_autofs_disabled2699 ··-·service_autofs_disabled
 2700 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2701 [customizations.services]
 2702 masked·=·["autofs"]
2704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82703 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2705 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2704 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2706 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2705 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2707 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2706 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2708 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2707 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2709 include·disable_autofs2708 include·disable_autofs
  
Offset 4386, 18 lines modifiedOffset 4386, 14 lines modified
4386 ···························7.64386 ···························7.6
4387 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,4387 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,
4388 ···························A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.24388 ···························A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
4389 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)4389 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
4390 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-44390 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
4391 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1.14391 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1.1
4392 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000269-GPOS-00103,·SRG-OS-000480-GPOS-002274392 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000269-GPOS-00103,·SRG-OS-000480-GPOS-00227
4393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4394 [customizations.services] 
4395 masked·=·["kdump"] 
4396 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x84393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
4397 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4394 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4398 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4395 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4399 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4396 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4400 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable4397 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
4401 #·Remediation·is·applicable·only·in·certain·platforms4398 #·Remediation·is·applicable·only·in·certain·platforms
4402 if·rpm·--quiet·-q·kernel;·then4399 if·rpm·--quiet·-q·kernel;·then
Offset 4514, 30 lines modifiedOffset 4510, 34 lines modified
4514 ··-·NIST-800-53-CM-7(b)4510 ··-·NIST-800-53-CM-7(b)
4515 ··-·disable_strategy4511 ··-·disable_strategy
4516 ··-·low_complexity4512 ··-·low_complexity
4517 ··-·low_disruption4513 ··-·low_disruption
4518 ··-·medium_severity4514 ··-·medium_severity
4519 ··-·no_reboot_needed4515 ··-·no_reboot_needed
4520 ··-·service_kdump_disabled4516 ··-·service_kdump_disabled
 4517 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4518 kdump·--disable
 4519 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4520 [customizations.services]
 4521 masked·=·["kdump"]
4521 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84522 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4522 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4523 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4523 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4524 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4524 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4525 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4525 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4526 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4526 include·disable_kdump4527 include·disable_kdump
  
4527 class·disable_kdump·{4528 class·disable_kdump·{
4528 ··service·{'kdump':4529 ··service·{'kdump':
4529 ····enable·=>·false,4530 ····enable·=>·false,
4530 ····ensure·=>·'stopped',4531 ····ensure·=>·'stopped',
4531 ··}4532 ··}
4532 }4533 }
4533 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4534 kdump·--disable 
4535 Group  ·Cron·and·At·Daemons·  Group·contains·2·rules4534 Group  ·Cron·and·At·Daemons·  Group·contains·2·rules
4536 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron4535 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·cron·and·at·services·are·used·to·allow·commands·to·be·executed·at·a·later·time.·The·cron
Max diff block lines reached; 18477/24044 bytes (76.85%) of diff not shown.
690 KB
./usr/share/doc/ssg-nondebian/ssg-almalinux9-guide-pci-dss.html
    
Offset 15847, 213 lines modifiedOffset 15847, 213 lines modified
0003de60:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003de60:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003de70:·646d·3331·3837·2220·7461·6269·6e64·6578··dm3187"·tabindex0003de70:·646d·3331·3837·2220·7461·6269·6e64·6578··dm3187"·tabindex
0003de80:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003de80:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003de90:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003de90:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003dea0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003dea0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003deb0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003deb0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003dec0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003dec0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003ded0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003ded0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003dee0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003def0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003df00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003df10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003df20:·7365·2220·6964·3d22·6964·6d33·3138·3722··se"·id="idm3187"0003dee0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003def0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003df00:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003df10:·6c61·7073·6522·2069·643d·2269·646d·3331··lapse"·id="idm31
 0003df20:·3837·223e·3c74·6162·6c65·2063·6c61·7373··87"><table·class
 0003df30:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003df40:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003df50:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003df60:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003df70:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003df80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003df90:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003dfa0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003dfb0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003dfc0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003dfd0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003dfe0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003dff0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003e000:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003df30:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p0003e010:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
 0003e020:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003e030:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003e040:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003e050:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet
 0003e060:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then
 0003e070:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003e080:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003e090:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst
 0003e0a0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003e0b0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003e0c0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003e0d0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003e0e0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003e0f0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 0003e100:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003df40:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003df50:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003df60:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003df70:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003df80:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003df90:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003dfa0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003dfb0:·7461·7267·6574·3d22·2369·646d·3331·3838··target="#idm3188 
0003dfc0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003dfd0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003dfe0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003dff0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003e000:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003e010:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003e020:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003e030:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003e040:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003e050:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003e060:·2069·643d·2269·646d·3331·3838·223e·3c74···id="idm3188"><t 
0003e070:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003e080:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003e090:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003e0a0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003e0b0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003e0c0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003e0d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003e0e0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003e0f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003e100:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003e110:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003e120:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003e130:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003e140:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003e150:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003e160:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003e170:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003e180:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003e190:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r 
0003e1a0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003e1b0:·726e·656c·3b20·7468·656e·0a0a·6966·2021··rnel;·then..if·! 
0003e1c0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003e1d0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003e1e0:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y 
0003e1f0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003e200:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003e210:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003e220:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003e230:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003e240:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003e250:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003e260:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003e270:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003e280:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003e290:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003e2a0:·3331·3839·2220·7461·6269·6e64·6578·3d22··3189"·tabindex=" 
0003e2b0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003e2c0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003e2d0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003e2e0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003e2f0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003e300:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003e310:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003e320:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003e330:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003e340:·6c6c·6170·7365·2220·6964·3d22·6964·6d33··llapse"·id="idm3 
0003e350:·3138·3922·3e3c·7461·626c·6520·636c·6173··189"><table·clas 
0003e360:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003e370:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003e380:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003e390:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003e3a0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003e3b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003e3c0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003e3d0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003e3e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003e3f0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003e400:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003e410:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003e420:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003e430:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
Max diff block lines reached; 620060/648102 bytes (95.67%) of diff not shown.
57.2 KB
html2text {}
    
Offset 187, 19 lines modifiedOffset 187, 14 lines modified
187 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)187 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
188 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3188 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
189 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5189 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
190 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199190 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
191 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79191 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
192 ············_\x8c_\x8i_\x8s············6.1.1192 ············_\x8c_\x8i_\x8s············6.1.1
193 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2193 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
195 [[packages]] 
196 name·=·"aide" 
197 version·=·"*" 
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
203 #·Remediation·is·applicable·only·in·certain·platforms199 #·Remediation·is·applicable·only·in·certain·platforms
204 if·rpm·--quiet·-q·kernel;·then200 if·rpm·--quiet·-q·kernel;·then
Offset 243, 33 lines modifiedOffset 238, 38 lines modified
243 ··-·PCI-DSSv4-11.5.2238 ··-·PCI-DSSv4-11.5.2
244 ··-·enable_strategy239 ··-·enable_strategy
245 ··-·low_complexity240 ··-·low_complexity
246 ··-·low_disruption241 ··-·low_disruption
247 ··-·medium_severity242 ··-·medium_severity
248 ··-·no_reboot_needed243 ··-·no_reboot_needed
249 ··-·package_aide_installed244 ··-·package_aide_installed
 245 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 246 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 247 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 248 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 249 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 250 package·--add=aide
 251 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 252 [[packages]]
 253 name·=·"aide"
 254 version·=·"*"
250 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8255 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
251 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low256 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
252 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low257 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
253 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false258 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
254 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable259 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
255 include·install_aide260 include·install_aide
  
256 class·install_aide·{261 class·install_aide·{
257 ··package·{·'aide':262 ··package·{·'aide':
258 ····ensure·=>·'installed',263 ····ensure·=>·'installed',
259 ··}264 ··}
260 }265 }
261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
262 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
263 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
264 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
265 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
266 package·--add=aide 
267 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*266 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
268 Run·the·following·command·to·generate·a·new·database:267 Run·the·following·command·to·generate·a·new·database:
269 $·sudo·/usr/sbin/aide·--init268 $·sudo·/usr/sbin/aide·--init
270 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/269 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/
271 aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides270 aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides
272 additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:271 additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
273 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz272 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
Offset 1490, 19 lines modifiedOffset 1490, 14 lines modified
1490 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861490 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1491 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1491 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1492 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11492 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1493 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251493 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1494 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331494 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1495 ············_\x8c_\x8i_\x8s·····5.2.11495 ············_\x8c_\x8i_\x8s·····5.2.1
1496 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21496 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1497 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1498 [[packages]] 
1499 name·=·"sudo" 
1500 version·=·"*" 
1501 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81497 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1502 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1498 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1503 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1499 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1504 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1500 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1505 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1501 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1506 #·Remediation·is·applicable·only·in·certain·platforms1502 #·Remediation·is·applicable·only·in·certain·platforms
1507 if·rpm·--quiet·-q·kernel;·then1503 if·rpm·--quiet·-q·kernel;·then
Offset 1544, 33 lines modifiedOffset 1539, 38 lines modified
1544 ··-·PCI-DSSv4-2.2.61539 ··-·PCI-DSSv4-2.2.6
1545 ··-·enable_strategy1540 ··-·enable_strategy
1546 ··-·low_complexity1541 ··-·low_complexity
1547 ··-·low_disruption1542 ··-·low_disruption
1548 ··-·medium_severity1543 ··-·medium_severity
1549 ··-·no_reboot_needed1544 ··-·no_reboot_needed
1550 ··-·package_sudo_installed1545 ··-·package_sudo_installed
 1546 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1547 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1548 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1549 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1550 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1551 package·--add=sudo
 1552 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1553 [[packages]]
 1554 name·=·"sudo"
 1555 version·=·"*"
1551 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1552 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1553 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1554 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1555 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1556 include·install_sudo1561 include·install_sudo
  
1557 class·install_sudo·{1562 class·install_sudo·{
1558 ··package·{·'sudo':1563 ··package·{·'sudo':
1559 ····ensure·=>·'installed',1564 ····ensure·=>·'installed',
1560 ··}1565 ··}
1561 }1566 }
1562 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1563 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1564 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1565 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1566 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1567 package·--add=sudo 
1568 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1567 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1569 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by1568 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by
1570 making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.1569 making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
Max diff block lines reached; 53145/58580 bytes (90.72%) of diff not shown.
205 KB
./usr/share/doc/ssg-nondebian/ssg-anolis23-guide-pci-dss.html
    
Offset 15457, 96 lines modifiedOffset 15457, 96 lines modified
0003c600:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003c600:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c610:·743d·2223·6964·6d31·3336·3522·2074·6162··t="#idm1365"·tab0003c610:·743d·2223·6964·6d31·3336·3522·2074·6162··t="#idm1365"·tab
0003c620:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003c620:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c630:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003c630:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c640:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003c640:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c650:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003c650:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c660:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003c660:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003c670:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003c670:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
 0003c680:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
 0003c690:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003c6a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003c6b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003c6c0:·643d·2269·646d·3133·3635·223e·3c74·6162··d="idm1365"><tab
 0003c6d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003c6e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003c6f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003c700:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003c710:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003c720:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c730:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003c740:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003c750:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003c760:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003c770:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003c780:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003c790:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c680:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003c690:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003c6a0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003c6b0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003c6c0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003c6d0:·3133·3635·223e·3c70·7265·3e3c·636f·6465··1365"><pre><code 
0003c6e0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003c6f0:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003c700:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003c710:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003c720:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003c730:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003c740:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003c750:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003c760:·6d31·3336·3622·2074·6162·696e·6465·783d··m1366"·tabindex= 
0003c770:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003c780:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003c790:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003c7a0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003c7b0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003c7c0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003c7d0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003c7e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003c7f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003c800:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003c810:·3133·3636·223e·3c74·6162·6c65·2063·6c61··1366"><table·cla 
0003c820:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003c830:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003c840:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003c850:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003c860:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003c870:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c880:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003c890:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003c8a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c8b0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003c8c0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003c7a0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003c7b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003c7c0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath
 0003c7d0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f
 0003c7e0:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f
 0003c7f0:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage
 0003c800:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:.
0003c8d0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003c8e0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003c8f0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003c900:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
0003c910:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
0003c920:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
0003c930:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
0003c940:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
0003c950:·6f0a·2020·7461·6773·3a0a·2020·2d20·434a··o.··tags:.··-·CJ 
0003c960:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003c970:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003c980:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003c990:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003c9a0:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003c9b0:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003c9c0:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003c9d0:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003c9e0:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003c9f0:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003ca00:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003ca10:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003ca20:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
0003ca30:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
0003ca40:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
0003ca50:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
0003ca60:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
0003ca70:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe 
0003ca80:·6e3a·2027·226b·6572·6e65·6c22·2069·6e20··n:·'"kernel"·in· 
0003ca90:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
0003caa0:·636b·6167·6573·270a·2020·7461·6773·3a0a··ckages'.··tags:. 
0003cab0:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1.0003c810:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1.
0003cac0:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-50003c820:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5
0003cad0:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC0003c830:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC
0003cae0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003c840:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003caf0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003c850:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003cb00:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s0003c860:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s
0003cb10:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_0003c870:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_
0003cb20:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l0003c880:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l
0003cb30:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··0003c890:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··
0003cb40:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit0003c8a0:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
0003cb50:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_0003c8b0:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
0003cb60:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa0003c8c0:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa
0003cb70:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe0003c8d0:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe
 0003c8e0:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur
 0003c8f0:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal
 0003c900:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.·
 0003c910:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.··
 0003c920:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present
 0003c930:·0a20·2077·6865·6e3a·2027·226b·6572·6e65··.··when:·'"kerne
 0003c940:·6c22·2069·6e20·616e·7369·626c·655f·6661··l"·in·ansible_fa
 0003c950:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
 0003c960:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
 0003c970:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST
 0003c980:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a).
 0003c990:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
 0003c9a0:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS
 0003c9b0:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en
 0003c9c0:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.··
Max diff block lines reached; 180914/192808 bytes (93.83%) of diff not shown.
16.8 KB
html2text {}
    
Offset 158, 19 lines modifiedOffset 158, 14 lines modified
158 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3158 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
159 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)159 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
160 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3160 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
161 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5161 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
162 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199162 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
163 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79163 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
164 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2164 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
166 [[packages]] 
167 name·=·"aide" 
168 version·=·"*" 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
174 -·name:·Gather·the·package·facts170 -·name:·Gather·the·package·facts
175 ··package_facts:171 ··package_facts:
Offset 199, 14 lines modifiedOffset 194, 19 lines modified
199 ··-·PCI-DSSv4-11.5.2194 ··-·PCI-DSSv4-11.5.2
200 ··-·enable_strategy195 ··-·enable_strategy
201 ··-·low_complexity196 ··-·low_complexity
202 ··-·low_disruption197 ··-·low_disruption
203 ··-·medium_severity198 ··-·medium_severity
204 ··-·no_reboot_needed199 ··-·no_reboot_needed
205 ··-·package_aide_installed200 ··-·package_aide_installed
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 202 [[packages]]
 203 name·=·"aide"
 204 version·=·"*"
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
211 include·install_aide210 include·install_aide
  
Offset 4833, 19 lines modifiedOffset 4833, 14 lines modified
4833 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94833 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4834 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14834 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4835 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)4835 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
4836 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14836 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4837 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.74837 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.7
4838 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R714838 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
4839 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.54839 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.5
4840 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4841 [[packages]] 
4842 name·=·"logrotate" 
4843 version·=·"*" 
4844 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84840 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4845 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4841 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4846 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4842 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4847 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4843 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4848 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4844 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4849 -·name:·Gather·the·package·facts4845 -·name:·Gather·the·package·facts
4850 ··package_facts:4846 ··package_facts:
Offset 4874, 14 lines modifiedOffset 4869, 19 lines modified
4874 ··-·PCI-DSSv4-10.5.14869 ··-·PCI-DSSv4-10.5.1
4875 ··-·enable_strategy4870 ··-·enable_strategy
4876 ··-·low_complexity4871 ··-·low_complexity
4877 ··-·low_disruption4872 ··-·low_disruption
4878 ··-·medium_severity4873 ··-·medium_severity
4879 ··-·no_reboot_needed4874 ··-·no_reboot_needed
4880 ··-·package_logrotate_installed4875 ··-·package_logrotate_installed
 4876 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4877 [[packages]]
 4878 name·=·"logrotate"
 4879 version·=·"*"
4881 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84880 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4882 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4881 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4883 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4882 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4884 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4883 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4885 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4884 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4886 include·install_logrotate4885 include·install_logrotate
  
Offset 4996, 19 lines modifiedOffset 4996, 14 lines modified
4996 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed4996 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed
4997 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023224997 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
4998 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)4998 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
4999 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.14999 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
5000 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,5000 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,
5001 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-002325001 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
5002 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.25002 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
5003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5004 [[packages]] 
5005 name·=·"firewalld" 
5006 version·=·"*" 
5007 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5008 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5004 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5009 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5005 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5010 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5006 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5011 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5007 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5012 -·name:·Gather·the·package·facts5008 -·name:·Gather·the·package·facts
5013 ··package_facts:5009 ··package_facts:
Offset 5035, 14 lines modifiedOffset 5030, 19 lines modified
5035 ··-·PCI-DSSv4-1.2.15030 ··-·PCI-DSSv4-1.2.1
5036 ··-·enable_strategy5031 ··-·enable_strategy
5037 ··-·low_complexity5032 ··-·low_complexity
5038 ··-·low_disruption5033 ··-·low_disruption
5039 ··-·medium_severity5034 ··-·medium_severity
5040 ··-·no_reboot_needed5035 ··-·no_reboot_needed
5041 ··-·package_firewalld_installed5036 ··-·package_firewalld_installed
 5037 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5038 [[packages]]
 5039 name·=·"firewalld"
 5040 version·=·"*"
5042 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85041 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5043 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5042 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5044 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5043 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5045 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5044 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5046 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5045 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5047 include·install_firewalld5046 include·install_firewalld
  
Offset 5070, 18 lines modifiedOffset 5070, 14 lines modified
5070 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)5070 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)
5071 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-15071 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
5072 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.15072 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
5073 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-5073 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-
5074 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-002325074 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
5075 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A215075 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
5076 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.25076 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
Max diff block lines reached; 11785/17197 bytes (68.53%) of diff not shown.
536 KB
./usr/share/doc/ssg-nondebian/ssg-anolis23-guide-standard.html
    
Offset 15048, 95 lines modifiedOffset 15048, 95 lines modified
0003ac70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003ac70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003ac80:·2369·646d·3133·3635·2220·7461·6269·6e64··#idm1365"·tabind0003ac80:·2369·646d·3133·3635·2220·7461·6269·6e64··#idm1365"·tabind
0003ac90:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003ac90:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003aca0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003aca0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003acb0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003acb0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003acc0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003acc0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003acd0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003acd0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003ace0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0003ace0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
 0003acf0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
 0003ad00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003ad10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003ad20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003ad30:·6964·6d31·3336·3522·3e3c·7461·626c·6520··idm1365"><table·
 0003ad40:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003ad50:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003ad60:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003ad70:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003ad80:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003ad90:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003ada0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003adb0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003adc0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003add0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003ade0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003adf0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003ae00:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003acf0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003ad00:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003ad10:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003ad20:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003ad30:·6170·7365·2220·6964·3d22·6964·6d31·3336··apse"·id="idm136 
0003ad40:·3522·3e3c·7072·653e·3c63·6f64·653e·0a5b··5"><pre><code>.[ 
0003ad50:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0003ad60:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio 
0003ad70:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
0003ad80:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003ad90:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003ada0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003adb0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003adc0:·612d·7461·7267·6574·3d22·2369·646d·3133··a-target="#idm13 
0003add0:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0" 
0003ade0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003adf0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003ae00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003ae10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003ae20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003ae30:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003ae40:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003ae50:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003ae60:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003ae70:·6170·7365·2220·6964·3d22·6964·6d31·3336··apse"·id="idm136 
0003ae80:·3622·3e3c·7461·626c·6520·636c·6173·733d··6"><table·class= 
0003ae90:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003aea0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003aeb0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003aec0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003aed0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003aee0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003aef0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003af00:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003af10:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003af20:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003af30:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003ae10:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003ae20:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003ae30:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather·
 0003ae40:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact
 0003ae50:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact
 0003ae60:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:·
0003af40:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003af50:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003af60:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003af70:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam 
0003af80:·653a·2047·6174·6865·7220·7468·6520·7061··e:·Gather·the·pa 
0003af90:·636b·6167·6520·6661·6374·730a·2020·7061··ckage·facts.··pa 
0003afa0:·636b·6167·655f·6661·6374·733a·0a20·2020··ckage_facts:.··· 
0003afb0:·206d·616e·6167·6572·3a20·6175·746f·0a20···manager:·auto.· 
0003afc0:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS- 
0003afd0:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS 
0003afe0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003aff0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003b000:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003b010:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
0003b020:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
0003b030:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
0003b040:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
0003b050:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
0003b060:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
0003b070:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
0003b080:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
0003b090:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name 
0003b0a0:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is 
0003b0b0:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac 
0003b0c0:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:· 
0003b0d0:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:· 
0003b0e0:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:· 
0003b0f0:·2722·6b65·726e·656c·2220·696e·2061·6e73··'"kernel"·in·ans 
0003b100:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
0003b110:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-0003ae70:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··-
0003b120:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.·0003ae80:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.·
0003b130:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C0003ae90:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
0003b140:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D0003aea0:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D
0003b150:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·0003aeb0:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·
0003b160:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.20003aec0:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2
0003b170:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra0003aed0:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra
0003b180:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com0003aee0:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com
0003b190:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_0003aef0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_
0003b1a0:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m0003af00:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m
0003b1b0:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.·0003af10:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.·
0003b1c0:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee0003af20:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee
0003b1d0:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_0003af30:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_
0003b1e0:·6169·6465·5f69·6e73·7461·6c6c·6564·0a3c··aide_installed.<0003af40:·6169·6465·5f69·6e73·7461·6c6c·6564·0a0a··aide_installed..
 0003af50:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a
 0003af60:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed
 0003af70:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.····
 0003af80:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s
 0003af90:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
 0003afa0:·7768·656e·3a20·2722·6b65·726e·656c·2220··when:·'"kernel"·
 0003afb0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 0003afc0:·2e70·6163·6b61·6765·7327·0a20·2074·6167··.packages'.··tag
 0003afd0:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10
 0003afe0:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80
 0003aff0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
 0003b000:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11.
 0003b010:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4-
 0003b020:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl
 0003b030:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l
 0003b040:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.··
Max diff block lines reached; 498266/510022 bytes (97.70%) of diff not shown.
37.7 KB
html2text {}
    
Offset 114, 19 lines modifiedOffset 114, 14 lines modified
114 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3114 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
122 [[packages]] 
123 name·=·"aide" 
124 version·=·"*" 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
130 -·name:·Gather·the·package·facts126 -·name:·Gather·the·package·facts
131 ··package_facts:127 ··package_facts:
Offset 155, 14 lines modifiedOffset 150, 19 lines modified
155 ··-·PCI-DSSv4-11.5.2150 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy151 ··-·enable_strategy
157 ··-·low_complexity152 ··-·low_complexity
158 ··-·low_disruption153 ··-·low_disruption
159 ··-·medium_severity154 ··-·medium_severity
160 ··-·no_reboot_needed155 ··-·no_reboot_needed
161 ··-·package_aide_installed156 ··-·package_aide_installed
 157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 158 [[packages]]
 159 name·=·"aide"
 160 version·=·"*"
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
167 include·install_aide166 include·install_aide
  
Offset 5116, 19 lines modifiedOffset 5116, 14 lines modified
5116 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.45116 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4
5117 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.95117 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
5118 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.15118 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
5119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)5119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
5120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-15120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
5121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-5121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
5122 ···························002275122 ···························00227
5123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5124 [[packages]] 
5125 name·=·"rsyslog" 
5126 version·=·"*" 
5127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5132 -·name:·Gather·the·package·facts5128 -·name:·Gather·the·package·facts
5133 ··package_facts:5129 ··package_facts:
Offset 5151, 14 lines modifiedOffset 5146, 19 lines modified
5151 ··-·NIST-800-53-CM-6(a)5146 ··-·NIST-800-53-CM-6(a)
5152 ··-·enable_strategy5147 ··-·enable_strategy
5153 ··-·low_complexity5148 ··-·low_complexity
5154 ··-·low_disruption5149 ··-·low_disruption
5155 ··-·medium_severity5150 ··-·medium_severity
5156 ··-·no_reboot_needed5151 ··-·no_reboot_needed
5157 ··-·package_rsyslog_installed5152 ··-·package_rsyslog_installed
 5153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5154 [[packages]]
 5155 name·=·"rsyslog"
 5156 version·=·"*"
5158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5163 include·install_rsyslog5162 include·install_rsyslog
  
Offset 5184, 18 lines modifiedOffset 5184, 14 lines modified
5184 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.45184 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4
5185 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,·SR·7.25185 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,·SR·7.2
5186 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,5186 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,
5187 ···························A.15.2.1,·A.15.2.2,·A.17.2.15187 ···························A.15.2.1,·A.15.2.2,·A.17.2.1
5188 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)5188 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
5189 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-15189 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
5190 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002275190 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
5191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5192 [customizations.services] 
5193 enabled·=·["rsyslog"] 
5194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5199 -·name:·Gather·the·package·facts5196 -·name:·Gather·the·package·facts
5200 ··package_facts:5197 ··package_facts:
Offset 5231, 14 lines modifiedOffset 5227, 18 lines modified
5231 ··-·NIST-800-53-CM-6(a)5227 ··-·NIST-800-53-CM-6(a)
5232 ··-·enable_strategy5228 ··-·enable_strategy
5233 ··-·low_complexity5229 ··-·low_complexity
5234 ··-·low_disruption5230 ··-·low_disruption
5235 ··-·medium_severity5231 ··-·medium_severity
5236 ··-·no_reboot_needed5232 ··-·no_reboot_needed
5237 ··-·service_rsyslog_enabled5233 ··-·service_rsyslog_enabled
 5234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5235 [customizations.services]
 5236 enabled·=·["rsyslog"]
5238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85237 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5238 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5239 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5240 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5241 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5243 include·enable_rsyslog5242 include·enable_rsyslog
  
Offset 5354, 19 lines modifiedOffset 5354, 14 lines modified
5354 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed5354 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed
5355 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023225355 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
5356 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)5356 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
5357 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.15357 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
5358 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,5358 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,
5359 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-002325359 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
5360 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.25360 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
5361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 32932/38613 bytes (85.29%) of diff not shown.
205 KB
./usr/share/doc/ssg-nondebian/ssg-anolis8-guide-pci-dss.html
    
Offset 15457, 95 lines modifiedOffset 15457, 95 lines modified
0003c600:·6172·6765·743d·2223·6964·6d31·3336·3522··arget="#idm1365"0003c600:·6172·6765·743d·2223·6964·6d31·3336·3522··arget="#idm1365"
0003c610:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003c610:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003c620:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003c620:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c630:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c630:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c640:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c640:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c650:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c650:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c660:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c660:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003c670:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 0003c680:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003c690:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003c6a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003c6b0:·6522·2069·643d·2269·646d·3133·3635·223e··e"·id="idm1365">
 0003c6c0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003c6d0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003c6e0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003c6f0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003c700:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003c710:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003c720:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003c730:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003c740:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003c750:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003c760:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003c670:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003c680:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003c690:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c6a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c6b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c6c0:·2269·646d·3133·3635·223e·3c70·7265·3e3c··"idm1365"><pre>< 
0003c6d0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003c6e0:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003c6f0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003c700:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c710:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003c720:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c730:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c740:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c750:·2223·6964·6d31·3336·3622·2074·6162·696e··"#idm1366"·tabin 
0003c760:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c770:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c780:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c790:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c7a0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c7b0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003c7c0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003c7d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c7e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c7f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c800:·2269·646d·3133·3636·223e·3c74·6162·6c65··"idm1366"><table 
0003c810:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003c820:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003c830:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003c840:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003c850:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003c860:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c870:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003c880:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003c890:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003c8a0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003c8b0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003c8c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003c8d0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003c8e0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003c770:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003c780:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003c790:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003c7a0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003c7b0:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
 0003c7c0:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa
 0003c7d0:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa
 0003c7e0:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma
 0003c7f0:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta
0003c8f0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003c900:·653e·2d20·6e61·6d65·3a20·4761·7468·6572··e>-·name:·Gather 
0003c910:·2074·6865·2070·6163·6b61·6765·2066·6163···the·package·fac 
0003c920:·7473·0a20·2070·6163·6b61·6765·5f66·6163··ts.··package_fac 
0003c930:·7473·3a0a·2020·2020·6d61·6e61·6765·723a··ts:.····manager: 
0003c940:·2061·7574·6f0a·2020·7461·6773·3a0a·2020···auto.··tags:.·· 
0003c950:·2d20·434a·4953·2d35·2e31·302e·312e·330a··-·CJIS-5.10.1.3. 
0003c960:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
0003c970:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI- 
0003c980:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··- 
0003c990:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5. 
0003c9a0:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str 
0003c9b0:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co 
0003c9c0:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low 
0003c9d0:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-· 
0003c9e0:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity. 
0003c9f0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne 
0003ca00:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package 
0003ca10:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed. 
0003ca20:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure· 
0003ca30:·6169·6465·2069·7320·696e·7374·616c·6c65··aide·is·installe 
0003ca40:·640a·2020·7061·636b·6167·653a·0a20·2020··d.··package:.··· 
0003ca50:·206e·616d·653a·2061·6964·650a·2020·2020···name:·aide.···· 
0003ca60:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.· 
0003ca70:·2077·6865·6e3a·2027·226b·6572·6e65·6c22···when:·'"kernel" 
0003ca80:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
0003ca90:·732e·7061·636b·6167·6573·270a·2020·7461··s.packages'.··ta 
0003caa0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.10003c800:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1
0003cab0:·302e·312e·330a·2020·2d20·4e49·5354·2d38··0.1.3.··-·NIST-80003c810:·302e·312e·330a·2020·2d20·4e49·5354·2d38··0.1.3.··-·NIST-8
0003cac0:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··0003c820:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
0003cad0:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-110003c830:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11
0003cae0:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv40003c840:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4
0003caf0:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab0003c850:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab
0003cb00:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-·0003c860:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-·
0003cb10:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·0003c870:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
0003cb20:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio0003c880:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio
0003cb30:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev0003c890:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev
0003cb40:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb0003c8a0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb
0003cb50:·6f6f·745f·6e65·6564·6564·0a20·202d·2070··oot_needed.··-·p0003c8b0:·6f6f·745f·6e65·6564·6564·0a20·202d·2070··oot_needed.··-·p
0003cb60:·6163·6b61·6765·5f61·6964·655f·696e·7374··ackage_aide_inst0003c8c0:·6163·6b61·6765·5f61·6964·655f·696e·7374··ackage_aide_inst
 0003c8d0:·616c·6c65·640a·0a2d·206e·616d·653a·2045··alled..-·name:·E
 0003c8e0:·6e73·7572·6520·6169·6465·2069·7320·696e··nsure·aide·is·in
 0003c8f0:·7374·616c·6c65·640a·2020·7061·636b·6167··stalled.··packag
 0003c900:·653a·0a20·2020·206e·616d·653a·2061·6964··e:.····name:·aid
 0003c910:·650a·2020·2020·7374·6174·653a·2070·7265··e.····state:·pre
 0003c920:·7365·6e74·0a20·2077·6865·6e3a·2027·226b··sent.··when:·'"k
 0003c930:·6572·6e65·6c22·2069·6e20·616e·7369·626c··ernel"·in·ansibl
 0003c940:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
 0003c950:·270a·2020·7461·6773·3a0a·2020·2d20·434a··'.··tags:.··-·CJ
 0003c960:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-·
 0003c970:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6
 0003c980:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS-
 0003c990:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI
 0003c9a0:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.··
 0003c9b0:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg
 0003c9c0:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple
Max diff block lines reached; 180638/192394 bytes (93.89%) of diff not shown.
16.8 KB
html2text {}
    
Offset 158, 19 lines modifiedOffset 158, 14 lines modified
158 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3158 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
159 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)159 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
160 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3160 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
161 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5161 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
162 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199162 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
163 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79163 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
164 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2164 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
166 [[packages]] 
167 name·=·"aide" 
168 version·=·"*" 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
174 -·name:·Gather·the·package·facts170 -·name:·Gather·the·package·facts
175 ··package_facts:171 ··package_facts:
Offset 199, 14 lines modifiedOffset 194, 19 lines modified
199 ··-·PCI-DSSv4-11.5.2194 ··-·PCI-DSSv4-11.5.2
200 ··-·enable_strategy195 ··-·enable_strategy
201 ··-·low_complexity196 ··-·low_complexity
202 ··-·low_disruption197 ··-·low_disruption
203 ··-·medium_severity198 ··-·medium_severity
204 ··-·no_reboot_needed199 ··-·no_reboot_needed
205 ··-·package_aide_installed200 ··-·package_aide_installed
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 202 [[packages]]
 203 name·=·"aide"
 204 version·=·"*"
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
211 include·install_aide210 include·install_aide
  
Offset 4833, 19 lines modifiedOffset 4833, 14 lines modified
4833 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.94833 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
4834 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.14834 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
4835 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)4835 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
4836 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-14836 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
4837 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.74837 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.7
4838 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R714838 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
4839 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.54839 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.5
4840 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4841 [[packages]] 
4842 name·=·"logrotate" 
4843 version·=·"*" 
4844 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84840 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4845 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4841 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4846 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4842 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4847 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4843 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4848 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4844 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4849 -·name:·Gather·the·package·facts4845 -·name:·Gather·the·package·facts
4850 ··package_facts:4846 ··package_facts:
Offset 4874, 14 lines modifiedOffset 4869, 19 lines modified
4874 ··-·PCI-DSSv4-10.5.14869 ··-·PCI-DSSv4-10.5.1
4875 ··-·enable_strategy4870 ··-·enable_strategy
4876 ··-·low_complexity4871 ··-·low_complexity
4877 ··-·low_disruption4872 ··-·low_disruption
4878 ··-·medium_severity4873 ··-·medium_severity
4879 ··-·no_reboot_needed4874 ··-·no_reboot_needed
4880 ··-·package_logrotate_installed4875 ··-·package_logrotate_installed
 4876 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4877 [[packages]]
 4878 name·=·"logrotate"
 4879 version·=·"*"
4881 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84880 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4882 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4881 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4883 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4882 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4884 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4883 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4885 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4884 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4886 include·install_logrotate4885 include·install_logrotate
  
Offset 4996, 19 lines modifiedOffset 4996, 14 lines modified
4996 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed4996 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed
4997 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023224997 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
4998 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)4998 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
4999 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.14999 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
5000 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,5000 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,
5001 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-002325001 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
5002 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.25002 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
5003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5004 [[packages]] 
5005 name·=·"firewalld" 
5006 version·=·"*" 
5007 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85003 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5008 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5004 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5009 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5005 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5010 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5006 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5011 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5007 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5012 -·name:·Gather·the·package·facts5008 -·name:·Gather·the·package·facts
5013 ··package_facts:5009 ··package_facts:
Offset 5035, 14 lines modifiedOffset 5030, 19 lines modified
5035 ··-·PCI-DSSv4-1.2.15030 ··-·PCI-DSSv4-1.2.1
5036 ··-·enable_strategy5031 ··-·enable_strategy
5037 ··-·low_complexity5032 ··-·low_complexity
5038 ··-·low_disruption5033 ··-·low_disruption
5039 ··-·medium_severity5034 ··-·medium_severity
5040 ··-·no_reboot_needed5035 ··-·no_reboot_needed
5041 ··-·package_firewalld_installed5036 ··-·package_firewalld_installed
 5037 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5038 [[packages]]
 5039 name·=·"firewalld"
 5040 version·=·"*"
5042 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85041 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5043 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5042 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5044 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5043 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5045 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5044 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5046 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5045 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5047 include·install_firewalld5046 include·install_firewalld
  
Offset 5070, 18 lines modifiedOffset 5070, 14 lines modified
5070 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)5070 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)
5071 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-15071 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
5072 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.15072 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
5073 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-5073 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-
5074 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-002325074 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
5075 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A215075 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
5076 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.25076 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
Max diff block lines reached; 11785/17197 bytes (68.53%) of diff not shown.
536 KB
./usr/share/doc/ssg-nondebian/ssg-anolis8-guide-standard.html
    
Offset 15047, 96 lines modifiedOffset 15047, 96 lines modified
0003ac60:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003ac60:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003ac70:·743d·2223·6964·6d31·3336·3522·2074·6162··t="#idm1365"·tab0003ac70:·743d·2223·6964·6d31·3336·3522·2074·6162··t="#idm1365"·tab
0003ac80:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003ac80:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003ac90:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003ac90:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003aca0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003aca0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003acb0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003acb0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003acc0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003acc0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003acd0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003acd0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
 0003ace0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
 0003acf0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003ad00:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003ad10:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003ad20:·643d·2269·646d·3133·3635·223e·3c74·6162··d="idm1365"><tab
 0003ad30:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003ad40:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003ad50:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003ad60:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003ad70:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003ad80:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003ad90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003ada0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003adb0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003adc0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003add0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003ade0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003adf0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003ace0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003acf0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003ad00:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003ad10:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003ad20:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003ad30:·3133·3635·223e·3c70·7265·3e3c·636f·6465··1365"><pre><code 
0003ad40:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003ad50:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003ad60:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003ad70:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003ad80:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003ad90:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003ada0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003adb0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003adc0:·6d31·3336·3622·2074·6162·696e·6465·783d··m1366"·tabindex= 
0003add0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003ade0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003adf0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003ae00:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003ae10:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003ae20:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003ae30:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003ae40:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003ae50:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003ae60:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003ae70:·3133·3636·223e·3c74·6162·6c65·2063·6c61··1366"><table·cla 
0003ae80:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003ae90:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003aea0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003aeb0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003aec0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003aed0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003aee0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003aef0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003af00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003af10:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003af20:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003ae00:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003ae10:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003ae20:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath
 0003ae30:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f
 0003ae40:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f
 0003ae50:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage
 0003ae60:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:.
0003af30:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003af40:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003af50:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003af60:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
0003af70:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
0003af80:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
0003af90:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
0003afa0:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
0003afb0:·6f0a·2020·7461·6773·3a0a·2020·2d20·434a··o.··tags:.··-·CJ 
0003afc0:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003afd0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003afe0:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003aff0:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003b000:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003b010:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003b020:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003b030:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003b040:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003b050:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003b060:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003b070:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003b080:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
0003b090:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
0003b0a0:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
0003b0b0:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
0003b0c0:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
0003b0d0:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe 
0003b0e0:·6e3a·2027·226b·6572·6e65·6c22·2069·6e20··n:·'"kernel"·in· 
0003b0f0:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
0003b100:·636b·6167·6573·270a·2020·7461·6773·3a0a··ckages'.··tags:. 
0003b110:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1.0003ae70:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1.
0003b120:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-50003ae80:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5
0003b130:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC0003ae90:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC
0003b140:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·0003aea0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
0003b150:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.0003aeb0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
0003b160:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s0003aec0:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s
0003b170:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_0003aed0:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_
0003b180:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l0003aee0:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l
0003b190:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··0003aef0:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··
0003b1a0:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit0003af00:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
0003b1b0:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_0003af10:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
0003b1c0:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa0003af20:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa
0003b1d0:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe0003af30:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe
 0003af40:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur
 0003af50:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal
 0003af60:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.·
 0003af70:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.··
 0003af80:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present
 0003af90:·0a20·2077·6865·6e3a·2027·226b·6572·6e65··.··when:·'"kerne
 0003afa0:·6c22·2069·6e20·616e·7369·626c·655f·6661··l"·in·ansible_fa
 0003afb0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··
 0003afc0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
 0003afd0:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST
 0003afe0:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a).
 0003aff0:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
 0003b000:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS
 0003b010:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en
 0003b020:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.··
Max diff block lines reached; 497852/509746 bytes (97.67%) of diff not shown.
37.7 KB
html2text {}
    
Offset 114, 19 lines modifiedOffset 114, 14 lines modified
114 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3114 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
122 [[packages]] 
123 name·=·"aide" 
124 version·=·"*" 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
130 -·name:·Gather·the·package·facts126 -·name:·Gather·the·package·facts
131 ··package_facts:127 ··package_facts:
Offset 155, 14 lines modifiedOffset 150, 19 lines modified
155 ··-·PCI-DSSv4-11.5.2150 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy151 ··-·enable_strategy
157 ··-·low_complexity152 ··-·low_complexity
158 ··-·low_disruption153 ··-·low_disruption
159 ··-·medium_severity154 ··-·medium_severity
160 ··-·no_reboot_needed155 ··-·no_reboot_needed
161 ··-·package_aide_installed156 ··-·package_aide_installed
 157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 158 [[packages]]
 159 name·=·"aide"
 160 version·=·"*"
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
167 include·install_aide166 include·install_aide
  
Offset 5116, 19 lines modifiedOffset 5116, 14 lines modified
5116 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.45116 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4
5117 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.95117 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
5118 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.15118 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
5119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)5119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
5120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-15120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
5121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-5121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
5122 ···························002275122 ···························00227
5123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5124 [[packages]] 
5125 name·=·"rsyslog" 
5126 version·=·"*" 
5127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5132 -·name:·Gather·the·package·facts5128 -·name:·Gather·the·package·facts
5133 ··package_facts:5129 ··package_facts:
Offset 5151, 14 lines modifiedOffset 5146, 19 lines modified
5151 ··-·NIST-800-53-CM-6(a)5146 ··-·NIST-800-53-CM-6(a)
5152 ··-·enable_strategy5147 ··-·enable_strategy
5153 ··-·low_complexity5148 ··-·low_complexity
5154 ··-·low_disruption5149 ··-·low_disruption
5155 ··-·medium_severity5150 ··-·medium_severity
5156 ··-·no_reboot_needed5151 ··-·no_reboot_needed
5157 ··-·package_rsyslog_installed5152 ··-·package_rsyslog_installed
 5153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5154 [[packages]]
 5155 name·=·"rsyslog"
 5156 version·=·"*"
5158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5163 include·install_rsyslog5162 include·install_rsyslog
  
Offset 5184, 18 lines modifiedOffset 5184, 14 lines modified
5184 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.45184 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.2.6.7,·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4
5185 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,·SR·7.25185 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,·SR·7.2
5186 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,5186 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,
5187 ···························A.15.2.1,·A.15.2.2,·A.17.2.15187 ···························A.15.2.1,·A.15.2.2,·A.17.2.1
5188 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)5188 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
5189 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-15189 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
5190 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002275190 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
5191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5192 [customizations.services] 
5193 enabled·=·["rsyslog"] 
5194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5199 -·name:·Gather·the·package·facts5196 -·name:·Gather·the·package·facts
5200 ··package_facts:5197 ··package_facts:
Offset 5231, 14 lines modifiedOffset 5227, 18 lines modified
5231 ··-·NIST-800-53-CM-6(a)5227 ··-·NIST-800-53-CM-6(a)
5232 ··-·enable_strategy5228 ··-·enable_strategy
5233 ··-·low_complexity5229 ··-·low_complexity
5234 ··-·low_disruption5230 ··-·low_disruption
5235 ··-·medium_severity5231 ··-·medium_severity
5236 ··-·no_reboot_needed5232 ··-·no_reboot_needed
5237 ··-·service_rsyslog_enabled5233 ··-·service_rsyslog_enabled
 5234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5235 [customizations.services]
 5236 enabled·=·["rsyslog"]
5238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85237 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5238 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5239 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5240 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5241 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5243 include·enable_rsyslog5242 include·enable_rsyslog
  
Offset 5354, 19 lines modifiedOffset 5354, 14 lines modified
5354 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed5354 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed
5355 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023225355 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
5356 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)5356 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
5357 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.15357 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
5358 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,5358 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,
5359 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-002325359 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
5360 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.25360 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
5361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 32932/38613 bytes (85.29%) of diff not shown.
3.04 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_enhanced.html
    
Offset 15320, 283 lines modifiedOffset 15320, 283 lines modified
0003bd70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003bd70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003bd80:·743d·2223·6964·6d38·3031·3222·2074·6162··t="#idm8012"·tab0003bd80:·743d·2223·6964·6d38·3031·3222·2074·6162··t="#idm8012"·tab
0003bd90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003bd90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003bda0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003bda0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003bdb0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003bdb0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003bdc0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bdc0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003bdd0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bdd0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003bde0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003bde0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s
0003bdf0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003be00:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003be10:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003be20:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003be30:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003be40:·3830·3132·223e·3c70·7265·3e3c·636f·6465··8012"><pre><code 
0003be50:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003be60:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003be70:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003be80:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003be90:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003bea0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003beb0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003bec0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003bed0:·6d38·3031·3322·2074·6162·696e·6465·783d··m8013"·tabindex= 
0003bee0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003bef0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003bf00:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003bf10:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003bf20:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003bf30:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003bf40:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br0003bdf0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
0003bf50:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003be00:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003bf60:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003be10:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003bf70:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm8010003be20:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm801
0003bf80:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=0003be30:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
0003bf90:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003be40:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003bfa0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003be50:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003bfb0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003be60:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003bfc0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003be70:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003bfd0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003be80:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003bfe0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003be90:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bff0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003bea0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003c000:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003beb0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003c010:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003bec0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003c020:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003bed0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003c030:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003bee0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003c040:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003bef0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003c050:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003bf00:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003c060:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003bf10:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003c070:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem0003bf20:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003bf30:·6167·6520·696e·7374·616c·6c20·6169·6465··age·install·aide
0003c080:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003c090:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003c0a0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003c0b0:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet· 
0003c0c0:·2d71·206b·6572·6e65·6c3b·2074·6865·6e0a··-q·kernel;·then. 
0003c0d0:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q 
0003c0e0:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th 
0003c0f0:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta 
0003c100:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi. 
0003c110:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003c120:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003c130:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003c140:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003c150:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003c160:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003bf40:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003c170:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003bf50:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003c180:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003bf60:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003c190:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003bf70:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003c1a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003bf80:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003c1b0:·2223·6964·6d38·3031·3422·2074·6162·696e··"#idm8014"·tabin0003bf90:·743d·2223·6964·6d38·3031·3322·2074·6162··t="#idm8013"·tab
0003c1c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003bfa0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003c1d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003bfb0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003c1e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003bfc0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003c1f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003bfd0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003c200:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003bfe0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003bff0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 0003c000:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 0003c010:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003c020:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003c030:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003c040:·6964·6d38·3031·3322·3e3c·7461·626c·6520··idm8013"><table·
 0003c050:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003c060:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003c070:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003c080:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003c090:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003c0a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003c0b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003c0c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003c0d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003c0e0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003c0f0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003c100:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003c110:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003c120:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003c130:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003c210:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003c140:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
0003c220:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003c230:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c240:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c250:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c260:·2269·646d·3830·3134·223e·3c74·6162·6c65··"idm8014"><table 
0003c270:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003c280:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003c290:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003c2a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003c2b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003c2c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c2d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003c2e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003c2f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003c300:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003c310:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003c320:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003c330:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003c150:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003c160:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003c170:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
 0003c180:·7175·6965·7420·2d71·206b·6572·6e65·6c3b··quiet·-q·kernel;
 0003c190:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003c1a0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 0003c1b0:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum
 0003c1c0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003c1d0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 0003c1e0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003c1f0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003c200:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003c210:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
Max diff block lines reached; 2924087/2961789 bytes (98.73%) of diff not shown.
223 KB
html2text {}
    
Offset 131, 19 lines modifiedOffset 131, 21 lines modified
131 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3131 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
133 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199133 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
134 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79134 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
135 ············_\x8c_\x8i_\x8s············5.3.1135 ············_\x8c_\x8i_\x8s············5.3.1
136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
137 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule137 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 143 package·install·aide
139 [[packages]] 
140 name·=·"aide" 
141 version·=·"*" 
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 #·Remediation·is·applicable·only·in·certain·platforms149 #·Remediation·is·applicable·only·in·certain·platforms
148 if·rpm·--quiet·-q·kernel;·then150 if·rpm·--quiet·-q·kernel;·then
Offset 189, 14 lines modifiedOffset 191, 26 lines modified
189 ··-·PCI-DSSv4-11.5.2191 ··-·PCI-DSSv4-11.5.2
190 ··-·enable_strategy192 ··-·enable_strategy
191 ··-·low_complexity193 ··-·low_complexity
192 ··-·low_disruption194 ··-·low_disruption
193 ··-·medium_severity195 ··-·medium_severity
194 ··-·no_reboot_needed196 ··-·no_reboot_needed
195 ··-·package_aide_installed197 ··-·package_aide_installed
 198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 203 package·--add=aide
 204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 205 [[packages]]
 206 name·=·"aide"
 207 version·=·"*"
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
201 dnf·install·aide213 dnf·install·aide
Offset 208, 28 lines modifiedOffset 222, 14 lines modified
208 include·install_aide222 include·install_aide
  
209 class·install_aide·{223 class·install_aide·{
210 ··package·{·'aide':224 ··package·{·'aide':
211 ····ensure·=>·'installed',225 ····ensure·=>·'installed',
212 ··}226 ··}
213 }227 }
214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
219 package·install·aide 
220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
225 package·--add=aide 
226 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*228 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
227 Run·the·following·command·to·generate·a·new·database:229 Run·the·following·command·to·generate·a·new·database:
228 $·sudo·/usr/sbin/aide·--init230 $·sudo·/usr/sbin/aide·--init
229 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:231 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
230 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz232 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
231 To·initiate·a·manual·check,·run·the·following·command:233 To·initiate·a·manual·check,·run·the·following·command:
232 $·sudo·/usr/sbin/aide·--check234 $·sudo·/usr/sbin/aide·--check
Offset 370, 26 lines modifiedOffset 370, 26 lines modified
370 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.370 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.
371 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*371 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
372 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.372 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
373 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.373 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
374 Severity: ··medium374 Severity: ··medium
375 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot375 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
376 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28376 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
378 [[customizations.filesystem]] 
379 mountpoint·=·"/boot" 
380 size·=·1073741824 
381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
382 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low378 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
383 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high379 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
384 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false380 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
385 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable381 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
386 part·/boot382 part·/boot
 383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 384 [[customizations.filesystem]]
 385 mountpoint·=·"/boot"
 386 size·=·1073741824
387 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*387 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
388 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.388 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
389 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.389 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
390 Severity: ··low390 Severity: ··low
391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home
392 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8392 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
393 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02393 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 398, 92 lines modifiedOffset 398, 92 lines modified
398 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3398 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
399 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)399 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
400 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4400 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
401 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227401 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
402 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28402 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
403 ············_\x8c_\x8i_\x8s············1.1.2.3.1403 ············_\x8c_\x8i_\x8s············1.1.2.3.1
404 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule404 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
405 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
406 [[customizations.filesystem]] 
407 mountpoint·=·"/home" 
408 size·=·1073741824 
409 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8405 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 222212/228836 bytes (97.11%) of diff not shown.
3.16 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_high.html
    
Offset 15326, 282 lines modifiedOffset 15326, 282 lines modified
0003bdd0:·7267·6574·3d22·2369·646d·3830·3132·2220··rget="#idm8012"·0003bdd0:·7267·6574·3d22·2369·646d·3830·3132·2220··rget="#idm8012"·
0003bde0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003bde0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003bdf0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003bdf0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003be00:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003be00:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003be10:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003be10:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003be20:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003be20:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003be30:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003be30:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003be40:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0003be50:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
0003be60:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003be70:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003be80:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003be90:·6964·6d38·3031·3222·3e3c·7072·653e·3c63··idm8012"><pre><c 
0003bea0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
0003beb0:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide". 
0003bec0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
0003bed0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003bee0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003bef0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003bf00:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003bf10:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003bf20:·2369·646d·3830·3133·2220·7461·6269·6e64··#idm8013"·tabind 
0003bf30:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003bf40:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003bf50:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003bf60:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003bf70:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003bf80:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003bf90:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>0003be40:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a>
0003bfa0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003be50:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003bfb0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003be60:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003bfc0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003be70:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003bfd0:·3830·3133·223e·3c74·6162·6c65·2063·6c61··8013"><table·cla0003be80:·3830·3132·223e·3c74·6162·6c65·2063·6c61··8012"><table·cla
0003bfe0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003be90:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003bff0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003bea0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003c000:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003beb0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003c010:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003bec0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003c020:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003bed0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003c030:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bee0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003c040:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003bef0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003c050:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003bf00:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003c060:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bf10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c070:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003bf20:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
0003c080:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr0003bf30:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
0003c090:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003bf40:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0003c0a0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003bf50:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003c0b0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab0003bf60:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003c0c0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·0003bf70:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 0003bf80:·6163·6b61·6765·2069·6e73·7461·6c6c·2061··ackage·install·a
0003c0d0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003c0e0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003c0f0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003c100:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui 
0003c110:·6574·202d·7120·6b65·726e·656c·3b20·7468··et·-q·kernel;·th 
0003c120:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
0003c130:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
0003c140:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in 
0003c150:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003c160:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003c170:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003c180:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003c190:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003c1a0:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003c1b0:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><0003bf90:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre
0003c1c0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b0003bfa0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
0003c1d0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·0003bfb0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
0003c1e0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col0003bfc0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
0003c1f0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ0003bfd0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
0003c200:·6574·3d22·2369·646d·3830·3134·2220·7461··et="#idm8014"·ta0003bfe0:·7267·6574·3d22·2369·646d·3830·3133·2220··rget="#idm8013"·
0003c210:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003bff0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003c220:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c000:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003c230:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c010:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003c240:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c020:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003c250:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c030:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003c260:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c040:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003c270:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003c280:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003c290:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003c2a0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003c2b0:·6964·3d22·6964·6d38·3031·3422·3e3c·7461··id="idm8014"><ta 
0003c2c0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003c2d0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003c2e0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003c2f0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003c300:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003c310:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003c320:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c330:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003c050:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 0003c060:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003c070:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003c080:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003c090:·643d·2269·646d·3830·3133·223e·3c74·6162··d="idm8013"><tab
 0003c0a0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003c0b0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003c0c0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003c0d0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003c0e0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003c0f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c100:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003c110:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003c120:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003c130:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003c140:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003c150:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003c160:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003c340:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003c170:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003c350:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003c360:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003c370:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c380:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003c390:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003c3a0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003c3b0:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat 
0003c3c0:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package·0003c180:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003c190:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 0003c1a0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 0003c1b0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 0003c1c0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 0003c1d0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 0003c1e0:·656c·3b20·7468·656e·0a0a·6966·2021·2072··el;·then..if·!·r
 0003c1f0:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 0003c200:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 0003c210:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 0003c220:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 0003c230:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003c240:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 0003c250:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
Max diff block lines reached; 3034319/3071883 bytes (98.78%) of diff not shown.
232 KB
html2text {}
    
Offset 132, 19 lines modifiedOffset 132, 21 lines modified
132 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3132 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
134 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199134 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
135 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79135 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
136 ············_\x8c_\x8i_\x8s············5.3.1136 ············_\x8c_\x8i_\x8s············5.3.1
137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
138 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule138 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 144 package·install·aide
140 [[packages]] 
141 name·=·"aide" 
142 version·=·"*" 
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
148 #·Remediation·is·applicable·only·in·certain·platforms150 #·Remediation·is·applicable·only·in·certain·platforms
149 if·rpm·--quiet·-q·kernel;·then151 if·rpm·--quiet·-q·kernel;·then
Offset 190, 14 lines modifiedOffset 192, 26 lines modified
190 ··-·PCI-DSSv4-11.5.2192 ··-·PCI-DSSv4-11.5.2
191 ··-·enable_strategy193 ··-·enable_strategy
192 ··-·low_complexity194 ··-·low_complexity
193 ··-·low_disruption195 ··-·low_disruption
194 ··-·medium_severity196 ··-·medium_severity
195 ··-·no_reboot_needed197 ··-·no_reboot_needed
196 ··-·package_aide_installed198 ··-·package_aide_installed
 199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 204 package·--add=aide
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 206 [[packages]]
 207 name·=·"aide"
 208 version·=·"*"
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
202 dnf·install·aide214 dnf·install·aide
Offset 209, 28 lines modifiedOffset 223, 14 lines modified
209 include·install_aide223 include·install_aide
  
210 class·install_aide·{224 class·install_aide·{
211 ··package·{·'aide':225 ··package·{·'aide':
212 ····ensure·=>·'installed',226 ····ensure·=>·'installed',
213 ··}227 ··}
214 }228 }
215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
220 package·install·aide 
221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
226 package·--add=aide 
227 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
228 Run·the·following·command·to·generate·a·new·database:230 Run·the·following·command·to·generate·a·new·database:
229 $·sudo·/usr/sbin/aide·--init231 $·sudo·/usr/sbin/aide·--init
230 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:232 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
231 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz233 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
232 To·initiate·a·manual·check,·run·the·following·command:234 To·initiate·a·manual·check,·run·the·following·command:
233 $·sudo·/usr/sbin/aide·--check235 $·sudo·/usr/sbin/aide·--check
Offset 876, 26 lines modifiedOffset 876, 26 lines modified
876 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.876 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.
877 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*877 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
878 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.878 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
879 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.879 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
880 Severity: ··medium880 Severity: ··medium
881 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot881 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
882 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28882 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
883 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
884 [[customizations.filesystem]] 
885 mountpoint·=·"/boot" 
886 size·=·1073741824 
887 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8883 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
888 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low884 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
889 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high885 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
890 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false886 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
891 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable887 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
892 part·/boot888 part·/boot
 889 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 890 [[customizations.filesystem]]
 891 mountpoint·=·"/boot"
 892 size·=·1073741824
893 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*893 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
894 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.894 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
895 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.895 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
896 Severity: ··low896 Severity: ··low
897 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home897 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home
898 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8898 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
899 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02899 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 904, 92 lines modifiedOffset 904, 92 lines modified
904 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3904 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
905 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)905 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
906 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4906 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
907 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227907 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
908 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28908 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
909 ············_\x8c_\x8i_\x8s············1.1.2.3.1909 ············_\x8c_\x8i_\x8s············1.1.2.3.1
910 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule910 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
912 [[customizations.filesystem]] 
913 mountpoint·=·"/home" 
914 size·=·1073741824 
915 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 230702/237326 bytes (97.21%) of diff not shown.
1.85 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_intermediary.html
    
Offset 15316, 283 lines modifiedOffset 15316, 283 lines modified
0003bd30:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003bd30:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bd40:·2369·646d·3830·3132·2220·7461·6269·6e64··#idm8012"·tabind0003bd40:·2369·646d·3830·3132·2220·7461·6269·6e64··#idm8012"·tabind
0003bd50:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003bd50:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003bd60:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003bd60:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003bd70:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003bd70:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003bd80:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003bd80:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003bd90:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003bd90:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003bda0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0003bda0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
0003bdb0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003bdc0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003bdd0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bde0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bdf0:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm801 
0003be00:·3222·3e3c·7072·653e·3c63·6f64·653e·0a5b··2"><pre><code>.[ 
0003be10:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0003be20:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio 
0003be30:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
0003be40:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003be50:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003be60:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003be70:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003be80:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80 
0003be90:·3133·2220·7461·6269·6e64·6578·3d22·3022··13"·tabindex="0" 
0003bea0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003beb0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003bec0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003bed0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003bee0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003bef0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003bf00:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d0003bdb0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0003bf10:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003bdc0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003bf20:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003bdd0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003bf30:·6522·2069·643d·2269·646d·3830·3133·223e··e"·id="idm8013">0003bde0:·6522·2069·643d·2269·646d·3830·3132·223e··e"·id="idm8012">
0003bf40:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003bdf0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003bf50:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003be00:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003bf60:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003be10:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003bf70:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003be20:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003bf80:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003be30:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003bf90:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003be40:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003bfa0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003be50:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003bfb0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003be60:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003bfc0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003be70:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003bfd0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003be80:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003bfe0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003be90:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003bff0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003bea0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003c000:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003beb0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003c010:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003bec0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003c020:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003bed0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003bee0:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003bef0:·2069·6e73·7461·6c6c·2061·6964·650a·3c2f···install·aide.</
0003c030:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003c040:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003c050:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003c060:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003c070:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003c080:·6b65·726e·656c·3b20·7468·656e·0a0a·6966··kernel;·then..if 
0003c090:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003c0a0:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then. 
0003c0b0:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install· 
0003c0c0:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el 
0003c0d0:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003c0e0:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003c0f0:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003c100:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003c110:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003c120:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003bf00:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003c130:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003bf10:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003c140:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003bf20:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003c150:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003bf30:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003c160:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003bf40:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003c170:·646d·3830·3134·2220·7461·6269·6e64·6578··dm8014"·tabindex0003bf50:·2369·646d·3830·3133·2220·7461·6269·6e64··#idm8013"·tabind
0003c180:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003bf60:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003c190:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003bf70:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003c1a0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003bf80:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003c1b0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003bf90:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003c1c0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003bfa0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003c1d0:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl0003bfb0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
0003c1e0:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a0003bfc0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003bfd0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003bfe0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003bff0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003c000:·3830·3133·223e·3c74·6162·6c65·2063·6c61··8013"><table·cla
 0003c010:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003c1f0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c200:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003c210:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c220:·6d38·3031·3422·3e3c·7461·626c·6520·636c··m8014"><table·cl 
0003c230:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003c240:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003c250:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003c020:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003c260:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003c270:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003c280:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c290:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003c2a0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c030:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003c040:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003c050:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003c060:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003c070:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003c080:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003c090:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c0a0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003c0b0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003c0c0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003c0d0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003c2b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c0e0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003c2c0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003c0f0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0003c100:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003c110:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003c120:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003c130:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 0003c140:·6574·202d·7120·6b65·726e·656c·3b20·7468··et·-q·kernel;·th
 0003c150:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 0003c160:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 0003c170:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003c180:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003c190:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 0003c1a0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003c1b0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003c1c0:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003c1d0:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
 0003c1e0:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
 0003c1f0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003c200:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003c210:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003c220:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003c230:·6574·3d22·2369·646d·3830·3134·2220·7461··et="#idm8014"·ta
Max diff block lines reached; 1747476/1785178 bytes (97.89%) of diff not shown.
149 KB
html2text {}
    
Offset 147, 19 lines modifiedOffset 147, 21 lines modified
147 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3147 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
148 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5148 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
149 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199149 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
150 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79150 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
151 ············_\x8c_\x8i_\x8s············5.3.1151 ············_\x8c_\x8i_\x8s············5.3.1
152 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2152 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
153 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule153 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 159 package·install·aide
155 [[packages]] 
156 name·=·"aide" 
157 version·=·"*" 
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
163 #·Remediation·is·applicable·only·in·certain·platforms165 #·Remediation·is·applicable·only·in·certain·platforms
164 if·rpm·--quiet·-q·kernel;·then166 if·rpm·--quiet·-q·kernel;·then
Offset 205, 14 lines modifiedOffset 207, 26 lines modified
205 ··-·PCI-DSSv4-11.5.2207 ··-·PCI-DSSv4-11.5.2
206 ··-·enable_strategy208 ··-·enable_strategy
207 ··-·low_complexity209 ··-·low_complexity
208 ··-·low_disruption210 ··-·low_disruption
209 ··-·medium_severity211 ··-·medium_severity
210 ··-·no_reboot_needed212 ··-·no_reboot_needed
211 ··-·package_aide_installed213 ··-·package_aide_installed
 214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 219 package·--add=aide
 220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 221 [[packages]]
 222 name·=·"aide"
 223 version·=·"*"
212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
213 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
214 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
215 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false227 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
216 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable228 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
217 dnf·install·aide229 dnf·install·aide
Offset 224, 28 lines modifiedOffset 238, 14 lines modified
224 include·install_aide238 include·install_aide
  
225 class·install_aide·{239 class·install_aide·{
226 ··package·{·'aide':240 ··package·{·'aide':
227 ····ensure·=>·'installed',241 ····ensure·=>·'installed',
228 ··}242 ··}
229 }243 }
230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
231 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
232 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
233 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
234 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
235 package·install·aide 
236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
241 package·--add=aide 
242 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*244 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
243 Run·the·following·command·to·generate·a·new·database:245 Run·the·following·command·to·generate·a·new·database:
244 $·sudo·/usr/sbin/aide·--init246 $·sudo·/usr/sbin/aide·--init
245 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the247 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
246 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these248 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
247 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their249 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
248 integrity.·The·newly-generated·database·can·be·installed·as·follows:250 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 406, 26 lines modifiedOffset 406, 26 lines modified
406 apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be406 apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be
407 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.407 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
408 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition408 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition
409 ············should·be·restricted.409 ············should·be·restricted.
410 Severity: ··medium410 Severity: ··medium
411 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot411 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
412 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28412 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
414 [[customizations.filesystem]] 
415 mountpoint·=·"/boot" 
416 size·=·1073741824 
417 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
418 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low414 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
419 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high415 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
420 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false416 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
421 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable417 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
422 part·/boot418 part·/boot
 419 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 420 [[customizations.filesystem]]
 421 mountpoint·=·"/boot"
 422 size·=·1073741824
423 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*423 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
424 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at424 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at
425 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such425 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such
426 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the426 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
427 mountpoint·can·instead·be·configured·later.427 mountpoint·can·instead·be·configured·later.
428 ············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more428 ············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more
429 Rationale:··restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill429 Rationale:··restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill
Offset 440, 102 lines modifiedOffset 440, 102 lines modified
440 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3440 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
441 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)441 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
442 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4442 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
443 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227443 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
444 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28444 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
445 ············_\x8c_\x8i_\x8s············1.1.2.3.1445 ············_\x8c_\x8i_\x8s············1.1.2.3.1
446 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule446 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
448 [[customizations.filesystem]] 
449 mountpoint·=·"/home" 
450 size·=·1073741824 
451 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 146486/152210 bytes (96.24%) of diff not shown.
502 KB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-anssi_bp28_minimal.html
    
Offset 14991, 295 lines modifiedOffset 14991, 295 lines modified
0003a8e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003a8e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003a8f0:·6d31·3332·3531·2220·7461·6269·6e64·6578··m13251"·tabindex0003a8f0:·6d31·3332·3531·2220·7461·6269·6e64·6578··m13251"·tabindex
0003a900:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003a900:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003a910:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003a910:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003a920:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003a920:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003a930:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003a930:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003a940:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003a940:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003a950:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003a950:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
 0003a960:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003a970:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003a980:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003a990:·2069·643d·2269·646d·3133·3235·3122·3e3c···id="idm13251"><
 0003a9a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003a9b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003a9c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003a9d0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003a9e0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003a9f0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003aa00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003aa10:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003a960:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003a970:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003a980:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003a990:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003a9a0:·7365·2220·6964·3d22·6964·6d31·3332·3531··se"·id="idm13251 
0003a9b0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003a9c0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003a9d0:·3d20·2264·6e66·2d61·7574·6f6d·6174·6963··=·"dnf-automatic 
0003a9e0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003a9f0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003aa00:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003aa10:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003aa20:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003aa30:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003aa40:·3d22·2369·646d·3133·3235·3222·2074·6162··="#idm13252"·tab 
0003aa50:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003aa60:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003aa70:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003aa80:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003aa90:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003aaa0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003aab0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003aac0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003aad0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003aae0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003aaf0:·6964·6d31·3332·3532·223e·3c74·6162·6c65··idm13252"><table 
0003ab00:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003ab10:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003ab20:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003ab30:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003ab40:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003ab50:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003aa20:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003ab60:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003ab70:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003ab80:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003ab90:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003aba0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003abb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003abc0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003abd0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003abe0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003abf0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003ac00:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003ac10:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003ac20:·6174·666f·726d·730a·6966·2021·2028·207b··atforms.if·!·(·{ 
0003ac30:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003ac40:·6b65·726e·656c·203b·7d20·2661·6d70·3b26··kernel·;}·&amp;& 
0003ac50:·616d·703b·207b·2072·706d·202d·2d71·7569··amp;·{·rpm·--qui 
0003ac60:·6574·202d·7120·7270·6d2d·6f73·7472·6565··et·-q·rpm-ostree 
0003ac70:·203b·7d20·2661·6d70·3b26·616d·703b·207b···;}·&amp;&amp;·{ 
0003ac80:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003ac90:·626f·6f74·6320·3b7d·2026·616d·703b·2661··bootc·;}·&amp;&a 
0003aca0:·6d70·3b20·7b20·2120·7270·6d20·2d2d·7175··mp;·{·!·rpm·--qu 
0003acb0:·6965·7420·2d71·206f·7065·6e73·6869·6674··iet·-q·openshift 
0003acc0:·2d6b·7562·656c·6574·203b·7d20·293b·2074··-kubelet·;}·);·t 
0003acd0:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q 
0003ace0:·202d·2d71·7569·6574·2022·646e·662d·6175···--quiet·"dnf-au 
0003acf0:·746f·6d61·7469·6322·203b·2074·6865·6e0a··tomatic"·;·then. 
0003ad00:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install· 
0003ad10:·2d79·2022·646e·662d·6175·746f·6d61·7469··-y·"dnf-automati 
0003ad20:·6322·0a66·690a·0a65·6c73·650a·2020·2020··c".fi..else.···· 
0003ad30:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003ad40:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003ad50:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003ad60:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003ad70:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
0003ad80:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003ad90:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003ada0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003adb0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003adc0:·6172·6765·743d·2223·6964·6d31·3332·3533··arget="#idm13253 
0003add0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003ade0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003adf0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003ae00:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003ae10:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003ae20:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003ae30:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003ae40:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003ae50:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003ae60:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003ae70:·7365·2220·6964·3d22·6964·6d31·3332·3533··se"·id="idm13253 
0003ae80:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003ae90:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003aea0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003aeb0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003aec0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003aed0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003aee0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003aef0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003af00:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003af10:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003af20:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003af30:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003af40:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003af50:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003af60:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003af70:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name 
0003af80:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac 
0003af90:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac 
0003afa0:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.···· 
0003afb0:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.·· 
0003afc0:·7461·6773·3a0a·2020·2d20·656e·6162·6c65··tags:.··-·enable 
0003afd0:·5f73·7472·6174·6567·790a·2020·2d20·6c6f··_strategy.··-·lo 
0003afe0:·775f·636f·6d70·6c65·7869·7479·0a20·202d··w_complexity.··- 
0003aff0:·206c·6f77·5f64·6973·7275·7074·696f·6e0a···low_disruption. 
0003b000:·2020·2d20·6d65·6469·756d·5f73·6576·6572····-·medium_sever 
Max diff block lines reached; 434512/473870 bytes (91.69%) of diff not shown.
39.4 KB
html2text {}
    
Offset 112, 19 lines modifiedOffset 112, 21 lines modified
112 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade112 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
113 ············suitable·for·automatic,·regular·execution.113 ············suitable·for·automatic,·regular·execution.
114 Severity: ··medium114 Severity: ··medium
115 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed115 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
116 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2116 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
117 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080117 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 124 package·install·dnf-automatic
120 [[packages]] 
121 name·=·"dnf-automatic" 
122 version·=·"*" 
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
128 #·Remediation·is·applicable·only·in·certain·platforms130 #·Remediation·is·applicable·only·in·certain·platforms
129 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-131 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 164, 14 lines modifiedOffset 166, 26 lines modified
164 ··tags:166 ··tags:
165 ··-·enable_strategy167 ··-·enable_strategy
166 ··-·low_complexity168 ··-·low_complexity
167 ··-·low_disruption169 ··-·low_disruption
168 ··-·medium_severity170 ··-·medium_severity
169 ··-·no_reboot_needed171 ··-·no_reboot_needed
170 ··-·package_dnf-automatic_installed172 ··-·package_dnf-automatic_installed
 173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 178 package·--add=dnf-automatic
 179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 180 [[packages]]
 181 name·=·"dnf-automatic"
 182 version·=·"*"
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
176 dnf·install·dnf-automatic188 dnf·install·dnf-automatic
Offset 183, 28 lines modifiedOffset 197, 14 lines modified
183 include·install_dnf-automatic197 include·install_dnf-automatic
  
184 class·install_dnf-automatic·{198 class·install_dnf-automatic·{
185 ··package·{·'dnf-automatic':199 ··package·{·'dnf-automatic':
186 ····ensure·=>·'installed',200 ····ensure·=>·'installed',
187 ··}201 ··}
188 }202 }
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
194 package·install·dnf-automatic 
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
200 package·--add=dnf-automatic 
201 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
202 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed204 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
203 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/205 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
204 automatic.conf.206 automatic.conf.
205 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation207 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
206 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and208 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
207 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in209 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10232, 14 lines modifiedOffset 10232, 21 lines modified
10232 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,10232 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
10233 ···························A.9.1.210233 ···························A.9.1.2
10234 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)10234 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
10235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-310235 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
10236 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R6210236 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R62
10237 ············_\x8c_\x8i_\x8s············2.2.310237 ············_\x8c_\x8i_\x8s············2.2.3
10238 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.4,·2.210238 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.4,·2.2
 10239 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 10240 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10241 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10242 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10243 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10244 package·remove·dhcp-server
10239 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810245 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10240 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10246 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10241 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10247 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10242 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10248 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10243 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10249 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
10244 #·CAUTION:·This·remediation·script·will·remove·dhcp-server10250 #·CAUTION:·This·remediation·script·will·remove·dhcp-server
Offset 10268, 14 lines modifiedOffset 10275, 21 lines modified
10268 ··-·PCI-DSSv4-2.2.410275 ··-·PCI-DSSv4-2.2.4
10269 ··-·disable_strategy10276 ··-·disable_strategy
10270 ··-·low_complexity10277 ··-·low_complexity
10271 ··-·low_disruption10278 ··-·low_disruption
10272 ··-·medium_severity10279 ··-·medium_severity
10273 ··-·no_reboot_needed10280 ··-·no_reboot_needed
10274 ··-·package_dhcp_removed10281 ··-·package_dhcp_removed
 10282 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10283 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10284 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10285 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10286 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10287 package·--remove=dhcp-server
10275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810288 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10276 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10289 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10277 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10290 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10278 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10291 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10279 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10292 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
10280 dnf·remove·dhcp-server10293 dnf·remove·dhcp-server
Offset 10287, 28 lines modifiedOffset 10301, 14 lines modified
10287 include·remove_dhcp-server10301 include·remove_dhcp-server
  
Max diff block lines reached; 35082/40281 bytes (87.09%) of diff not shown.
4.66 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis.html
    
Offset 15373, 283 lines modifiedOffset 15373, 283 lines modified
0003c0c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003c0c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003c0d0:·6964·6d38·3031·3222·2074·6162·696e·6465··idm8012"·tabinde0003c0d0:·6964·6d38·3031·3222·2074·6162·696e·6465··idm8012"·tabinde
0003c0e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003c0e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003c0f0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003c0f0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003c100:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003c100:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003c110:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003c110:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003c120:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003c120:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003c130:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003c130:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
0003c140:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003c150:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003c160:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003c170:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003c180:·7073·6522·2069·643d·2269·646d·3830·3132··pse"·id="idm8012 
0003c190:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003c1a0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003c1b0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003c1c0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003c1d0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003c1e0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003c1f0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003c200:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003c210:·2d74·6172·6765·743d·2223·6964·6d38·3031··-target="#idm801 
0003c220:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"· 
0003c230:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003c240:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003c250:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003c260:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003c270:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003c280:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003c290:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003c140:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003c2a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003c150:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c2b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003c160:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c2c0:·2220·6964·3d22·6964·6d38·3031·3322·3e3c··"·id="idm8013"><0003c170:·2220·6964·3d22·6964·6d38·3031·3222·3e3c··"·id="idm8012"><
0003c2d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003c180:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c2e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003c190:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c2f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003c1a0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c300:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003c1b0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c310:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003c1c0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c320:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003c1d0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003c330:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003c1e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c340:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003c350:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c360:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003c370:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003c380:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c390:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003c3a0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003c3b0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003c3c0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003c3d0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003c3e0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003c3f0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003c400:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003c410:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if· 
0003c420:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003c430:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003c440:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·- 
0003c450:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003c460:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003c470:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003c480:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003c490:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003c4a0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003c4b0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003c4c0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003c4d0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003c4e0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003c4f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003c500:·6d38·3031·3422·2074·6162·696e·6465·783d··m8014"·tabindex= 
0003c510:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003c520:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003c530:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003c540:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003c550:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003c560:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003c570:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003c580:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003c590:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003c5a0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003c5b0:·3830·3134·223e·3c74·6162·6c65·2063·6c61··8014"><table·cla 
0003c5c0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003c5d0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003c5e0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003c5f0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003c600:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003c610:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c620:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003c630:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003c640:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c650:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003c660:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003c670:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003c680:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003c690:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003c6a0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
0003c6b0:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
0003c6c0:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
0003c6d0:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
0003c6e0:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
0003c6f0:·6f0a·2020·7461·6773·3a0a·2020·2d20·434a··o.··tags:.··-·CJ 
0003c700:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003c710:·4449·5341·2d53·5449·472d·5248·454c·2d30··DISA-STIG-RHEL-0 
0003c720:·382d·3031·3033·3539·0a20·202d·204e·4953··8-010359.··-·NIS 
0003c730:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003c740:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003c750:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003c760:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
0003c770:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
0003c780:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
0003c790:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
0003c7a0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
0003c7b0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
0003c7c0:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
0003c7d0:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
0003c7e0:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name 
0003c7f0:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is 
0003c800:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac 
0003c810:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:· 
0003c820:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:· 
0003c830:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:· 
0003c840:·2722·6b65·726e·656c·2220·696e·2061·6e73··'"kernel"·in·ans 
0003c850:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
0003c860:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··- 
0003c870:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003c880:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE 
0003c890:·4c2d·3038·2d30·3130·3335·390a·2020·2d20··L-08-010359.··-· 
0003c8a0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
Max diff block lines reached; 4460526/4498228 bytes (99.16%) of diff not shown.
382 KB
html2text {}
    
Offset 139, 19 lines modifiedOffset 139, 21 lines modified
139 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3139 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
140 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5140 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
141 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199141 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
142 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79142 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
143 ············_\x8c_\x8i_\x8s············5.3.1143 ············_\x8c_\x8i_\x8s············5.3.1
144 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2144 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
145 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule145 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 151 package·install·aide
147 [[packages]] 
148 name·=·"aide" 
149 version·=·"*" 
150 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
151 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
152 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
153 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
154 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
155 #·Remediation·is·applicable·only·in·certain·platforms157 #·Remediation·is·applicable·only·in·certain·platforms
156 if·rpm·--quiet·-q·kernel;·then158 if·rpm·--quiet·-q·kernel;·then
Offset 197, 14 lines modifiedOffset 199, 26 lines modified
197 ··-·PCI-DSSv4-11.5.2199 ··-·PCI-DSSv4-11.5.2
198 ··-·enable_strategy200 ··-·enable_strategy
199 ··-·low_complexity201 ··-·low_complexity
200 ··-·low_disruption202 ··-·low_disruption
201 ··-·medium_severity203 ··-·medium_severity
202 ··-·no_reboot_needed204 ··-·no_reboot_needed
203 ··-·package_aide_installed205 ··-·package_aide_installed
 206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 211 package·--add=aide
 212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 213 [[packages]]
 214 name·=·"aide"
 215 version·=·"*"
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
209 dnf·install·aide221 dnf·install·aide
Offset 216, 28 lines modifiedOffset 230, 14 lines modified
216 include·install_aide230 include·install_aide
  
217 class·install_aide·{231 class·install_aide·{
218 ··package·{·'aide':232 ··package·{·'aide':
219 ····ensure·=>·'installed',233 ····ensure·=>·'installed',
220 ··}234 ··}
221 }235 }
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
227 package·install·aide 
228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
229 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
230 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
231 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
232 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
233 package·--add=aide 
234 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*236 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
235 Run·the·following·command·to·generate·a·new·database:237 Run·the·following·command·to·generate·a·new·database:
236 $·sudo·/usr/sbin/aide·--init238 $·sudo·/usr/sbin/aide·--init
237 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:239 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
238 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz240 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
239 To·initiate·a·manual·check,·run·the·following·command:241 To·initiate·a·manual·check,·run·the·following·command:
240 $·sudo·/usr/sbin/aide·--check242 $·sudo·/usr/sbin/aide·--check
Offset 769, 14 lines modifiedOffset 769, 39 lines modified
769 »       echo·"to·see·what·package·to·(re)install"·>&2769 »       echo·"to·see·what·package·to·(re)install"·>&2
  
770 »       false··#·end·with·an·error·code770 »       false··#·end·with·an·error·code
771 elif·test·"$rc"·!=·0;·then771 elif·test·"$rc"·!=·0;·then
772 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2772 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
773 »       false··#·end·with·an·error·code773 »       false··#·end·with·an·error·code
774 fi774 fi
 775 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 776 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 777 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 778 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 779 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 780 ---
 781 apiVersion:·machineconfiguration.openshift.io/v1
 782 kind:·MachineConfig
 783 spec:
 784 ··config:
 785 ····ignition:
 786 ······version:·3.1.0
 787 ····systemd:
 788 ······units:
 789 ········-·name:·configure-crypto-policy.service
 790 ··········enabled:·true
 791 ··········contents:·|
 792 ············[Unit]
 793 ············Before=kubelet.service
 794 ············[Service]
 795 ············Type=oneshot
 796 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 797 ············RemainAfterExit=yes
 798 ············[Install]
 799 ············WantedBy=multi-user.target
775 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8800 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
776 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low801 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
777 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low802 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
778 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false803 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
779 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict804 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
780 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable805 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
781 ··set_fact:806 ··set_fact:
Offset 823, 39 lines modifiedOffset 848, 14 lines modified
823 ··-·PCI-DSSv4-2.2.7848 ··-·PCI-DSSv4-2.2.7
824 ··-·configure_crypto_policy849 ··-·configure_crypto_policy
825 ··-·high_severity850 ··-·high_severity
826 ··-·low_complexity851 ··-·low_complexity
827 ··-·low_disruption852 ··-·low_disruption
828 ··-·no_reboot_needed853 ··-·no_reboot_needed
Max diff block lines reached; 386275/391174 bytes (98.75%) of diff not shown.
2.67 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_server_l1.html
    
Offset 15335, 282 lines modifiedOffset 15335, 282 lines modified
0003be60:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm800003be60:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80
0003be70:·3132·2220·7461·6269·6e64·6578·3d22·3022··12"·tabindex="0"0003be70:·3132·2220·7461·6269·6e64·6578·3d22·3022··12"·tabindex="0"
0003be80:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003be80:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003be90:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003be90:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003bea0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003bea0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003beb0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003beb0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003bec0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003bec0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003bed0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003bee0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003bef0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003bf00:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003bf10:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003bf20:·6964·3d22·6964·6d38·3031·3222·3e3c·7072··id="idm8012"><pr 
0003bf30:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003bf40:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003bf50:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003bf60:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003bf70:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003bf80:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003bf90:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003bfa0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003bfb0:·6574·3d22·2369·646d·3830·3133·2220·7461··et="#idm8013"·ta 
0003bfc0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003bfd0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003bfe0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003bff0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003c000:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003c010:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003c020:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...0003bed0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
0003c030:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003bee0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003c040:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003bef0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003c050:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003bf00:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003c060:·2269·646d·3830·3133·223e·3c74·6162·6c65··"idm8013"><table0003bf10:·2269·646d·3830·3132·223e·3c74·6162·6c65··"idm8012"><table
0003c070:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003bf20:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003c080:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003bf30:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003c090:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003bf40:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003c0a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003bf50:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003c0b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003bf60:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003c0c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bf70:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003c0d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003bf80:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003c0e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003bf90:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003c0f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bfa0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003c100:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003bfb0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003c110:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003bfc0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003c120:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003bfd0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003c130:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003bfe0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003c140:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003bff0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003c150:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003c000:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003c010:·653e·0a70·6163·6b61·6765·2069·6e73·7461··e>.package·insta
0003c160:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003c170:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003c180:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003c190:·6174·666f·726d·730a·6966·2072·706d·202d··atforms.if·rpm·- 
0003c1a0:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel 
0003c1b0:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm 
0003c1c0:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid 
0003c1d0:·6522·203b·2074·6865·6e0a·2020·2020·7975··e"·;·then.····yu 
0003c1e0:·6d20·696e·7374·616c·6c20·2d79·2022·6169··m·install·-y·"ai 
0003c1f0:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.··· 
0003c200:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003c210:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003c220:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003c230:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003c240:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p0003c020:·6c6c·2061·6964·650a·3c2f·636f·6465·3e3c··ll·aide.</code><
0003c250:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003c260:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003c270:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003c280:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003c290:·7461·7267·6574·3d22·2369·646d·3830·3134··target="#idm8014 
0003c2a0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003c2b0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003c2c0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003c2d0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003c2e0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003c2f0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003c300:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003c310:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003c320:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c330:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c340:·7365·2220·6964·3d22·6964·6d38·3031·3422··se"·id="idm8014" 
0003c350:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003c360:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003c370:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003c380:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003c390:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003c3a0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003c3b0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c3c0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003c3d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c3e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003c3f0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003c400:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003c410:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003c420:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003c430:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003c440:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name: 
0003c450:·2047·6174·6865·7220·7468·6520·7061·636b···Gather·the·pack 
0003c460:·6167·6520·6661·6374·730a·2020·7061·636b··age·facts.··pack 
0003c470:·6167·655f·6661·6374·733a·0a20·2020·206d··age_facts:.····m 
0003c480:·616e·6167·6572·3a20·6175·746f·0a20·2074··anager:·auto.··t 
0003c490:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5. 
0003c4a0:·3130·2e31·2e33·0a20·202d·2044·4953·412d··10.1.3.··-·DISA- 
0003c4b0:·5354·4947·2d52·4845·4c2d·3038·2d30·3130··STIG-RHEL-08-010 
0003c4c0:·3335·390a·2020·2d20·4e49·5354·2d38·3030··359.··-·NIST-800 
0003c4d0:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-· 
0003c4e0:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.5 
0003c4f0:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1 
0003c500:·312e·352e·320a·2020·2d20·656e·6162·6c65··1.5.2.··-·enable 
0003c510:·5f73·7472·6174·6567·790a·2020·2d20·6c6f··_strategy.··-·lo 
0003c520:·775f·636f·6d70·6c65·7869·7479·0a20·202d··w_complexity.··- 
0003c530:·206c·6f77·5f64·6973·7275·7074·696f·6e0a···low_disruption. 
0003c540:·2020·2d20·6d65·6469·756d·5f73·6576·6572····-·medium_sever 
0003c550:·6974·790a·2020·2d20·6e6f·5f72·6562·6f6f··ity.··-·no_reboo 
0003c560:·745f·6e65·6564·6564·0a20·202d·2070·6163··t_needed.··-·pac 
0003c570:·6b61·6765·5f61·6964·655f·696e·7374·616c··kage_aide_instal 
0003c580:·6c65·640a·0a2d·206e·616d·653a·2045·6e73··led..-·name:·Ens 
0003c590:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst 
0003c5a0:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package: 
0003c5b0:·0a20·2020·206e·616d·653a·2061·6964·650a··.····name:·aide. 
0003c5c0:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese 
0003c5d0:·6e74·0a20·2077·6865·6e3a·2027·226b·6572··nt.··when:·'"ker 
0003c5e0:·6e65·6c22·2069·6e20·616e·7369·626c·655f··nel"·in·ansible_ 
0003c5f0:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
0003c600:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS 
0003c610:·2d35·2e31·302e·312e·330a·2020·2d20·4449··-5.10.1.3.··-·DI 
0003c620:·5341·2d53·5449·472d·5248·454c·2d30·382d··SA-STIG-RHEL-08- 
0003c630:·3031·3033·3539·0a20·202d·204e·4953·542d··010359.··-·NIST- 
Max diff block lines reached; 2512370/2549934 bytes (98.53%) of diff not shown.
248 KB
html2text {}
    
Offset 133, 19 lines modifiedOffset 133, 21 lines modified
133 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3133 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
134 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5134 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
135 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199135 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
136 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79136 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
137 ············_\x8c_\x8i_\x8s············5.3.1137 ············_\x8c_\x8i_\x8s············5.3.1
138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2138 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
139 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule139 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 145 package·install·aide
141 [[packages]] 
142 name·=·"aide" 
143 version·=·"*" 
144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
149 #·Remediation·is·applicable·only·in·certain·platforms151 #·Remediation·is·applicable·only·in·certain·platforms
150 if·rpm·--quiet·-q·kernel;·then152 if·rpm·--quiet·-q·kernel;·then
Offset 191, 14 lines modifiedOffset 193, 26 lines modified
191 ··-·PCI-DSSv4-11.5.2193 ··-·PCI-DSSv4-11.5.2
192 ··-·enable_strategy194 ··-·enable_strategy
193 ··-·low_complexity195 ··-·low_complexity
194 ··-·low_disruption196 ··-·low_disruption
195 ··-·medium_severity197 ··-·medium_severity
196 ··-·no_reboot_needed198 ··-·no_reboot_needed
197 ··-·package_aide_installed199 ··-·package_aide_installed
 200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 205 package·--add=aide
 206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 207 [[packages]]
 208 name·=·"aide"
 209 version·=·"*"
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
203 dnf·install·aide215 dnf·install·aide
Offset 210, 28 lines modifiedOffset 224, 14 lines modified
210 include·install_aide224 include·install_aide
  
211 class·install_aide·{225 class·install_aide·{
212 ··package·{·'aide':226 ··package·{·'aide':
213 ····ensure·=>·'installed',227 ····ensure·=>·'installed',
214 ··}228 ··}
215 }229 }
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
221 package·install·aide 
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
227 package·--add=aide 
228 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*230 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
229 Run·the·following·command·to·generate·a·new·database:231 Run·the·following·command·to·generate·a·new·database:
230 $·sudo·/usr/sbin/aide·--init232 $·sudo·/usr/sbin/aide·--init
231 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:233 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
232 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz234 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
233 To·initiate·a·manual·check,·run·the·following·command:235 To·initiate·a·manual·check,·run·the·following·command:
234 $·sudo·/usr/sbin/aide·--check236 $·sudo·/usr/sbin/aide·--check
Offset 763, 14 lines modifiedOffset 763, 39 lines modified
763 »       echo·"to·see·what·package·to·(re)install"·>&2763 »       echo·"to·see·what·package·to·(re)install"·>&2
  
764 »       false··#·end·with·an·error·code764 »       false··#·end·with·an·error·code
765 elif·test·"$rc"·!=·0;·then765 elif·test·"$rc"·!=·0;·then
766 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2766 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
767 »       false··#·end·with·an·error·code767 »       false··#·end·with·an·error·code
768 fi768 fi
 769 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 770 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 771 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 772 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 773 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 774 ---
 775 apiVersion:·machineconfiguration.openshift.io/v1
 776 kind:·MachineConfig
 777 spec:
 778 ··config:
 779 ····ignition:
 780 ······version:·3.1.0
 781 ····systemd:
 782 ······units:
 783 ········-·name:·configure-crypto-policy.service
 784 ··········enabled:·true
 785 ··········contents:·|
 786 ············[Unit]
 787 ············Before=kubelet.service
 788 ············[Service]
 789 ············Type=oneshot
 790 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 791 ············RemainAfterExit=yes
 792 ············[Install]
 793 ············WantedBy=multi-user.target
769 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8794 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
770 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low795 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
771 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low796 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
772 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false797 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
773 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict798 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
774 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable799 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
775 ··set_fact:800 ··set_fact:
Offset 817, 39 lines modifiedOffset 842, 14 lines modified
817 ··-·PCI-DSSv4-2.2.7842 ··-·PCI-DSSv4-2.2.7
818 ··-·configure_crypto_policy843 ··-·configure_crypto_policy
819 ··-·high_severity844 ··-·high_severity
820 ··-·low_complexity845 ··-·low_complexity
821 ··-·low_disruption846 ··-·low_disruption
822 ··-·no_reboot_needed847 ··-·no_reboot_needed
Max diff block lines reached; 249327/254226 bytes (98.07%) of diff not shown.
2.39 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l1.html
    
Offset 15326, 283 lines modifiedOffset 15326, 283 lines modified
0003bdd0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003bdd0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003bde0:·2369·646d·3830·3132·2220·7461·6269·6e64··#idm8012"·tabind0003bde0:·2369·646d·3830·3132·2220·7461·6269·6e64··#idm8012"·tabind
0003bdf0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003bdf0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003be00:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003be00:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003be10:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003be10:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003be20:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003be20:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003be30:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003be30:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003be40:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0003be40:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
0003be50:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003be60:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003be70:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003be80:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003be90:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm801 
0003bea0:·3222·3e3c·7072·653e·3c63·6f64·653e·0a5b··2"><pre><code>.[ 
0003beb0:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0003bec0:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio 
0003bed0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
0003bee0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003bef0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003bf00:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003bf10:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003bf20:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80 
0003bf30:·3133·2220·7461·6269·6e64·6578·3d22·3022··13"·tabindex="0" 
0003bf40:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003bf50:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003bf60:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003bf70:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003bf80:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003bf90:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003bfa0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d0003be50:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0003bfb0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003be60:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003bfc0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003be70:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003bfd0:·6522·2069·643d·2269·646d·3830·3133·223e··e"·id="idm8013">0003be80:·6522·2069·643d·2269·646d·3830·3132·223e··e"·id="idm8012">
0003bfe0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003be90:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003bff0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003bea0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003c000:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003beb0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003c010:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003bec0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003c020:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003bed0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003c030:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003bee0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003c040:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003bef0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003c050:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</0003bf00:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
0003c060:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bf10:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003c070:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo0003bf20:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003c080:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003bf30:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
0003c090:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><0003bf40:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003c0a0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th0003bf50:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003c0b0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>0003bf60:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
0003c0c0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003bf70:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003bf80:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003bf90:·2069·6e73·7461·6c6c·2061·6964·650a·3c2f···install·aide.</
0003c0d0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003c0e0:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003c0f0:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003c100:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003c110:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003c120:·6b65·726e·656c·3b20·7468·656e·0a0a·6966··kernel;·then..if 
0003c130:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003c140:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then. 
0003c150:·2020·2020·7975·6d20·696e·7374·616c·6c20······yum·install· 
0003c160:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el 
0003c170:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003c180:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003c190:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003c1a0:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003c1b0:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003c1c0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0003bfa0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
0003c1d0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0003bfb0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
0003c1e0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0003bfc0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
0003c1f0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0003bfd0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
0003c200:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003bfe0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003c210:·646d·3830·3134·2220·7461·6269·6e64·6578··dm8014"·tabindex0003bff0:·2369·646d·3830·3133·2220·7461·6269·6e64··#idm8013"·tabind
0003c220:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003c000:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003c230:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003c010:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003c240:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003c020:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003c250:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003c030:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003c260:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003c040:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003c270:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl0003c050:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
0003c280:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a0003c060:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003c070:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003c080:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003c090:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003c0a0:·3830·3133·223e·3c74·6162·6c65·2063·6c61··8013"><table·cla
 0003c0b0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003c290:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c2a0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003c2b0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c2c0:·6d38·3031·3422·3e3c·7461·626c·6520·636c··m8014"><table·cl 
0003c2d0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003c2e0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003c2f0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003c0c0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003c300:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003c310:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003c320:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c330:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003c340:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003c0d0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003c0e0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003c0f0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003c100:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003c110:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003c120:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003c130:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003c140:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003c150:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003c160:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003c170:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
0003c350:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003c180:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003c360:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003c190:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 0003c1a0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003c1b0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003c1c0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003c1d0:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 0003c1e0:·6574·202d·7120·6b65·726e·656c·3b20·7468··et·-q·kernel;·th
 0003c1f0:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q·
 0003c200:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·;
 0003c210:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003c220:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide".
 0003c230:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
 0003c240:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003c250:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003c260:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003c270:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
 0003c280:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
 0003c290:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003c2a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003c2b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003c2c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003c2d0:·6574·3d22·2369·646d·3830·3134·2220·7461··et="#idm8014"·ta
Max diff block lines reached; 2236910/2274612 bytes (98.34%) of diff not shown.
225 KB
html2text {}
    
Offset 132, 19 lines modifiedOffset 132, 21 lines modified
132 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3132 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
134 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199134 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
135 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79135 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
136 ············_\x8c_\x8i_\x8s············5.3.1136 ············_\x8c_\x8i_\x8s············5.3.1
137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
138 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule138 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 144 package·install·aide
140 [[packages]] 
141 name·=·"aide" 
142 version·=·"*" 
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
148 #·Remediation·is·applicable·only·in·certain·platforms150 #·Remediation·is·applicable·only·in·certain·platforms
149 if·rpm·--quiet·-q·kernel;·then151 if·rpm·--quiet·-q·kernel;·then
Offset 190, 14 lines modifiedOffset 192, 26 lines modified
190 ··-·PCI-DSSv4-11.5.2192 ··-·PCI-DSSv4-11.5.2
191 ··-·enable_strategy193 ··-·enable_strategy
192 ··-·low_complexity194 ··-·low_complexity
193 ··-·low_disruption195 ··-·low_disruption
194 ··-·medium_severity196 ··-·medium_severity
195 ··-·no_reboot_needed197 ··-·no_reboot_needed
196 ··-·package_aide_installed198 ··-·package_aide_installed
 199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 204 package·--add=aide
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 206 [[packages]]
 207 name·=·"aide"
 208 version·=·"*"
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
202 dnf·install·aide214 dnf·install·aide
Offset 209, 28 lines modifiedOffset 223, 14 lines modified
209 include·install_aide223 include·install_aide
  
210 class·install_aide·{224 class·install_aide·{
211 ··package·{·'aide':225 ··package·{·'aide':
212 ····ensure·=>·'installed',226 ····ensure·=>·'installed',
213 ··}227 ··}
214 }228 }
215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
220 package·install·aide 
221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
226 package·--add=aide 
227 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
228 Run·the·following·command·to·generate·a·new·database:230 Run·the·following·command·to·generate·a·new·database:
229 $·sudo·/usr/sbin/aide·--init231 $·sudo·/usr/sbin/aide·--init
230 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:232 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
231 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz233 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
232 To·initiate·a·manual·check,·run·the·following·command:234 To·initiate·a·manual·check,·run·the·following·command:
233 $·sudo·/usr/sbin/aide·--check235 $·sudo·/usr/sbin/aide·--check
Offset 762, 14 lines modifiedOffset 762, 39 lines modified
762 »       echo·"to·see·what·package·to·(re)install"·>&2762 »       echo·"to·see·what·package·to·(re)install"·>&2
  
763 »       false··#·end·with·an·error·code763 »       false··#·end·with·an·error·code
764 elif·test·"$rc"·!=·0;·then764 elif·test·"$rc"·!=·0;·then
765 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2765 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
766 »       false··#·end·with·an·error·code766 »       false··#·end·with·an·error·code
767 fi767 fi
 768 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 769 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 770 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 771 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 772 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 773 ---
 774 apiVersion:·machineconfiguration.openshift.io/v1
 775 kind:·MachineConfig
 776 spec:
 777 ··config:
 778 ····ignition:
 779 ······version:·3.1.0
 780 ····systemd:
 781 ······units:
 782 ········-·name:·configure-crypto-policy.service
 783 ··········enabled:·true
 784 ··········contents:·|
 785 ············[Unit]
 786 ············Before=kubelet.service
 787 ············[Service]
 788 ············Type=oneshot
 789 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 790 ············RemainAfterExit=yes
 791 ············[Install]
 792 ············WantedBy=multi-user.target
768 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
769 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low794 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
770 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low795 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
771 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false796 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
772 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict797 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
773 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable798 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
774 ··set_fact:799 ··set_fact:
Offset 816, 39 lines modifiedOffset 841, 14 lines modified
816 ··-·PCI-DSSv4-2.2.7841 ··-·PCI-DSSv4-2.2.7
817 ··-·configure_crypto_policy842 ··-·configure_crypto_policy
818 ··-·high_severity843 ··-·high_severity
819 ··-·low_complexity844 ··-·low_complexity
820 ··-·low_disruption845 ··-·low_disruption
821 ··-·no_reboot_needed846 ··-·no_reboot_needed
Max diff block lines reached; 225054/229953 bytes (97.87%) of diff not shown.
4.49 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cis_workstation_l2.html
    
Offset 15365, 282 lines modifiedOffset 15365, 282 lines modified
0003c040:·2d74·6172·6765·743d·2223·6964·6d38·3031··-target="#idm8010003c040:·2d74·6172·6765·743d·2223·6964·6d38·3031··-target="#idm801
0003c050:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·0003c050:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
0003c060:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003c060:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003c070:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003c070:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003c080:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003c080:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003c090:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003c090:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003c0a0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003c0a0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003c0b0:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003c0c0:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003c0d0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003c0e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003c0f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003c100:·643d·2269·646d·3830·3132·223e·3c70·7265··d="idm8012"><pre 
0003c110:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003c120:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003c130:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003c140:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003c150:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003c160:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003c170:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003c180:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003c190:·743d·2223·6964·6d38·3031·3322·2074·6162··t="#idm8013"·tab 
0003c1a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003c1b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003c1c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003c1d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003c1e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003c1f0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003c200:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003c210:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003c220:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003c230:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003c240:·6964·6d38·3031·3322·3e3c·7461·626c·6520··idm8013"><table· 
0003c250:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003c260:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003c270:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003c280:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003c290:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003c2a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c2b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003c2c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003c2d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003c2e0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003c2f0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003c300:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003c310:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003c320:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003c330:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003c340:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003c350:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003c360:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003c370:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·-- 
0003c380:·7175·6965·7420·2d71·206b·6572·6e65·6c3b··quiet·-q·kernel; 
0003c390:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003c3a0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
0003c3b0:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum 
0003c3c0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003c3d0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
0003c3e0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003c3f0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003c400:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003c410:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003c420:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
0003c430:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003c440:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003c450:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003c460:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003c470:·6172·6765·743d·2223·6964·6d38·3031·3422··arget="#idm8014" 
0003c480:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003c490:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003c4a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003c4b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003c4c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003c4d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003c4e0:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003c4f0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003c500:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c510:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c520:·6522·2069·643d·2269·646d·3830·3134·223e··e"·id="idm8014"> 
0003c530:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003c540:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003c550:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003c560:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003c570:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003c580:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003c590:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c5a0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003c5b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c5c0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003c5d0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003c5e0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003c5f0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003c600:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003c610:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003c620:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:· 
0003c630:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa 
0003c640:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa 
0003c650:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma 
0003c660:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta 
0003c670:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1 
0003c680:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S 
0003c690:·5449·472d·5248·454c·2d30·382d·3031·3033··TIG-RHEL-08-0103 
0003c6a0:·3539·0a20·202d·204e·4953·542d·3830·302d··59.··-·NIST-800- 
0003c6b0:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
0003c6c0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
0003c6d0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
0003c6e0:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
0003c6f0:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
0003c700:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
0003c710:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
0003c720:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
0003c730:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
0003c740:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
0003c750:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
0003c760:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu 
0003c770:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
0003c780:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
0003c790:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
0003c7a0:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
0003c7b0:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern 
0003c7c0:·656c·2220·696e·2061·6e73·6962·6c65·5f66··el"·in·ansible_f 
0003c7d0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
0003c7e0:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS- 
0003c7f0:·352e·3130·2e31·2e33·0a20·202d·2044·4953··5.10.1.3.··-·DIS 
0003c800:·412d·5354·4947·2d52·4845·4c2d·3038·2d30··A-STIG-RHEL-08-0 
0003c810:·3130·3335·390a·2020·2d20·4e49·5354·2d38··10359.··-·NIST-8 
0003c820:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).·· 
Max diff block lines reached; 4298601/4336165 bytes (99.13%) of diff not shown.
368 KB
html2text {}
    
Offset 138, 19 lines modifiedOffset 138, 21 lines modified
138 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3138 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
140 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199140 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
141 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79141 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
142 ············_\x8c_\x8i_\x8s············5.3.1142 ············_\x8c_\x8i_\x8s············5.3.1
143 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2143 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
144 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule144 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 150 package·install·aide
146 [[packages]] 
147 name·=·"aide" 
148 version·=·"*" 
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
154 #·Remediation·is·applicable·only·in·certain·platforms156 #·Remediation·is·applicable·only·in·certain·platforms
155 if·rpm·--quiet·-q·kernel;·then157 if·rpm·--quiet·-q·kernel;·then
Offset 196, 14 lines modifiedOffset 198, 26 lines modified
196 ··-·PCI-DSSv4-11.5.2198 ··-·PCI-DSSv4-11.5.2
197 ··-·enable_strategy199 ··-·enable_strategy
198 ··-·low_complexity200 ··-·low_complexity
199 ··-·low_disruption201 ··-·low_disruption
200 ··-·medium_severity202 ··-·medium_severity
201 ··-·no_reboot_needed203 ··-·no_reboot_needed
202 ··-·package_aide_installed204 ··-·package_aide_installed
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 210 package·--add=aide
 211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 212 [[packages]]
 213 name·=·"aide"
 214 version·=·"*"
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
208 dnf·install·aide220 dnf·install·aide
Offset 215, 28 lines modifiedOffset 229, 14 lines modified
215 include·install_aide229 include·install_aide
  
216 class·install_aide·{230 class·install_aide·{
217 ··package·{·'aide':231 ··package·{·'aide':
218 ····ensure·=>·'installed',232 ····ensure·=>·'installed',
219 ··}233 ··}
220 }234 }
221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
226 package·install·aide 
227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
230 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
231 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
232 package·--add=aide 
233 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*235 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
234 Run·the·following·command·to·generate·a·new·database:236 Run·the·following·command·to·generate·a·new·database:
235 $·sudo·/usr/sbin/aide·--init237 $·sudo·/usr/sbin/aide·--init
236 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:238 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
237 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz239 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
238 To·initiate·a·manual·check,·run·the·following·command:240 To·initiate·a·manual·check,·run·the·following·command:
239 $·sudo·/usr/sbin/aide·--check241 $·sudo·/usr/sbin/aide·--check
Offset 768, 14 lines modifiedOffset 768, 39 lines modified
768 »       echo·"to·see·what·package·to·(re)install"·>&2768 »       echo·"to·see·what·package·to·(re)install"·>&2
  
769 »       false··#·end·with·an·error·code769 »       false··#·end·with·an·error·code
770 elif·test·"$rc"·!=·0;·then770 elif·test·"$rc"·!=·0;·then
771 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2771 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
772 »       false··#·end·with·an·error·code772 »       false··#·end·with·an·error·code
773 fi773 fi
 774 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 775 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 776 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 777 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 778 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 779 ---
 780 apiVersion:·machineconfiguration.openshift.io/v1
 781 kind:·MachineConfig
 782 spec:
 783 ··config:
 784 ····ignition:
 785 ······version:·3.1.0
 786 ····systemd:
 787 ······units:
 788 ········-·name:·configure-crypto-policy.service
 789 ··········enabled:·true
 790 ··········contents:·|
 791 ············[Unit]
 792 ············Before=kubelet.service
 793 ············[Service]
 794 ············Type=oneshot
 795 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 796 ············RemainAfterExit=yes
 797 ············[Install]
 798 ············WantedBy=multi-user.target
774 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8799 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
775 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low800 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
776 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low801 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
777 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false802 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
778 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict803 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
779 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable804 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
780 ··set_fact:805 ··set_fact:
Offset 822, 39 lines modifiedOffset 847, 14 lines modified
822 ··-·PCI-DSSv4-2.2.7847 ··-·PCI-DSSv4-2.2.7
823 ··-·configure_crypto_policy848 ··-·configure_crypto_policy
824 ··-·high_severity849 ··-·high_severity
825 ··-·low_complexity850 ··-·low_complexity
826 ··-·low_disruption851 ··-·low_disruption
827 ··-·no_reboot_needed852 ··-·no_reboot_needed
Max diff block lines reached; 371520/376419 bytes (98.70%) of diff not shown.
4.18 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-cui.html
    
Offset 15357, 282 lines modifiedOffset 15357, 282 lines modified
0003bfc0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm80003bfc0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
0003bfd0:·3031·3222·2074·6162·696e·6465·783d·2230··012"·tabindex="00003bfd0:·3031·3222·2074·6162·696e·6465·783d·2230··012"·tabindex="0
0003bfe0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003bfe0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003bff0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003bff0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003c000:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003c000:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003c010:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003c010:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003c020:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003c020:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003c030:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
0003c030:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B 
0003c040:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
0003c050:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c060:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c070:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003c080:·2069·643d·2269·646d·3830·3132·223e·3c70···id="idm8012"><p 
0003c090:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
0003c0a0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a 
0003c0b0:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·" 
0003c0c0:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
0003c0d0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c0e0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003c0f0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003c100:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c110:·6765·743d·2223·6964·6d38·3031·3322·2074··get="#idm8013"·t 
0003c120:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c130:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c140:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c150:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003c160:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003c170:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003c180:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003c190:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003c040:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003c1a0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003c050:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003c1b0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003c060:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003c1c0:·3d22·6964·6d38·3031·3322·3e3c·7461·626c··="idm8013"><tabl0003c070:·3d22·6964·6d38·3031·3222·3e3c·7461·626c··="idm8012"><tabl
0003c1d0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003c080:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003c1e0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003c090:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003c1f0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003c0a0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003c200:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003c0b0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003c210:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003c0c0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003c220:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003c0d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003c230:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003c240:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003c250:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003c260:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003c270:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003c280:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003c290:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003c2a0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003c2b0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003c2c0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003c2d0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003c2e0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003c2f0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm· 
0003c300:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003c310:·6c3b·2074·6865·6e0a·0a69·6620·2120·7270··l;·then..if·!·rp 
0003c320:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003c330:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y 
0003c340:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a 
0003c350:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003c360:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003c370:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003c380:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003c390:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003c3a0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003c3b0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003c3c0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003c3d0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003c3e0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003c3f0:·2d74·6172·6765·743d·2223·6964·6d38·3031··-target="#idm801 
0003c400:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"· 
0003c410:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003c420:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003c430:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003c440:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003c450:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003c460:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003c470:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003c480:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003c490:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003c4a0:·7073·6522·2069·643d·2269·646d·3830·3134··pse"·id="idm8014 
0003c4b0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003c4c0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003c4d0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003c4e0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003c4f0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003c500:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003c510:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003c520:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003c530:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003c540:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003c550:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003c560:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003c570:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003c580:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003c590:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003c5a0:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name 
0003c5b0:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac 
0003c5c0:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac 
0003c5d0:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.···· 
0003c5e0:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.·· 
0003c5f0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5 
0003c600:·2e31·302e·312e·330a·2020·2d20·4449·5341··.10.1.3.··-·DISA 
0003c610:·2d53·5449·472d·5248·454c·2d30·382d·3031··-STIG-RHEL-08-01 
0003c620:·3033·3539·0a20·202d·204e·4953·542d·3830··0359.··-·NIST-80 
0003c630:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
0003c640:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11. 
0003c650:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4- 
0003c660:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl 
0003c670:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l 
0003c680:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.·· 
0003c690:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption 
0003c6a0:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve 
0003c6b0:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo 
0003c6c0:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa 
0003c6d0:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta 
0003c6e0:·6c6c·6564·0a0a·2d20·6e61·6d65·3a20·456e··lled..-·name:·En 
0003c6f0:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins 
0003c700:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package 
0003c710:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide 
0003c720:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres 
0003c730:·656e·740a·2020·7768·656e·3a20·2722·6b65··ent.··when:·'"ke 
0003c740:·726e·656c·2220·696e·2061·6e73·6962·6c65··rnel"·in·ansible 
0003c750:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
0003c760:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI 
0003c770:·532d·352e·3130·2e31·2e33·0a20·202d·2044··S-5.10.1.3.··-·D 
0003c780:·4953·412d·5354·4947·2d52·4845·4c2d·3038··ISA-STIG-RHEL-08 
0003c790:·2d30·3130·3335·390a·2020·2d20·4e49·5354··-010359.··-·NIST 
Max diff block lines reached; 3895824/3933388 bytes (99.04%) of diff not shown.
435 KB
html2text {}
    
Offset 138, 19 lines modifiedOffset 138, 21 lines modified
138 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3138 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5139 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
140 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199140 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
141 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79141 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
142 ············_\x8c_\x8i_\x8s············5.3.1142 ············_\x8c_\x8i_\x8s············5.3.1
143 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2143 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
144 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule144 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 150 package·install·aide
146 [[packages]] 
147 name·=·"aide" 
148 version·=·"*" 
149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
154 #·Remediation·is·applicable·only·in·certain·platforms156 #·Remediation·is·applicable·only·in·certain·platforms
155 if·rpm·--quiet·-q·kernel;·then157 if·rpm·--quiet·-q·kernel;·then
Offset 196, 14 lines modifiedOffset 198, 26 lines modified
196 ··-·PCI-DSSv4-11.5.2198 ··-·PCI-DSSv4-11.5.2
197 ··-·enable_strategy199 ··-·enable_strategy
198 ··-·low_complexity200 ··-·low_complexity
199 ··-·low_disruption201 ··-·low_disruption
200 ··-·medium_severity202 ··-·medium_severity
201 ··-·no_reboot_needed203 ··-·no_reboot_needed
202 ··-·package_aide_installed204 ··-·package_aide_installed
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 210 package·--add=aide
 211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 212 [[packages]]
 213 name·=·"aide"
 214 version·=·"*"
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
208 dnf·install·aide220 dnf·install·aide
Offset 215, 28 lines modifiedOffset 229, 14 lines modified
215 include·install_aide229 include·install_aide
  
216 class·install_aide·{230 class·install_aide·{
217 ··package·{·'aide':231 ··package·{·'aide':
218 ····ensure·=>·'installed',232 ····ensure·=>·'installed',
219 ··}233 ··}
220 }234 }
221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
226 package·install·aide 
227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
230 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
231 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
232 package·--add=aide 
233 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules235 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
234 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.236 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
235 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.237 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
236 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.238 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
237 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*239 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 263, 31 lines modifiedOffset 263, 31 lines modified
263 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877263 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
264 ············_\x8i_\x8s_\x8m······1446264 ············_\x8i_\x8s_\x8m······1446
265 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1265 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
266 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12266 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
267 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1267 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
268 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176268 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
269 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule269 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
271 [customizations] 
272 fips·=·true 
273 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
274 #·Remediation·is·applicable·only·in·certain·platforms271 #·Remediation·is·applicable·only·in·certain·platforms
275 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then272 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
276 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then273 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
277 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF274 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
278 kargs·=·["fips=1"]275 kargs·=·["fips=1"]
279 EOF276 EOF
280 fi277 fi
  
281 else278 else
282 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'279 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
283 fi280 fi
 281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 282 [customizations]
 283 fips·=·true
284 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules284 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules
285 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:285 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
286 ····*·GnuTLS·library286 ····*·GnuTLS·library
287 ····*·OpenSSL·library287 ····*·OpenSSL·library
288 ····*·NSS·library288 ····*·NSS·library
289 ····*·OpenJDK289 ····*·OpenJDK
290 ····*·Libkrb5290 ····*·Libkrb5
Offset 299, 19 lines modifiedOffset 299, 21 lines modified
299 $·sudo·yum·install·crypto-policies299 $·sudo·yum·install·crypto-policies
300 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.300 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
301 Severity: ··medium301 Severity: ··medium
302 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed302 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
303 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123303 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
304 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1304 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
305 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174305 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
306 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8306 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 307 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 308 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 438486/445435 bytes (98.44%) of diff not shown.
2.08 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-e8.html
    
Offset 17764, 183 lines modifiedOffset 17764, 183 lines modified
00045630:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm800045630:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8
00045640:·3736·3422·2074·6162·696e·6465·783d·2230··764"·tabindex="000045640:·3736·3422·2074·6162·696e·6465·783d·2230··764"·tabindex="0
00045650:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00045650:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00045660:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00045660:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00045670:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00045670:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00045680:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00045680:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00045690:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00045690:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
000456a0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
000456b0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
000456c0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
000456d0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
000456e0:·6c61·7073·6522·2069·643d·2269·646d·3837··lapse"·id="idm87 
000456f0:·3634·223e·3c74·6162·6c65·2063·6c61·7373··64"><table·class 
00045700:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st000456a0:·6961·7469·6f6e·204b·7562·6572·6e65·7465··iation·Kubernete
 000456b0:·7320·736e·6970·7065·7420·e287·b23c·2f61··s·snippet·...</a
 000456c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 000456d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 000456e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 000456f0:·6d38·3736·3422·3e3c·7461·626c·6520·636c··m8764"><table·cl
 00045700:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00045710:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
00045710:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00045720:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
00045720:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
00045730:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
00045740:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00045730:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00045740:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 00045750:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00045760:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00045770:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
00045750:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00045780:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00045790:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 000457a0:·7464·3e74·7275·653c·2f74·643e·3c2f·7472··td>true</td></tr
00045760:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
00045770:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
00045780:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00045790:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
000457a0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
000457b0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:000457b0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
000457c0:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric000457c0:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr
000457d0:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab000457d0:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t
000457e0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·000457e0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
000457f0:·6e61·6d65·3a20·5843·4344·4620·5661·6c75··name:·XCCDF·Valu 
00045800:·6520·7661·725f·7379·7374·656d·5f63·7279··e·var_system_cry 
00045810:·7074·6f5f·706f·6c69·6379·2023·2070·726f··pto_policy·#·pro 
00045820:·6d6f·7465·2074·6f20·7661·7269·6162·6c65··mote·to·variable 
00045830:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···000457f0:·2d2d·2d0a·6170·6956·6572·7369·6f6e·3a20··---.apiVersion:·
 00045800:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura
 00045810:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i
 00045820:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi
 00045830:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.·
 00045840:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign
 00045850:·6974·696f·6e3a·0a20·2020·2020·2076·6572··ition:.······ver
 00045860:·7369·6f6e·3a20·332e·312e·300a·2020·2020··sion:·3.1.0.····
 00045870:·7379·7374·656d·643a·0a20·2020·2020·2075··systemd:.······u
 00045880:·6e69·7473·3a0a·2020·2020·2020·2020·2d20··nits:.········-·
 00045890:·6e61·6d65·3a20·636f·6e66·6967·7572·652d··name:·configure-
 000458a0:·6372·7970·746f·2d70·6f6c·6963·792e·7365··crypto-policy.se
 000458b0:·7276·6963·650a·2020·2020·2020·2020·2020··rvice.··········
 000458c0:·656e·6162·6c65·643a·2074·7275·650a·2020··enabled:·true.··
 000458d0:·2020·2020·2020·2020·636f·6e74·656e·7473··········contents
 000458e0:·3a20·7c0a·2020·2020·2020·2020·2020·2020··:·|.············
 000458f0:·5b55·6e69·745d·0a20·2020·2020·2020·2020··[Unit].·········
 00045900:·2020·2042·6566·6f72·653d·6b75·6265·6c65·····Before=kubele
 00045910:·742e·7365·7276·6963·650a·2020·2020·2020··t.service.······
 00045920:·2020·2020·2020·5b53·6572·7669·6365·5d0a········[Service].
 00045930:·2020·2020·2020·2020·2020·2020·5479·7065··············Type
 00045940:·3d6f·6e65·7368·6f74·0a20·2020·2020·2020··=oneshot.·······
 00045950:·2020·2020·2045·7865·6353·7461·7274·3d75·······ExecStart=u
 00045960:·7064·6174·652d·6372·7970·746f·2d70·6f6c··pdate-crypto-pol
 00045970:·6963·6965·7320·2d2d·7365·7420·7b7b·2e76··icies·--set·{{.v
00045840:·2076·6172·5f73·7973·7465·6d5f·6372·7970···var_system_cryp00045980:·6172·5f73·7973·7465·6d5f·6372·7970·746f··ar_system_crypto
 00045990:·5f70·6f6c·6963·797d·7d0a·2020·2020·2020··_policy}}.······
 000459a0:·2020·2020·2020·5265·6d61·696e·4166·7465········RemainAfte
 000459b0:·7245·7869·743d·7965·730a·2020·2020·2020··rExit=yes.······
 000459c0:·2020·2020·2020·5b49·6e73·7461·6c6c·5d0a········[Install].
 000459d0:·2020·2020·2020·2020·2020·2020·5761·6e74··············Want
 000459e0:·6564·4279·3d6d·756c·7469·2d75·7365·722e··edBy=multi-user.
00045850:·746f·5f70·6f6c·6963·793a·2021·2173·7472··to_policy:·!!str 
00045860:·203c·6162·6272·2074·6974·6c65·3d22·6672···<abbr·title="fr 
00045870:·6f6d·2050·726f·6669·6c65·2f72·6566·696e··om·Profile/refin 
00045880:·652d·7661·6c75·653a·2078·6363·6466·5f6f··e-value:·xccdf_o 
00045890:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co 
000458a0:·6e74·656e·745f·7661·6c75·655f·7661·725f··ntent_value_var_ 
000458b0:·7379·7374·656d·5f63·7279·7074·6f5f·706f··system_crypto_po 
000458c0:·6c69·6379·223e·4445·4641·554c·543a·4e4f··licy">DEFAULT:NO 
000458d0:·2d53·4841·313c·2f61·6262·723e·0a20·2074··-SHA1</abbr>.··t 
000458e0:·6167·733a·0a20·2020·202d·2061·6c77·6179··ags:.····-·alway 
000458f0:·730a·0a2d·206e·616d·653a·2043·6f6e·6669··s..-·name:·Confi 
00045900:·6775·7265·2053·7973·7465·6d20·4372·7970··gure·System·Cryp 
00045910:·746f·6772·6170·6879·2050·6f6c·6963·790a··tography·Policy. 
00045920:·2020·6c69·6e65·696e·6669·6c65·3a0a·2020····lineinfile:.·· 
00045930:·2020·7061·7468·3a20·2f65·7463·2f63·7279····path:·/etc/cry 
00045940:·7074·6f2d·706f·6c69·6369·6573·2f63·6f6e··pto-policies/con 
00045950:·6669·670a·2020·2020·7265·6765·7870·3a20··fig.····regexp:· 
00045960:·5e28·3f21·2329·285c·532b·2924·0a20·2020··^(?!#)(\S+)$.··· 
00045970:·206c·696e·653a·2027·7b7b·2076·6172·5f73···line:·'{{·var_s 
00045980:·7973·7465·6d5f·6372·7970·746f·5f70·6f6c··ystem_crypto_pol 
00045990:·6963·7920·7d7d·270a·2020·2020·6372·6561··icy·}}'.····crea 
000459a0:·7465·3a20·7472·7565·0a20·2074·6167·733a··te:·true.··tags: 
000459b0:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R 
000459c0:·4845·4c2d·3038·2d30·3130·3032·300a·2020··HEL-08-010020.·· 
000459d0:·2d20·4e49·5354·2d38·3030·2d35·332d·4143··-·NIST-800-53-AC 
000459e0:·2d31·3728·3229·0a20·202d·204e·4953·542d··-17(2).··-·NIST- 
000459f0:·3830·302d·3533·2d41·432d·3137·2861·290a··800-53-AC-17(a). 
00045a00:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
00045a10:·434d·2d36·2861·290a·2020·2d20·4e49·5354··CM-6(a).··-·NIST 
00045a20:·2d38·3030·2d35·332d·4d41·2d34·2836·290a··-800-53-MA-4(6). 
00045a30:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
00045a40:·5343·2d31·3228·3229·0a20·202d·204e·4953··SC-12(2).··-·NIS 
00045a50:·542d·3830·302d·3533·2d53·432d·3132·2833··T-800-53-SC-12(3 
00045a60:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
00045a70:·332d·5343·2d31·330a·2020·2d20·5043·492d··3-SC-13.··-·PCI- 
00045a80:·4453·5376·342d·322e·320a·2020·2d20·5043··DSSv4-2.2.··-·PC 
00045a90:·492d·4453·5376·342d·322e·322e·370a·2020··I-DSSv4-2.2.7.·· 
00045aa0:·2d20·636f·6e66·6967·7572·655f·6372·7970··-·configure_cryp 
00045ab0:·746f·5f70·6f6c·6963·790a·2020·2d20·6869··to_policy.··-·hi 
00045ac0:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-· 
00045ad0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.· 
00045ae0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio 
00045af0:·6e0a·2020·2d20·6e6f·5f72·6562·6f6f·745f··n.··-·no_reboot_ 
00045b00:·6e65·6564·6564·0a20·202d·2072·6573·7472··needed.··-·restr 
00045b10:·6963·745f·7374·7261·7465·6779·0a0a·2d20··ict_strategy..-· 
00045b20:·6e61·6d65·3a20·5665·7269·6679·2074·6861··name:·Verify·tha 
00045b30:·7420·4372·7970·746f·2050·6f6c·6963·7920··t·Crypto·Policy· 
00045b40:·6973·2053·6574·2028·7275·6e74·696d·6529··is·Set·(runtime) 
00045b50:·0a20·2063·6f6d·6d61·6e64·3a20·2f75·7372··.··command:·/usr 
00045b60:·2f62·696e·2f75·7064·6174·652d·6372·7970··/bin/update-cryp 
Max diff block lines reached; 1984747/2008649 bytes (98.81%) of diff not shown.
173 KB
html2text {}
    
Offset 729, 14 lines modifiedOffset 729, 39 lines modified
729 »       echo·"to·see·what·package·to·(re)install"·>&2729 »       echo·"to·see·what·package·to·(re)install"·>&2
  
730 »       false··#·end·with·an·error·code730 »       false··#·end·with·an·error·code
731 elif·test·"$rc"·!=·0;·then731 elif·test·"$rc"·!=·0;·then
732 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2732 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
733 »       false··#·end·with·an·error·code733 »       false··#·end·with·an·error·code
734 fi734 fi
 735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 737 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 738 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 739 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 740 ---
 741 apiVersion:·machineconfiguration.openshift.io/v1
 742 kind:·MachineConfig
 743 spec:
 744 ··config:
 745 ····ignition:
 746 ······version:·3.1.0
 747 ····systemd:
 748 ······units:
 749 ········-·name:·configure-crypto-policy.service
 750 ··········enabled:·true
 751 ··········contents:·|
 752 ············[Unit]
 753 ············Before=kubelet.service
 754 ············[Service]
 755 ············Type=oneshot
 756 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 757 ············RemainAfterExit=yes
 758 ············[Install]
 759 ············WantedBy=multi-user.target
735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8760 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low761 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
737 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low762 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
738 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false763 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
739 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict764 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
740 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable765 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
741 ··set_fact:766 ··set_fact:
Offset 783, 39 lines modifiedOffset 808, 14 lines modified
783 ··-·PCI-DSSv4-2.2.7808 ··-·PCI-DSSv4-2.2.7
784 ··-·configure_crypto_policy809 ··-·configure_crypto_policy
785 ··-·high_severity810 ··-·high_severity
786 ··-·low_complexity811 ··-·low_complexity
787 ··-·low_disruption812 ··-·low_disruption
788 ··-·no_reboot_needed813 ··-·no_reboot_needed
789 ··-·restrict_strategy814 ··-·restrict_strategy
790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
791 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
792 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
793 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
794 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
795 --- 
796 apiVersion:·machineconfiguration.openshift.io/v1 
797 kind:·MachineConfig 
798 spec: 
799 ··config: 
800 ····ignition: 
801 ······version:·3.1.0 
802 ····systemd: 
803 ······units: 
804 ········-·name:·configure-crypto-policy.service 
805 ··········enabled:·true 
806 ··········contents:·| 
807 ············[Unit] 
808 ············Before=kubelet.service 
809 ············[Service] 
810 ············Type=oneshot 
811 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
812 ············RemainAfterExit=yes 
813 ············[Install] 
814 ············WantedBy=multi-user.target 
815 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*815 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
816 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.816 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
817 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.817 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
818 Severity: ··medium818 Severity: ··medium
819 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy819 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
820 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453820 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
821 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)821 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 1154, 19 lines modifiedOffset 1154, 21 lines modified
1154 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.1154 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.
1155 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1155 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1156 The·rear·package·can·be·installed·with·the·following·command:1156 The·rear·package·can·be·installed·with·the·following·command:
1157 $·sudo·yum·install·rear1157 $·sudo·yum·install·rear
1158 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.1158 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.
1159 Severity: ·medium1159 Severity: ·medium
1160 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed1160 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed
1161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1166 package·install·rear
1162 [[packages]] 
1163 name·=·"rear" 
1164 version·=·"*" 
1165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1170 #·Remediation·is·applicable·only·in·certain·platforms1172 #·Remediation·is·applicable·only·in·certain·platforms
1171 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1173 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1195, 14 lines modifiedOffset 1197, 26 lines modified
1195 ··tags:1197 ··tags:
1196 ··-·enable_strategy1198 ··-·enable_strategy
1197 ··-·low_complexity1199 ··-·low_complexity
1198 ··-·low_disruption1200 ··-·low_disruption
1199 ··-·medium_severity1201 ··-·medium_severity
1200 ··-·no_reboot_needed1202 ··-·no_reboot_needed
1201 ··-·package_rear_installed1203 ··-·package_rear_installed
 1204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1209 package·--add=rear
 1210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1211 [[packages]]
 1212 name·=·"rear"
 1213 version·=·"*"
1202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 170410/176821 bytes (96.37%) of diff not shown.
2.2 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-hipaa.html
    
Offset 17096, 181 lines modifiedOffset 17096, 181 lines modified
00042c70:·6574·3d22·2369·646d·3837·3634·2220·7461··et="#idm8764"·ta00042c70:·6574·3d22·2369·646d·3837·3634·2220·7461··et="#idm8764"·ta
00042c80:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00042c80:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00042c90:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00042c90:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00042ca0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00042ca0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00042cb0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00042cb0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00042cc0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00042cc0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00042cd0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00042cd0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00042ce0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
00042cf0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00042d00:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00042d10:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00042d20:·6964·3d22·6964·6d38·3736·3422·3e3c·7461··id="idm8764"><ta 
00042d30:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
00042d40:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
00042d50:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
00042d60:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
00042d70:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit00042ce0:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp
 00042cf0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00042d00:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00042d10:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00042d20:·6522·2069·643d·2269·646d·3837·3634·223e··e"·id="idm8764">
 00042d30:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 00042d40:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 00042d50:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 00042d60:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 00042d70:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 00042d80:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 00042d90:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00042da0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
00042d80:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</00042db0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00042d90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00042dc0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 00042dd0:·6f74·3a3c·2f74·683e·3c74·643e·7472·7565··ot:</th><td>true
00042da0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
00042db0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00042dc0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
00042dd0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
00042de0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00042de0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00042df0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t00042df0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
00042e00:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><00042e00:·3c74·643e·7265·7374·7269·6374·3c2f·7464··<td>restrict</td
00042e10:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre00042e10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
00042e20:·3e3c·636f·6465·3e2d·206e·616d·653a·2058··><code>-·name:·X 
00042e30:·4343·4446·2056·616c·7565·2076·6172·5f73··CCDF·Value·var_s 
00042e40:·7973·7465·6d5f·6372·7970·746f·5f70·6f6c··ystem_crypto_pol 
00042e50:·6963·7920·2320·7072·6f6d·6f74·6520·746f··icy·#·promote·to 
00042e60:·2076·6172·6961·626c·650a·2020·7365·745f···variable.··set_ 
00042e70:·6661·6374·3a0a·2020·2020·7661·725f·7379··fact:.····var_sy00042e20:·7265·3e3c·636f·6465·3e2d·2d2d·0a61·7069··re><code>---.api
 00042e30:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine
 00042e40:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op
 00042e50:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki
 00042e60:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi
 00042e70:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config
 00042e80:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.
 00042e90:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3
 00042ea0:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd
 00042eb0:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·
 00042ec0:·2020·2020·2020·202d·206e·616d·653a·2063·········-·name:·c
 00042ed0:·6f6e·6669·6775·7265·2d63·7279·7074·6f2d··onfigure-crypto-
 00042ee0:·706f·6c69·6379·2e73·6572·7669·6365·0a20··policy.service.·
 00042ef0:·2020·2020·2020·2020·2065·6e61·626c·6564···········enabled
 00042f00:·3a20·7472·7565·0a20·2020·2020·2020·2020··:·true.·········
 00042f10:·2063·6f6e·7465·6e74·733a·207c·0a20·2020···contents:·|.···
 00042f20:·2020·2020·2020·2020·205b·556e·6974·5d0a···········[Unit].
 00042f30:·2020·2020·2020·2020·2020·2020·4265·666f··············Befo
 00042f40:·7265·3d6b·7562·656c·6574·2e73·6572·7669··re=kubelet.servi
 00042f50:·6365·0a20·2020·2020·2020·2020·2020·205b··ce.············[
 00042f60:·5365·7276·6963·655d·0a20·2020·2020·2020··Service].·······
 00042f70:·2020·2020·2054·7970·653d·6f6e·6573·686f·······Type=onesho
 00042f80:·740a·2020·2020·2020·2020·2020·2020·4578··t.············Ex
 00042f90:·6563·5374·6172·743d·7570·6461·7465·2d63··ecStart=update-c
 00042fa0:·7279·7074·6f2d·706f·6c69·6369·6573·202d··rypto-policies·-
 00042fb0:·2d73·6574·207b·7b2e·7661·725f·7379·7374··-set·{{.var_syst
00042e80:·7374·656d·5f63·7279·7074·6f5f·706f·6c69··stem_crypto_poli00042fc0:·656d·5f63·7279·7074·6f5f·706f·6c69·6379··em_crypto_policy
00042e90:·6379·3a20·2121·7374·7220·3c61·6262·7220··cy:·!!str·<abbr· 
00042ea0:·7469·746c·653d·2266·726f·6d20·5072·6f66··title="from·Prof 
00042eb0:·696c·652f·7265·6669·6e65·2d76·616c·7565··ile/refine-value 
00042ec0:·3a20·7863·6364·665f·6f72·672e·7373·6770··:·xccdf_org.ssgp 
00042ed0:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f76··roject.content_v 
00042ee0:·616c·7565·5f76·6172·5f73·7973·7465·6d5f··alue_var_system_ 
00042ef0:·6372·7970·746f·5f70·6f6c·6963·7922·3e46··crypto_policy">F 
00042f00:·4950·533c·2f61·6262·723e·0a20·2074·6167··IPS</abbr>.··tag 
00042f10:·733a·0a20·2020·202d·2061·6c77·6179·730a··s:.····-·always. 
00042f20:·0a2d·206e·616d·653a·2043·6f6e·6669·6775··.-·name:·Configu 
00042f30:·7265·2053·7973·7465·6d20·4372·7970·746f··re·System·Crypto 
00042f40:·6772·6170·6879·2050·6f6c·6963·790a·2020··graphy·Policy.·· 
00042f50:·6c69·6e65·696e·6669·6c65·3a0a·2020·2020··lineinfile:.···· 
00042f60:·7061·7468·3a20·2f65·7463·2f63·7279·7074··path:·/etc/crypt 
00042f70:·6f2d·706f·6c69·6369·6573·2f63·6f6e·6669··o-policies/confi 
00042f80:·670a·2020·2020·7265·6765·7870·3a20·5e28··g.····regexp:·^( 
00042f90:·3f21·2329·285c·532b·2924·0a20·2020·206c··?!#)(\S+)$.····l 
00042fa0:·696e·653a·2027·7b7b·2076·6172·5f73·7973··ine:·'{{·var_sys00042fd0:·7d7d·0a20·2020·2020·2020·2020·2020·2052··}}.············R
 00042fe0:·656d·6169·6e41·6674·6572·4578·6974·3d79··emainAfterExit=y
 00042ff0:·6573·0a20·2020·2020·2020·2020·2020·205b··es.············[
 00043000:·496e·7374·616c·6c5d·0a20·2020·2020·2020··Install].·······
 00043010:·2020·2020·2057·616e·7465·6442·793d·6d75·······WantedBy=mu
 00043020:·6c74·692d·7573·6572·2e74·6172·6765·740a··lti-user.target.
 00043030:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 00043040:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 00043050:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 00043060:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 00043070:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 00043080:·3d22·2369·646d·3837·3635·2220·7461·6269··="#idm8765"·tabi
 00043090:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 000430a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 000430b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 000430c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 000430d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 000430e0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
 000430f0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·..
 00043100:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00043110:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00043120:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00043130:·3d22·6964·6d38·3736·3522·3e3c·7461·626c··="idm8765"><tabl
 00043140:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00043150:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00043160:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00043170:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00043180:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00043190:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 000431a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 000431b0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 000431c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 000431d0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 000431e0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 000431f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00043200:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00043210:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t
 00043220:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
Max diff block lines reached; 2117296/2140922 bytes (98.90%) of diff not shown.
160 KB
html2text {}
    
Offset 562, 14 lines modifiedOffset 562, 39 lines modified
562 »       echo·"to·see·what·package·to·(re)install"·>&2562 »       echo·"to·see·what·package·to·(re)install"·>&2
  
563 »       false··#·end·with·an·error·code563 »       false··#·end·with·an·error·code
564 elif·test·"$rc"·!=·0;·then564 elif·test·"$rc"·!=·0;·then
565 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2565 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
566 »       false··#·end·with·an·error·code566 »       false··#·end·with·an·error·code
567 fi567 fi
 568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 573 ---
 574 apiVersion:·machineconfiguration.openshift.io/v1
 575 kind:·MachineConfig
 576 spec:
 577 ··config:
 578 ····ignition:
 579 ······version:·3.1.0
 580 ····systemd:
 581 ······units:
 582 ········-·name:·configure-crypto-policy.service
 583 ··········enabled:·true
 584 ··········contents:·|
 585 ············[Unit]
 586 ············Before=kubelet.service
 587 ············[Service]
 588 ············Type=oneshot
 589 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 590 ············RemainAfterExit=yes
 591 ············[Install]
 592 ············WantedBy=multi-user.target
568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low594 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low595 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false596 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict597 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
573 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable598 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
574 ··set_fact:599 ··set_fact:
Offset 616, 39 lines modifiedOffset 641, 14 lines modified
616 ··-·PCI-DSSv4-2.2.7641 ··-·PCI-DSSv4-2.2.7
617 ··-·configure_crypto_policy642 ··-·configure_crypto_policy
618 ··-·high_severity643 ··-·high_severity
619 ··-·low_complexity644 ··-·low_complexity
620 ··-·low_disruption645 ··-·low_disruption
621 ··-·no_reboot_needed646 ··-·no_reboot_needed
622 ··-·restrict_strategy647 ··-·restrict_strategy
623 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
624 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
625 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
626 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
627 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
628 --- 
629 apiVersion:·machineconfiguration.openshift.io/v1 
630 kind:·MachineConfig 
631 spec: 
632 ··config: 
633 ····ignition: 
634 ······version:·3.1.0 
635 ····systemd: 
636 ······units: 
637 ········-·name:·configure-crypto-policy.service 
638 ··········enabled:·true 
639 ··········contents:·| 
640 ············[Unit] 
641 ············Before=kubelet.service 
642 ············[Service] 
643 ············Type=oneshot 
644 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
645 ············RemainAfterExit=yes 
646 ············[Install] 
647 ············WantedBy=multi-user.target 
648 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*648 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
649 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.649 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
650 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.650 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
651 Severity: ··medium651 Severity: ··medium
652 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy652 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
653 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453653 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
654 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)654 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 1620, 18 lines modifiedOffset 1620, 21 lines modified
1620 ············_\x8c_\x8u_\x8i·····3.4.51620 ············_\x8c_\x8u_\x8i·····3.4.5
1621 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-0022351621 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-002235
1622 ············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1622 ············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1623 References:·_\x8n_\x8i_\x8s_\x8t····CM-61623 References:·_\x8n_\x8i_\x8s_\x8t····CM-6
1624 ············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.11624 ············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.1
1625 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271625 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1626 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-230532r1017294_rule1626 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-230532r1017294_rule
1627 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81627 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1628 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1629 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1630 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1631 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1632 service·disable·debug-shell
1628 [customizations.services] 
1629 masked·=·["debug-shell"] 
1630 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81633 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1631 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1634 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1632 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1635 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1633 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1636 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1634 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1637 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1635 #·Remediation·is·applicable·only·in·certain·platforms1638 #·Remediation·is·applicable·only·in·certain·platforms
1636 if·rpm·--quiet·-q·kernel;·then1639 if·rpm·--quiet·-q·kernel;·then
Offset 1653, 14 lines modifiedOffset 1656, 33 lines modified
1653 #·so·let's·reset·the·state·so·OVAL·checks·pass.1656 #·so·let's·reset·the·state·so·OVAL·checks·pass.
1654 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.1657 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
1655 "$SYSTEMCTL_EXEC"·reset-failed·'debug-shell.service'·||·true1658 "$SYSTEMCTL_EXEC"·reset-failed·'debug-shell.service'·||·true
  
1656 else1659 else
1657 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1660 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1658 fi1661 fi
 1662 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1663 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1664 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 1665 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 1666 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
 1667 apiVersion:·machineconfiguration.openshift.io/v1
 1668 kind:·MachineConfig
 1669 spec:
 1670 ··config:
 1671 ····ignition:
 1672 ······version:·3.1.0
 1673 ····systemd:
 1674 ······units:
 1675 ······-·name:·debug-shell.service
 1676 ········enabled:·false
 1677 ········mask:·true
Max diff block lines reached; 158762/164234 bytes (96.67%) of diff not shown.
2.73 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ism_o.html
    
Offset 17604, 283 lines modifiedOffset 17604, 283 lines modified
00044c30:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00044c30:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00044c40:·3830·3132·2220·7461·6269·6e64·6578·3d22··8012"·tabindex="00044c40:·3830·3132·2220·7461·6269·6e64·6578·3d22··8012"·tabindex="
00044c50:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00044c50:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00044c60:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00044c60:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00044c70:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00044c70:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00044c80:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00044c80:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00044c90:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00044c90:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00044ca0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·00044ca0:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
00044cb0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
00044cc0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00044cd0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00044ce0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00044cf0:·2220·6964·3d22·6964·6d38·3031·3222·3e3c··"·id="idm8012">< 
00044d00:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
00044d10:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
00044d20:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=· 
00044d30:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
00044d40:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00044d50:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00044d60:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00044d70:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00044d80:·7267·6574·3d22·2369·646d·3830·3133·2220··rget="#idm8013"· 
00044d90:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00044da0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00044db0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00044dc0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00044dd0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
00044de0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
00044df0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
00044e00:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00044cb0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00044e10:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00044cc0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00044e20:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00044cd0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00044e30:·643d·2269·646d·3830·3133·223e·3c74·6162··d="idm8013"><tab00044ce0:·643d·2269·646d·3830·3132·223e·3c74·6162··d="idm8012"><tab
00044e40:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00044cf0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
00044e50:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00044d00:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
00044e60:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab00044d10:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00044e70:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t00044d20:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00044e80:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00044d30:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00044e90:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00044d40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00044ea0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D00044d50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00044eb0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><00044d60:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
00044ec0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00044d70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00044ed0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<00044d80:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
00044ee0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t00044d90:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
00044ef0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00044da0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
00044f00:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00044db0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00044f10:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr00044dc0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
00044f20:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c00044dd0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00044de0:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins
 00044df0:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code
00044f30:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
00044f40:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
00044f50:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
00044f60:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm 
00044f70:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern 
00044f80:·656c·3b20·7468·656e·0a0a·6966·2021·2072··el;·then..if·!·r 
00044f90:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
00044fa0:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
00044fb0:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·" 
00044fc0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
00044fd0:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
00044fe0:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
00044ff0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
00045000:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
00045010:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
00045020:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl00044e00:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
00045030:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc00044e10:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
00045040:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl00044e20:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
00045050:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat00044e30:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
00045060:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm8000044e40:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00045070:·3134·2220·7461·6269·6e64·6578·3d22·3022··14"·tabindex="0"00044e50:·3830·3133·2220·7461·6269·6e64·6578·3d22··8013"·tabindex="
00045080:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00044e60:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00045090:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00044e70:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
000450a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00044e80:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
000450b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00044e90:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
000450c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00044ea0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00044eb0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 00044ec0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 00044ed0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00044ee0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00044ef0:·7073·6522·2069·643d·2269·646d·3830·3133··pse"·id="idm8013
 00044f00:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00044f10:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
000450d0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
000450e0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
000450f0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00045100:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00045110:·6170·7365·2220·6964·3d22·6964·6d38·3031··apse"·id="idm801 
00045120:·3422·3e3c·7461·626c·6520·636c·6173·733d··4"><table·class= 
00045130:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
00045140:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
00045150:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden00044f20:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
00045160:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
00045170:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
00045180:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00045190:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
000451a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
000451b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
000451c0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f00044f30:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00044f40:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00044f50:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00044f60:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00044f70:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00044f80:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00044f90:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00044fa0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00044fb0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00044fc0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00044fd0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00044fe0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00044ff0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 00045000:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 00045010:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 00045020:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00045030:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 00045040:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then..
 00045050:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 00045060:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 00045070:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 00045080:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 00045090:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 000450a0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 000450b0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 000450c0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 000450d0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 000450e0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 000450f0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
Max diff block lines reached; 2583578/2621280 bytes (98.56%) of diff not shown.
232 KB
html2text {}
    
Offset 712, 19 lines modifiedOffset 712, 21 lines modified
712 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3712 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
713 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5713 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
714 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199714 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
715 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79715 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
716 ············_\x8c_\x8i_\x8s············5.3.1716 ············_\x8c_\x8i_\x8s············5.3.1
717 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2717 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
718 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule718 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
719 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8719 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 720 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 721 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 722 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 723 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 724 package·install·aide
720 [[packages]] 
721 name·=·"aide" 
722 version·=·"*" 
723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8725 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
724 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low726 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
725 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low727 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
726 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false728 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
727 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable729 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
728 #·Remediation·is·applicable·only·in·certain·platforms730 #·Remediation·is·applicable·only·in·certain·platforms
729 if·rpm·--quiet·-q·kernel;·then731 if·rpm·--quiet·-q·kernel;·then
Offset 770, 14 lines modifiedOffset 772, 26 lines modified
770 ··-·PCI-DSSv4-11.5.2772 ··-·PCI-DSSv4-11.5.2
771 ··-·enable_strategy773 ··-·enable_strategy
772 ··-·low_complexity774 ··-·low_complexity
773 ··-·low_disruption775 ··-·low_disruption
774 ··-·medium_severity776 ··-·medium_severity
775 ··-·no_reboot_needed777 ··-·no_reboot_needed
776 ··-·package_aide_installed778 ··-·package_aide_installed
 779 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 780 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 781 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 782 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 783 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 784 package·--add=aide
 785 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 786 [[packages]]
 787 name·=·"aide"
 788 version·=·"*"
777 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8789 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
778 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low790 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
779 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low791 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
780 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false792 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
781 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable793 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
782 dnf·install·aide794 dnf·install·aide
Offset 789, 28 lines modifiedOffset 803, 14 lines modified
789 include·install_aide803 include·install_aide
  
790 class·install_aide·{804 class·install_aide·{
791 ··package·{·'aide':805 ··package·{·'aide':
792 ····ensure·=>·'installed',806 ····ensure·=>·'installed',
793 ··}807 ··}
794 }808 }
795 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
796 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
797 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
798 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
799 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
800 package·install·aide 
801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
802 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
803 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
804 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
805 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
806 package·--add=aide 
807 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule809 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule
808 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.810 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
809 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.811 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
810 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.812 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
811 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*813 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 823, 31 lines modifiedOffset 823, 31 lines modified
823 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877823 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
824 ············_\x8i_\x8s_\x8m······1446824 ············_\x8i_\x8s_\x8m······1446
825 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1825 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
826 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12826 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
827 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1827 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
828 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176828 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
829 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule829 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
830 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
831 [customizations] 
832 fips·=·true 
833 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8830 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
834 #·Remediation·is·applicable·only·in·certain·platforms831 #·Remediation·is·applicable·only·in·certain·platforms
835 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then832 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
836 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then833 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
837 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF834 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
838 kargs·=·["fips=1"]835 kargs·=·["fips=1"]
839 EOF836 EOF
840 fi837 fi
  
841 else838 else
842 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'839 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
843 fi840 fi
 841 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 842 [customizations]
 843 fips·=·true
844 Group  ·System·Cryptographic·Policies·  Group·contains·3·rules844 Group  ·System·Cryptographic·Policies·  Group·contains·3·rules
845 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:845 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
846 ····*·GnuTLS·library846 ····*·GnuTLS·library
847 ····*·OpenSSL·library847 ····*·OpenSSL·library
848 ····*·NSS·library848 ····*·NSS·library
849 ····*·OpenJDK849 ····*·OpenJDK
850 ····*·Libkrb5850 ····*·Libkrb5
Offset 888, 14 lines modifiedOffset 888, 39 lines modified
888 »       echo·"to·see·what·package·to·(re)install"·>&2888 »       echo·"to·see·what·package·to·(re)install"·>&2
  
889 »       false··#·end·with·an·error·code889 »       false··#·end·with·an·error·code
890 elif·test·"$rc"·!=·0;·then890 elif·test·"$rc"·!=·0;·then
891 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2891 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
892 »       false··#·end·with·an·error·code892 »       false··#·end·with·an·error·code
893 fi893 fi
 894 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 895 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 896 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 230312/237303 bytes (97.05%) of diff not shown.
4.18 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-ospp.html
    
Offset 15330, 283 lines modifiedOffset 15330, 283 lines modified
0003be10:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003be10:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003be20:·6964·6d38·3031·3222·2074·6162·696e·6465··idm8012"·tabinde0003be20:·6964·6d38·3031·3222·2074·6162·696e·6465··idm8012"·tabinde
0003be30:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003be30:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003be40:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003be40:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003be50:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003be50:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003be60:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003be60:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003be70:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003be70:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003be80:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003be80:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
0003be90:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003bea0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003beb0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003bec0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003bed0:·7073·6522·2069·643d·2269·646d·3830·3132··pse"·id="idm8012 
0003bee0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003bef0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003bf00:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003bf10:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003bf20:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003bf30:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003bf40:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003bf50:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003bf60:·2d74·6172·6765·743d·2223·6964·6d38·3031··-target="#idm801 
0003bf70:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"· 
0003bf80:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003bf90:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003bfa0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003bfb0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003bfc0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003bfd0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003bfe0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003be90:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003bff0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003bea0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003c000:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003beb0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003c010:·2220·6964·3d22·6964·6d38·3031·3322·3e3c··"·id="idm8013"><0003bec0:·2220·6964·3d22·6964·6d38·3031·3222·3e3c··"·id="idm8012"><
0003c020:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003bed0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003c030:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003bee0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003c040:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003bef0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003c050:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003bf00:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003c060:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003bf10:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003c070:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003bf20:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003c080:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c090:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003c0a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c0b0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003c0c0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003c0d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c0e0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003c0f0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003c100:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003c110:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003c120:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003c130:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003c140:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003c150:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003c160:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if· 
0003c170:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003c180:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003c190:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·- 
0003c1a0:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003c1b0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003c1c0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003c1d0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003c1e0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003c1f0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003c200:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003c210:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003c220:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003c230:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003c240:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003c250:·6d38·3031·3422·2074·6162·696e·6465·783d··m8014"·tabindex= 
0003c260:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003c270:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003c280:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003c290:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003c2a0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003c2b0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003c2c0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003c2d0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003c2e0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003c2f0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003c300:·3830·3134·223e·3c74·6162·6c65·2063·6c61··8014"><table·cla 
0003c310:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003c320:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003c330:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003c340:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003c350:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003c360:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003c370:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003c380:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003c390:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003bf30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003c3a0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003c3b0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003c3c0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003bf40:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003bf50:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bf60:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003c3d0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003bf70:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003bf80:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003bf90:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003bfa0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003bfb0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003bfc0:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003bfd0:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c
 0003bfe0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003bff0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003c000:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003c010:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003c020:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003c030:·6964·6d38·3031·3322·2074·6162·696e·6465··idm8013"·tabinde
 0003c040:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003c050:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003c060:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003c070:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003c080:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003c090:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003c0a0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003c0b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003c0c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003c0d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 0003c0e0:·3031·3322·3e3c·7461·626c·6520·636c·6173··013"><table·clas
 0003c0f0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003c100:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003c110:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003c120:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003c130:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003c140:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003c150:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003c3e0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003c3f0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
Max diff block lines reached; 3895686/3933388 bytes (99.04%) of diff not shown.
435 KB
html2text {}
    
Offset 130, 19 lines modifiedOffset 130, 21 lines modified
130 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3130 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
131 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5131 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
132 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199132 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
133 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79133 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
134 ············_\x8c_\x8i_\x8s············5.3.1134 ············_\x8c_\x8i_\x8s············5.3.1
135 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2135 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
136 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule136 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 142 package·install·aide
138 [[packages]] 
139 name·=·"aide" 
140 version·=·"*" 
141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
146 #·Remediation·is·applicable·only·in·certain·platforms148 #·Remediation·is·applicable·only·in·certain·platforms
147 if·rpm·--quiet·-q·kernel;·then149 if·rpm·--quiet·-q·kernel;·then
Offset 188, 14 lines modifiedOffset 190, 26 lines modified
188 ··-·PCI-DSSv4-11.5.2190 ··-·PCI-DSSv4-11.5.2
189 ··-·enable_strategy191 ··-·enable_strategy
190 ··-·low_complexity192 ··-·low_complexity
191 ··-·low_disruption193 ··-·low_disruption
192 ··-·medium_severity194 ··-·medium_severity
193 ··-·no_reboot_needed195 ··-·no_reboot_needed
194 ··-·package_aide_installed196 ··-·package_aide_installed
 197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 202 package·--add=aide
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 204 [[packages]]
 205 name·=·"aide"
 206 version·=·"*"
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
200 dnf·install·aide212 dnf·install·aide
Offset 207, 28 lines modifiedOffset 221, 14 lines modified
207 include·install_aide221 include·install_aide
  
208 class·install_aide·{222 class·install_aide·{
209 ··package·{·'aide':223 ··package·{·'aide':
210 ····ensure·=>·'installed',224 ····ensure·=>·'installed',
211 ··}225 ··}
212 }226 }
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
218 package·install·aide 
219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
224 package·--add=aide 
225 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules227 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
226 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.228 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
227 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.229 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
228 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.230 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*231 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 255, 31 lines modifiedOffset 255, 31 lines modified
255 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877255 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
256 ············_\x8i_\x8s_\x8m······1446256 ············_\x8i_\x8s_\x8m······1446
257 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1257 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
258 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12258 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
259 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1259 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
260 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176260 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
261 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule261 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
262 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
263 [customizations] 
264 fips·=·true 
265 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8262 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
266 #·Remediation·is·applicable·only·in·certain·platforms263 #·Remediation·is·applicable·only·in·certain·platforms
267 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then264 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
268 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then265 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
269 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF266 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
270 kargs·=·["fips=1"]267 kargs·=·["fips=1"]
271 EOF268 EOF
272 fi269 fi
  
273 else270 else
274 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'271 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
275 fi272 fi
 273 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 274 [customizations]
 275 fips·=·true
276 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules276 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules
277 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:277 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
278 ····*·GnuTLS·library278 ····*·GnuTLS·library
279 ····*·OpenSSL·library279 ····*·OpenSSL·library
280 ····*·NSS·library280 ····*·NSS·library
281 ····*·OpenJDK281 ····*·OpenJDK
282 ····*·Libkrb5282 ····*·Libkrb5
Offset 291, 19 lines modifiedOffset 291, 21 lines modified
291 $·sudo·yum·install·crypto-policies291 $·sudo·yum·install·crypto-policies
292 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.292 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
293 Severity: ··medium293 Severity: ··medium
294 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed294 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
295 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123295 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
296 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1296 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
297 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174297 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
298 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8298 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 299 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 300 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 438484/445433 bytes (98.44%) of diff not shown.
2.89 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-pci-dss.html
    
Offset 16856, 283 lines modifiedOffset 16856, 283 lines modified
00041d70:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00041d70:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00041d80:·2223·6964·6d38·3031·3222·2074·6162·696e··"#idm8012"·tabin00041d80:·2223·6964·6d38·3031·3222·2074·6162·696e··"#idm8012"·tabin
00041d90:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00041d90:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00041da0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00041da0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00041db0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00041db0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00041dc0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00041dc0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00041dd0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00041dd0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00041de0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB00041de0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
00041df0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
00041e00:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00041e10:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00041e20:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00041e30:·6c61·7073·6522·2069·643d·2269·646d·3830··lapse"·id="idm80 
00041e40:·3132·223e·3c70·7265·3e3c·636f·6465·3e0a··12"><pre><code>. 
00041e50:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
00041e60:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
00041e70:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
00041e80:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00041e90:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00041ea0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00041eb0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00041ec0:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8 
00041ed0:·3031·3322·2074·6162·696e·6465·783d·2230··013"·tabindex="0 
00041ee0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
00041ef0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
00041f00:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
00041f10:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
00041f20:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
00041f30:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
00041f40:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><00041df0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
00041f50:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel00041e00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00041f60:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap00041e10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00041f70:·7365·2220·6964·3d22·6964·6d38·3031·3322··se"·id="idm8013"00041e20:·7365·2220·6964·3d22·6964·6d38·3031·3222··se"·id="idm8012"
00041f80:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t00041e30:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00041f90:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip00041e40:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
00041fa0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere00041e50:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
00041fb0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense00041e60:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
00041fc0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl00041e70:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
00041fd0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l00041e80:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
00041fe0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>00041e90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00041ff0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<00041ea0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
00042000:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00041eb0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00042010:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb00041ec0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
00042020:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal00041ed0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
00042030:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>00041ee0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
00042040:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t00041ef0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
00042050:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td00041f00:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
00042060:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p00041f10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00041f20:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 00041f30:·6520·696e·7374·616c·6c20·6169·6465·0a3c··e·install·aide.<
00042070:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
00042080:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
00042090:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
000420a0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
000420b0:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
000420c0:·206b·6572·6e65·6c3b·2074·6865·6e0a·0a69···kernel;·then..i 
000420d0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
000420e0:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
000420f0:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install 
00042100:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
00042110:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
00042120:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
00042130:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
00042140:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
00042150:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
00042160:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>00041f40:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
00042170:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt00041f50:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
00042180:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-00041f60:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
00042190:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse00041f70:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
000421a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00041f80:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
000421b0:·6964·6d38·3031·3422·2074·6162·696e·6465··idm8014"·tabinde00041f90:·2223·6964·6d38·3031·3322·2074·6162·696e··"#idm8013"·tabin
000421c0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt00041fa0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
000421d0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande00041fb0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
000421e0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=00041fc0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
000421f0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev00041fd0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00042200:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R00041fe0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00042210:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib00041ff0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 00042000:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 00042010:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00042020:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00042030:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00042040:·6d38·3031·3322·3e3c·7461·626c·6520·636c··m8013"><table·cl
 00042050:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
00042220:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
00042230:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00042240:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00042250:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00042260:·646d·3830·3134·223e·3c74·6162·6c65·2063··dm8014"><table·c 
00042270:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
00042280:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
00042290:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c00042060:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
000422a0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
000422b0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
000422c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
000422d0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
000422e0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l00042070:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 00042080:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00042090:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 000420a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 000420b0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 000420c0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 000420d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 000420e0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 000420f0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00042100:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00042110:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
000422f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>00042120:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
00042300:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>00042130:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 00042140:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 00042150:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 00042160:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 00042170:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 00042180:·6965·7420·2d71·206b·6572·6e65·6c3b·2074··iet·-q·kernel;·t
 00042190:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 000421a0:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"·
 000421b0:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 000421c0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 000421d0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 000421e0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 000421f0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 00042200:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 00042210:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 00042220:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 00042230:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 00042240:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 00042250:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 00042260:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
Max diff block lines reached; 2748422/2786124 bytes (98.65%) of diff not shown.
237 KB
html2text {}
    
Offset 528, 19 lines modifiedOffset 528, 21 lines modified
528 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3528 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
529 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5529 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
530 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199530 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
531 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79531 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
532 ············_\x8c_\x8i_\x8s············5.3.1532 ············_\x8c_\x8i_\x8s············5.3.1
533 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2533 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
534 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule534 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
535 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8535 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 536 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 537 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 538 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 539 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 540 package·install·aide
536 [[packages]] 
537 name·=·"aide" 
538 version·=·"*" 
539 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
540 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low542 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
541 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low543 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
542 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false544 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
543 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable545 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
544 #·Remediation·is·applicable·only·in·certain·platforms546 #·Remediation·is·applicable·only·in·certain·platforms
545 if·rpm·--quiet·-q·kernel;·then547 if·rpm·--quiet·-q·kernel;·then
Offset 586, 14 lines modifiedOffset 588, 26 lines modified
586 ··-·PCI-DSSv4-11.5.2588 ··-·PCI-DSSv4-11.5.2
587 ··-·enable_strategy589 ··-·enable_strategy
588 ··-·low_complexity590 ··-·low_complexity
589 ··-·low_disruption591 ··-·low_disruption
590 ··-·medium_severity592 ··-·medium_severity
591 ··-·no_reboot_needed593 ··-·no_reboot_needed
592 ··-·package_aide_installed594 ··-·package_aide_installed
 595 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 596 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 597 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 598 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 599 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 600 package·--add=aide
 601 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 602 [[packages]]
 603 name·=·"aide"
 604 version·=·"*"
593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8605 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
594 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low606 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
595 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low607 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
596 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false608 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
597 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable609 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
598 dnf·install·aide610 dnf·install·aide
Offset 605, 28 lines modifiedOffset 619, 14 lines modified
605 include·install_aide619 include·install_aide
  
606 class·install_aide·{620 class·install_aide·{
607 ··package·{·'aide':621 ··package·{·'aide':
608 ····ensure·=>·'installed',622 ····ensure·=>·'installed',
609 ··}623 ··}
610 }624 }
611 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
612 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
613 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
614 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
615 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
616 package·install·aide 
617 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
618 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
619 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
620 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
621 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
622 package·--add=aide 
623 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*625 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
624 Run·the·following·command·to·generate·a·new·database:626 Run·the·following·command·to·generate·a·new·database:
625 $·sudo·/usr/sbin/aide·--init627 $·sudo·/usr/sbin/aide·--init
626 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:628 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
627 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz629 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
628 To·initiate·a·manual·check,·run·the·following·command:630 To·initiate·a·manual·check,·run·the·following·command:
629 $·sudo·/usr/sbin/aide·--check631 $·sudo·/usr/sbin/aide·--check
Offset 973, 14 lines modifiedOffset 973, 39 lines modified
973 »       echo·"to·see·what·package·to·(re)install"·>&2973 »       echo·"to·see·what·package·to·(re)install"·>&2
  
974 »       false··#·end·with·an·error·code974 »       false··#·end·with·an·error·code
975 elif·test·"$rc"·!=·0;·then975 elif·test·"$rc"·!=·0;·then
976 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2976 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
977 »       false··#·end·with·an·error·code977 »       false··#·end·with·an·error·code
978 fi978 fi
 979 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 980 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 981 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 982 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 983 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 984 ---
 985 apiVersion:·machineconfiguration.openshift.io/v1
 986 kind:·MachineConfig
 987 spec:
 988 ··config:
 989 ····ignition:
 990 ······version:·3.1.0
 991 ····systemd:
 992 ······units:
 993 ········-·name:·configure-crypto-policy.service
 994 ··········enabled:·true
 995 ··········contents:·|
 996 ············[Unit]
 997 ············Before=kubelet.service
 998 ············[Service]
 999 ············Type=oneshot
 1000 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 1001 ············RemainAfterExit=yes
 1002 ············[Install]
 1003 ············WantedBy=multi-user.target
979 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81004 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
980 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1005 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
981 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1006 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
982 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1007 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
983 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict1008 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
984 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable1009 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
985 ··set_fact:1010 ··set_fact:
Offset 1027, 39 lines modifiedOffset 1052, 14 lines modified
1027 ··-·PCI-DSSv4-2.2.71052 ··-·PCI-DSSv4-2.2.7
1028 ··-·configure_crypto_policy1053 ··-·configure_crypto_policy
1029 ··-·high_severity1054 ··-·high_severity
1030 ··-·low_complexity1055 ··-·low_complexity
1031 ··-·low_disruption1056 ··-·low_disruption
1032 ··-·no_reboot_needed1057 ··-·no_reboot_needed
Max diff block lines reached; 237598/242499 bytes (97.98%) of diff not shown.
4.16 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-stig.html
    
Offset 15363, 282 lines modifiedOffset 15363, 282 lines modified
0003c020:·6172·6765·743d·2223·6964·6d38·3031·3222··arget="#idm8012"0003c020:·6172·6765·743d·2223·6964·6d38·3031·3222··arget="#idm8012"
0003c030:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003c030:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003c040:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003c040:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003c050:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003c050:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003c060:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003c060:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003c070:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003c070:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003c080:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003c080:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003c090:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003c0a0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003c0b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003c0c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003c0d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003c0e0:·2269·646d·3830·3132·223e·3c70·7265·3e3c··"idm8012"><pre>< 
0003c0f0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003c100:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003c110:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003c120:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003c130:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003c140:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003c150:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003c160:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003c170:·2223·6964·6d38·3031·3322·2074·6162·696e··"#idm8013"·tabin 
0003c180:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003c190:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003c1a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003c1b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003c1c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003c1d0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003c1e0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a0003c090:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a
0003c1f0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003c0a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003c200:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003c0b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003c210:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003c0c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003c220:·6d38·3031·3322·3e3c·7461·626c·6520·636c··m8013"><table·cl0003c0d0:·6d38·3031·3222·3e3c·7461·626c·6520·636c··m8012"><table·cl
0003c230:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003c240:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003c250:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003c260:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003c270:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003c280:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c290:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003c2a0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003c2b0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c2c0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003c2d0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003c2e0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003c2f0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003c300:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003c310:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0003c320:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003c330:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003c340:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003c350:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu 
0003c360:·6965·7420·2d71·206b·6572·6e65·6c3b·2074··iet·-q·kernel;·t 
0003c370:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q 
0003c380:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"· 
0003c390:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i 
0003c3a0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003c3b0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g 
0003c3c0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003c3d0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003c3e0:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003c3f0:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003c400:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003c410:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003c420:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003c430:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003c440:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003c450:·6765·743d·2223·6964·6d38·3031·3422·2074··get="#idm8014"·t 
0003c460:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003c470:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003c480:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003c490:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003c4a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003c4b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003c4c0:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003c4d0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003c4e0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003c4f0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003c500:·2069·643d·2269·646d·3830·3134·223e·3c74···id="idm8014"><t 
0003c510:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003c520:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003c530:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003c540:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003c550:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003c560:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003c570:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c580:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003c590:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003c5a0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003c5b0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003c5c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003c5d0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003c5e0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003c5f0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003c600:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4761··<code>-·name:·Ga 
0003c610:·7468·6572·2074·6865·2070·6163·6b61·6765··ther·the·package 
0003c620:·2066·6163·7473·0a20·2070·6163·6b61·6765···facts.··package 
0003c630:·5f66·6163·7473·3a0a·2020·2020·6d61·6e61··_facts:.····mana 
0003c640:·6765·723a·2061·7574·6f0a·2020·7461·6773··ger:·auto.··tags 
0003c650:·3a0a·2020·2d20·434a·4953·2d35·2e31·302e··:.··-·CJIS-5.10. 
0003c660:·312e·330a·2020·2d20·4449·5341·2d53·5449··1.3.··-·DISA-STI 
0003c670:·472d·5248·454c·2d30·382d·3031·3033·3539··G-RHEL-08-010359 
0003c680:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003c690:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI 
0003c6a0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.·· 
0003c6b0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5 
0003c6c0:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st 
0003c6d0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c 
0003c6e0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo 
0003c6f0:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··- 
0003c700:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity 
0003c710:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n 
0003c720:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag 
0003c730:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed 
0003c740:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure 
0003c750:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install 
0003c760:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.·· 
0003c770:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.··· 
0003c780:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present. 
0003c790:·2020·7768·656e·3a20·2722·6b65·726e·656c····when:·'"kernel 
0003c7a0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
0003c7b0:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t 
0003c7c0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5. 
0003c7d0:·3130·2e31·2e33·0a20·202d·2044·4953·412d··10.1.3.··-·DISA- 
0003c7e0:·5354·4947·2d52·4845·4c2d·3038·2d30·3130··STIG-RHEL-08-010 
0003c7f0:·3335·390a·2020·2d20·4e49·5354·2d38·3030··359.··-·NIST-800 
0003c800:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-· 
Max diff block lines reached; 3916351/3953915 bytes (99.05%) of diff not shown.
398 KB
html2text {}
    
Offset 136, 19 lines modifiedOffset 136, 21 lines modified
136 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3136 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
139 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79139 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
140 ············_\x8c_\x8i_\x8s············5.3.1140 ············_\x8c_\x8i_\x8s············5.3.1
141 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2141 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
142 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule142 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 144 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 145 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 146 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 147 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 148 package·install·aide
144 [[packages]] 
145 name·=·"aide" 
146 version·=·"*" 
147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8149 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low150 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low151 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false152 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable153 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
152 #·Remediation·is·applicable·only·in·certain·platforms154 #·Remediation·is·applicable·only·in·certain·platforms
153 if·rpm·--quiet·-q·kernel;·then155 if·rpm·--quiet·-q·kernel;·then
Offset 194, 14 lines modifiedOffset 196, 26 lines modified
194 ··-·PCI-DSSv4-11.5.2196 ··-·PCI-DSSv4-11.5.2
195 ··-·enable_strategy197 ··-·enable_strategy
196 ··-·low_complexity198 ··-·low_complexity
197 ··-·low_disruption199 ··-·low_disruption
198 ··-·medium_severity200 ··-·medium_severity
199 ··-·no_reboot_needed201 ··-·no_reboot_needed
200 ··-·package_aide_installed202 ··-·package_aide_installed
 203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 208 package·--add=aide
 209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 210 [[packages]]
 211 name·=·"aide"
 212 version·=·"*"
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
206 dnf·install·aide218 dnf·install·aide
Offset 213, 28 lines modifiedOffset 227, 14 lines modified
213 include·install_aide227 include·install_aide
  
214 class·install_aide·{228 class·install_aide·{
215 ··package·{·'aide':229 ··package·{·'aide':
216 ····ensure·=>·'installed',230 ····ensure·=>·'installed',
217 ··}231 ··}
218 }232 }
219 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
220 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
221 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
222 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
223 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
224 package·install·aide 
225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
230 package·--add=aide 
231 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*233 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
232 Run·the·following·command·to·generate·a·new·database:234 Run·the·following·command·to·generate·a·new·database:
233 $·sudo·/usr/sbin/aide·--init235 $·sudo·/usr/sbin/aide·--init
234 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:236 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
235 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz237 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
236 To·initiate·a·manual·check,·run·the·following·command:238 To·initiate·a·manual·check,·run·the·following·command:
237 $·sudo·/usr/sbin/aide·--check239 $·sudo·/usr/sbin/aide·--check
Offset 1732, 31 lines modifiedOffset 1732, 31 lines modified
1732 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008771732 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
1733 ············_\x8i_\x8s_\x8m······14461733 ············_\x8i_\x8s_\x8m······1446
1734 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11734 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1735 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121735 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1736 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11736 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1737 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761737 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1738 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule1738 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
1739 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1740 [customizations] 
1741 fips·=·true 
1742 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81739 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1743 #·Remediation·is·applicable·only·in·certain·platforms1740 #·Remediation·is·applicable·only·in·certain·platforms
1744 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then1741 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
1745 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1742 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1746 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1743 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1747 kargs·=·["fips=1"]1744 kargs·=·["fips=1"]
1748 EOF1745 EOF
1749 fi1746 fi
  
1750 else1747 else
1751 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1748 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1752 fi1749 fi
 1750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1751 [customizations]
 1752 fips·=·true
1753 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1753 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1754 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·8·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1754 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·8·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1755 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1755 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1756 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1756 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1757 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1757 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
1758 Severity: ··high1758 Severity: ··high
1759 Rule·ID:····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled1759 Rule·ID:····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled
Offset 1917, 14 lines modifiedOffset 1917, 39 lines modified
1917 »       echo·"to·see·what·package·to·(re)install"·>&21917 »       echo·"to·see·what·package·to·(re)install"·>&2
  
1918 »       false··#·end·with·an·error·code1918 »       false··#·end·with·an·error·code
1919 elif·test·"$rc"·!=·0;·then1919 elif·test·"$rc"·!=·0;·then
1920 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&21920 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
1921 »       false··#·end·with·an·error·code1921 »       false··#·end·with·an·error·code
1922 fi1922 fi
 1923 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1924 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1925 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 398942/407359 bytes (97.93%) of diff not shown.
4.1 MB
./usr/share/doc/ssg-nondebian/ssg-centos8-guide-stig_gui.html
    
Offset 15382, 282 lines modifiedOffset 15382, 282 lines modified
0003c150:·7461·7267·6574·3d22·2369·646d·3830·3132··target="#idm80120003c150:·7461·7267·6574·3d22·2369·646d·3830·3132··target="#idm8012
0003c160:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003c160:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003c170:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003c170:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003c180:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003c180:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003c190:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003c190:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003c1a0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003c1a0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003c1b0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003c1b0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003c1c0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003c1d0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003c1e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003c1f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003c200:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003c210:·3d22·6964·6d38·3031·3222·3e3c·7072·653e··="idm8012"><pre> 
0003c220:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003c230:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003c240:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003c250:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003c260:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003c270:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003c280:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003c290:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003c2a0:·3d22·2369·646d·3830·3133·2220·7461·6269··="#idm8013"·tabi 
0003c2b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003c2c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003c2d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003c2e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003c2f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003c300:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003c310:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003c320:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003c330:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003c340:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003c350:·646d·3830·3133·223e·3c74·6162·6c65·2063··dm8013"><table·c 
0003c360:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003c370:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003c380:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003c390:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003c3a0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003c3b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c3c0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003c3d0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003c3e0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c3f0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003c400:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003c410:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003c420:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003c430:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003c440:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003c450:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003c460:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003c470:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003c480:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q 
0003c490:·7569·6574·202d·7120·6b65·726e·656c·3b20··uiet·-q·kernel;· 
0003c4a0:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003c4b0:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003c4c0:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum· 
0003c4d0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003c4e0:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003c4f0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003c500:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003c510:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003c520:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003c530:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003c540:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c550:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c560:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c570:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c580:·7267·6574·3d22·2369·646d·3830·3134·2220··rget="#idm8014"· 
0003c590:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c5a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c5b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c5c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c5d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c5e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c5f0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003c600:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003c610:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003c620:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003c630:·2220·6964·3d22·6964·6d38·3031·3422·3e3c··"·id="idm8014">< 
0003c640:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003c650:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003c660:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003c670:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003c680:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003c690:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003c6a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c6b0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003c6c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c6d0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003c6e0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003c6f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003c700:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003c710:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003c720:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003c730:·3e3c·636f·6465·3e2d·206e·616d·653a·2047··><code>-·name:·G 
0003c740:·6174·6865·7220·7468·6520·7061·636b·6167··ather·the·packag 
0003c750:·6520·6661·6374·730a·2020·7061·636b·6167··e·facts.··packag 
0003c760:·655f·6661·6374·733a·0a20·2020·206d·616e··e_facts:.····man 
0003c770:·6167·6572·3a20·6175·746f·0a20·2074·6167··ager:·auto.··tag 
0003c780:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10 
0003c790:·2e31·2e33·0a20·202d·2044·4953·412d·5354··.1.3.··-·DISA-ST 
0003c7a0:·4947·2d52·4845·4c2d·3038·2d30·3130·3335··IG-RHEL-08-01035 
0003c7b0:·390a·2020·2d20·4e49·5354·2d38·3030·2d35··9.··-·NIST-800-5 
0003c7c0:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC 
0003c7d0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.· 
0003c7e0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11. 
0003c7f0:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s 
0003c800:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_ 
0003c810:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l 
0003c820:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.·· 
0003c830:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit 
0003c840:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_ 
0003c850:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa 
0003c860:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe 
0003c870:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur 
0003c880:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal 
0003c890:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.· 
0003c8a0:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.·· 
0003c8b0:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present 
0003c8c0:·0a20·2077·6865·6e3a·2027·226b·6572·6e65··.··when:·'"kerne 
0003c8d0:·6c22·2069·6e20·616e·7369·626c·655f·6661··l"·in·ansible_fa 
0003c8e0:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
0003c8f0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5 
0003c900:·2e31·302e·312e·330a·2020·2d20·4449·5341··.10.1.3.··-·DISA 
0003c910:·2d53·5449·472d·5248·454c·2d30·382d·3031··-STIG-RHEL-08-01 
0003c920:·3033·3539·0a20·202d·204e·4953·542d·3830··0359.··-·NIST-80 
0003c930:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
Max diff block lines reached; 3857091/3894655 bytes (99.04%) of diff not shown.
393 KB
html2text {}
    
Offset 141, 19 lines modifiedOffset 141, 21 lines modified
141 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3141 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
142 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5142 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
143 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199143 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
144 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79144 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
145 ············_\x8c_\x8i_\x8s············5.3.1145 ············_\x8c_\x8i_\x8s············5.3.1
146 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2146 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
147 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule147 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 153 package·install·aide
149 [[packages]] 
150 name·=·"aide" 
151 version·=·"*" 
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
157 #·Remediation·is·applicable·only·in·certain·platforms159 #·Remediation·is·applicable·only·in·certain·platforms
158 if·rpm·--quiet·-q·kernel;·then160 if·rpm·--quiet·-q·kernel;·then
Offset 199, 14 lines modifiedOffset 201, 26 lines modified
199 ··-·PCI-DSSv4-11.5.2201 ··-·PCI-DSSv4-11.5.2
200 ··-·enable_strategy202 ··-·enable_strategy
201 ··-·low_complexity203 ··-·low_complexity
202 ··-·low_disruption204 ··-·low_disruption
203 ··-·medium_severity205 ··-·medium_severity
204 ··-·no_reboot_needed206 ··-·no_reboot_needed
205 ··-·package_aide_installed207 ··-·package_aide_installed
 208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 213 package·--add=aide
 214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 215 [[packages]]
 216 name·=·"aide"
 217 version·=·"*"
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
211 dnf·install·aide223 dnf·install·aide
Offset 218, 28 lines modifiedOffset 232, 14 lines modified
218 include·install_aide232 include·install_aide
  
219 class·install_aide·{233 class·install_aide·{
220 ··package·{·'aide':234 ··package·{·'aide':
221 ····ensure·=>·'installed',235 ····ensure·=>·'installed',
222 ··}236 ··}
223 }237 }
224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
227 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
228 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
229 package·install·aide 
230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
231 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
232 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
233 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
234 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
235 package·--add=aide 
236 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*238 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
237 Run·the·following·command·to·generate·a·new·database:239 Run·the·following·command·to·generate·a·new·database:
238 $·sudo·/usr/sbin/aide·--init240 $·sudo·/usr/sbin/aide·--init
239 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:241 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
240 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz242 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
241 To·initiate·a·manual·check,·run·the·following·command:243 To·initiate·a·manual·check,·run·the·following·command:
242 $·sudo·/usr/sbin/aide·--check244 $·sudo·/usr/sbin/aide·--check
Offset 1737, 31 lines modifiedOffset 1737, 31 lines modified
1737 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008771737 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
1738 ············_\x8i_\x8s_\x8m······14461738 ············_\x8i_\x8s_\x8m······1446
1739 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11739 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1740 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121740 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1741 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11741 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1742 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761742 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1743 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule1743 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
1744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1745 [customizations] 
1746 fips·=·true 
1747 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1748 #·Remediation·is·applicable·only·in·certain·platforms1745 #·Remediation·is·applicable·only·in·certain·platforms
1749 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then1746 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
1750 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1747 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1751 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1748 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1752 kargs·=·["fips=1"]1749 kargs·=·["fips=1"]
1753 EOF1750 EOF
1754 fi1751 fi
  
1755 else1752 else
1756 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1753 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1757 fi1754 fi
 1755 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1756 [customizations]
 1757 fips·=·true
1758 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1758 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1759 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·8·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1759 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·8·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1760 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1760 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1761 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1761 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1762 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1762 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
1763 Severity: ··high1763 Severity: ··high
1764 Rule·ID:····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled1764 Rule·ID:····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled
Offset 1922, 14 lines modifiedOffset 1922, 39 lines modified
1922 »       echo·"to·see·what·package·to·(re)install"·>&21922 »       echo·"to·see·what·package·to·(re)install"·>&2
  
1923 »       false··#·end·with·an·error·code1923 »       false··#·end·with·an·error·code
1924 elif·test·"$rc"·!=·0;·then1924 elif·test·"$rc"·!=·0;·then
1925 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&21925 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
1926 »       false··#·end·with·an·error·code1926 »       false··#·end·with·an·error·code
1927 fi1927 fi
 1928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1929 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1930 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 393724/402141 bytes (97.91%) of diff not shown.
2.77 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_enhanced.html
    
Offset 15178, 279 lines modifiedOffset 15178, 279 lines modified
0003b490:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b490:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b4a0:·3d22·2369·646d·3733·3331·2220·7461·6269··="#idm7331"·tabi0003b4a0:·3d22·2369·646d·3733·3331·2220·7461·6269··="#idm7331"·tabi
0003b4b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b4b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b4c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b4c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b4d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b4d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b4e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b4e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b4f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b4f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b500:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003b500:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
0003b510:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003b520:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b530:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b540:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b550:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b560:·3333·3122·3e3c·7072·653e·3c63·6f64·653e··331"><pre><code> 
0003b570:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003b580:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003b590:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003b5a0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b5b0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b5c0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b5d0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b5e0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b5f0:·3733·3332·2220·7461·6269·6e64·6578·3d22··7332"·tabindex=" 
0003b600:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b610:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b620:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b630:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b640:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b650:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b660:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0003b510:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
0003b670:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b520:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003b680:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b530:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003b690:·7073·6522·2069·643d·2269·646d·3733·3332··pse"·id="idm73320003b540:·7073·6522·2069·643d·2269·646d·3733·3331··pse"·id="idm7331
0003b6a0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b550:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003b6b0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b560:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003b6c0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b570:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003b6d0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b580:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003b6e0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b590:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003b6f0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b5a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003b700:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b5b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b710:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b5c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003b720:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b5d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b730:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b5e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003b740:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b5f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b750:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b600:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003b760:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b610:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003b770:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b620:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003b780:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b630:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003b790:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme0003b640:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003b650:·6765·2069·6e73·7461·6c6c·2061·6964·650a··ge·install·aide.
0003b7a0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b7b0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b7c0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b7d0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003b7e0:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then.. 
0003b7f0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b800:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b810:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal 
0003b820:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b830:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b840:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b850:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b860:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b870:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b880:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003b660:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003b890:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003b670:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003b8a0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003b680:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003b8b0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003b690:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003b8c0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b6a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b8d0:·2369·646d·3733·3333·2220·7461·6269·6e64··#idm7333"·tabind0003b6b0:·3d22·2369·646d·3733·3332·2220·7461·6269··="#idm7332"·tabi
0003b8e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b6c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b8f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b6d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b900:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b6e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b910:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b6f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b920:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b700:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b930:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003b710:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
0003b940:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b950:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b960:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b970:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b720:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003b730:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b740:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b750:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b980:·6964·6d37·3333·3322·3e3c·7461·626c·6520··idm7333"><table·0003b760:·646d·3733·3332·223e·3c74·6162·6c65·2063··dm7332"><table·c
 0003b770:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b990:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b9a0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b9b0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b780:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b9c0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b9d0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b9e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b9f0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003ba00:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b790:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b7a0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b7b0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b7c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b7d0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b7e0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b7f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b800:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b810:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b820:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b830:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003ba10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b840:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003ba20:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b850:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b860:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003b870:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003b880:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003b890:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q
 0003b8a0:·7569·6574·202d·7120·6b65·726e·656c·3b20··uiet·-q·kernel;·
 0003b8b0:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·-
 0003b8c0:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide"
 0003b8d0:·203b·2074·6865·6e0a·2020·2020·646e·6620···;·then.····dnf·
 0003b8e0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003b8f0:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 0003b900:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 0003b910:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 0003b920:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 0003b930:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 0003b940:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
 0003b950:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003b960:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003b970:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003b980:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003b990:·7267·6574·3d22·2369·646d·3733·3333·2220··rget="#idm7333"·
 0003b9a0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003b9b0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
Max diff block lines reached; 2652658/2689808 bytes (98.62%) of diff not shown.
208 KB
html2text {}
    
Offset 119, 19 lines modifiedOffset 119, 21 lines modified
119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
123 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79123 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
124 ············_\x8c_\x8i_\x8s············6.1.1124 ············_\x8c_\x8i_\x8s············6.1.1
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 131 package·install·aide
127 [[packages]] 
128 name·=·"aide" 
129 version·=·"*" 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
135 #·Remediation·is·applicable·only·in·certain·platforms137 #·Remediation·is·applicable·only·in·certain·platforms
136 if·rpm·--quiet·-q·kernel;·then138 if·rpm·--quiet·-q·kernel;·then
Offset 175, 14 lines modifiedOffset 177, 26 lines modified
175 ··-·PCI-DSSv4-11.5.2177 ··-·PCI-DSSv4-11.5.2
176 ··-·enable_strategy178 ··-·enable_strategy
177 ··-·low_complexity179 ··-·low_complexity
178 ··-·low_disruption180 ··-·low_disruption
179 ··-·medium_severity181 ··-·medium_severity
180 ··-·no_reboot_needed182 ··-·no_reboot_needed
181 ··-·package_aide_installed183 ··-·package_aide_installed
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 package·--add=aide
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 191 [[packages]]
 192 name·=·"aide"
 193 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
187 dnf·install·aide199 dnf·install·aide
Offset 194, 28 lines modifiedOffset 208, 14 lines modified
194 include·install_aide208 include·install_aide
  
195 class·install_aide·{209 class·install_aide·{
196 ··package·{·'aide':210 ··package·{·'aide':
197 ····ensure·=>·'installed',211 ····ensure·=>·'installed',
198 ··}212 ··}
199 }213 }
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
205 package·install·aide 
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
211 package·--add=aide 
212 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
213 Run·the·following·command·to·generate·a·new·database:215 Run·the·following·command·to·generate·a·new·database:
214 $·sudo·/usr/sbin/aide·--init216 $·sudo·/usr/sbin/aide·--init
215 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
216 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
217 To·initiate·a·manual·check,·run·the·following·command:219 To·initiate·a·manual·check,·run·the·following·command:
218 $·sudo·/usr/sbin/aide·--check220 $·sudo·/usr/sbin/aide·--check
Offset 350, 26 lines modifiedOffset 350, 26 lines modified
350 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.350 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.
351 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*351 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
352 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.352 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
353 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.353 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
354 Severity: ··medium354 Severity: ··medium
355 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot355 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
356 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28356 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
357 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
358 [[customizations.filesystem]] 
359 mountpoint·=·"/boot" 
360 size·=·1073741824 
361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8357 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
362 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low358 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
363 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high359 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
364 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false360 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
365 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable361 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
366 part·/boot362 part·/boot
 363 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 364 [[customizations.filesystem]]
 365 mountpoint·=·"/boot"
 366 size·=·1073741824
367 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*367 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
368 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.368 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
369 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.369 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
370 Severity: ··low370 Severity: ··low
371 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home371 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home
372 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8372 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
373 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02373 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 377, 92 lines modifiedOffset 377, 92 lines modified
377 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6377 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
378 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3378 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
379 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)379 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
380 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4380 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
381 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227381 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
382 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28382 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
383 ············_\x8c_\x8i_\x8s············1.1.2.3.1383 ············_\x8c_\x8i_\x8s············1.1.2.3.1
384 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
385 [[customizations.filesystem]] 
386 mountpoint·=·"/home" 
387 size·=·1073741824 
388 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8384 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 206083/212757 bytes (96.86%) of diff not shown.
2.88 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_high.html
    
Offset 15184, 278 lines modifiedOffset 15184, 278 lines modified
0003b4f0:·6765·743d·2223·6964·6d37·3333·3122·2074··get="#idm7331"·t0003b4f0:·6765·743d·2223·6964·6d37·3333·3122·2074··get="#idm7331"·t
0003b500:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b500:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b510:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b510:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b520:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b520:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b530:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b530:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b540:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b540:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b550:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b550:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b560:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003b570:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003b580:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b590:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b5a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b5b0:·646d·3733·3331·223e·3c70·7265·3e3c·636f··dm7331"><pre><co 
0003b5c0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003b5d0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003b5e0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003b5f0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b600:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b610:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b620:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b630:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b640:·6964·6d37·3333·3222·2074·6162·696e·6465··idm7332"·tabinde 
0003b650:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b660:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b670:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b680:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b690:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b6a0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b6b0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><0003b560:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003b6c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b570:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b6d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b580:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b6e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003b590:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003b6f0:·3333·3222·3e3c·7461·626c·6520·636c·6173··332"><table·clas0003b5a0:·3333·3122·3e3c·7461·626c·6520·636c·6173··331"><table·clas
0003b700:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b5b0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b710:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b5c0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b720:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b5d0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b730:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b5e0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b740:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b5f0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b750:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b760:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b770:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b780:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b790:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b7a0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b7b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b7c0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b7d0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b7e0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b7f0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b800:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b810:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b820:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003b830:·7420·2d71·206b·6572·6e65·6c3b·2074·6865··t·-q·kernel;·the 
0003b840:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003b850:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003b860:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins 
0003b870:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003b880:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003b890:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b8a0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b8b0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b8c0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b8d0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b8e0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b8f0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b900:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b910:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b920:·743d·2223·6964·6d37·3333·3322·2074·6162··t="#idm7333"·tab 
0003b930:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b940:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b950:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b960:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b970:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b980:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b990:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b9a0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b9b0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b9c0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b9d0:·643d·2269·646d·3733·3333·223e·3c74·6162··d="idm7333"><tab 
0003b9e0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b9f0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003ba00:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003ba10:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003ba20:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003ba30:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003ba40:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003ba50:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003ba60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b600:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003ba70:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003ba80:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b610:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b620:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003ba90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b630:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003baa0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003bab0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003bac0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bad0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003bae0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f 
0003baf0:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f 
0003bb00:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage 
0003bb10:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:. 
0003bb20:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003bb30:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5 
0003bb40:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC 
0003bb50:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.· 
0003bb60:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11. 
0003bb70:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s 
0003bb80:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_ 
0003bb90:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l 
0003bba0:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.·· 
0003bbb0:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit 
0003bbc0:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_ 
0003bbd0:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa 
0003bbe0:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe 
0003bbf0:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur 
0003bc00:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal 
0003bc10:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.· 
0003bc20:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.·· 
0003bc30:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present 
0003bc40:·0a20·2077·6865·6e3a·2027·226b·6572·6e65··.··when:·'"kerne 
0003bc50:·6c22·2069·6e20·616e·7369·626c·655f·6661··l"·in·ansible_fa 
0003bc60:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··0003b640:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b650:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b660:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b670:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b680:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003b690:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003b6a0:·636b·6167·6520·696e·7374·616c·6c20·6169··ckage·install·ai
Max diff block lines reached; 2763927/2800939 bytes (98.68%) of diff not shown.
216 KB
html2text {}
    
Offset 120, 19 lines modifiedOffset 120, 21 lines modified
120 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)120 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
125 ············_\x8c_\x8i_\x8s············6.1.1125 ············_\x8c_\x8i_\x8s············6.1.1
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 132 package·install·aide
128 [[packages]] 
129 name·=·"aide" 
130 version·=·"*" 
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
136 #·Remediation·is·applicable·only·in·certain·platforms138 #·Remediation·is·applicable·only·in·certain·platforms
137 if·rpm·--quiet·-q·kernel;·then139 if·rpm·--quiet·-q·kernel;·then
Offset 176, 14 lines modifiedOffset 178, 26 lines modified
176 ··-·PCI-DSSv4-11.5.2178 ··-·PCI-DSSv4-11.5.2
177 ··-·enable_strategy179 ··-·enable_strategy
178 ··-·low_complexity180 ··-·low_complexity
179 ··-·low_disruption181 ··-·low_disruption
180 ··-·medium_severity182 ··-·medium_severity
181 ··-·no_reboot_needed183 ··-·no_reboot_needed
182 ··-·package_aide_installed184 ··-·package_aide_installed
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 190 package·--add=aide
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 192 [[packages]]
 193 name·=·"aide"
 194 version·=·"*"
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
188 dnf·install·aide200 dnf·install·aide
Offset 195, 28 lines modifiedOffset 209, 14 lines modified
195 include·install_aide209 include·install_aide
  
196 class·install_aide·{210 class·install_aide·{
197 ··package·{·'aide':211 ··package·{·'aide':
198 ····ensure·=>·'installed',212 ····ensure·=>·'installed',
199 ··}213 ··}
200 }214 }
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
206 package·install·aide 
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
212 package·--add=aide 
213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
214 Run·the·following·command·to·generate·a·new·database:216 Run·the·following·command·to·generate·a·new·database:
215 $·sudo·/usr/sbin/aide·--init217 $·sudo·/usr/sbin/aide·--init
216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
218 To·initiate·a·manual·check,·run·the·following·command:220 To·initiate·a·manual·check,·run·the·following·command:
219 $·sudo·/usr/sbin/aide·--check221 $·sudo·/usr/sbin/aide·--check
Offset 844, 26 lines modifiedOffset 844, 26 lines modified
844 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.844 If·a·system·has·already·been·installed,·and·the·default·partitioning·scheme·was·used,·it·is·possible·but·nontrivial·to·modify·it·to·create·separate·logical·volumes·for·the·directories·listed·above.·The·Logical·Volume·Manager·(LVM)·makes·this·possible.
845 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*845 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
846 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.846 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
847 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.847 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
848 Severity: ··medium848 Severity: ··medium
849 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot849 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
850 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28850 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
851 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
852 [[customizations.filesystem]] 
853 mountpoint·=·"/boot" 
854 size·=·1073741824 
855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8851 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
856 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low852 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
857 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high853 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
858 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false854 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
859 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable855 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
860 part·/boot856 part·/boot
 857 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 858 [[customizations.filesystem]]
 859 mountpoint·=·"/boot"
 860 size·=·1073741824
861 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*861 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
862 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.862 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
863 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.863 Rationale:··Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
864 Severity: ··low864 Severity: ··low
865 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home865 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_home
866 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8866 ············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
867 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02867 ············_\x8c_\x8o_\x8b_\x8i_\x8t_\x85·········APO13.01,·DSS05.02
Offset 871, 92 lines modifiedOffset 871, 92 lines modified
871 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6871 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
872 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3872 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
873 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)873 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
874 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4874 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
875 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227875 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
876 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28876 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
877 ············_\x8c_\x8i_\x8s············1.1.2.3.1877 ············_\x8c_\x8i_\x8s············1.1.2.3.1
878 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
879 [[customizations.filesystem]] 
880 mountpoint·=·"/home" 
881 size·=·1073741824 
882 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8878 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 214571/221245 bytes (96.98%) of diff not shown.
1.6 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_intermediary.html
    
Offset 15174, 279 lines modifiedOffset 15174, 279 lines modified
0003b450:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b450:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b460:·6964·6d37·3333·3122·2074·6162·696e·6465··idm7331"·tabinde0003b460:·6964·6d37·3333·3122·2074·6162·696e·6465··idm7331"·tabinde
0003b470:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b470:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b480:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b480:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b490:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b490:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b4a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b4a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b4b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b4b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b4c0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003b4c0:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
0003b4d0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003b4e0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b4f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b500:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b510:·7073·6522·2069·643d·2269·646d·3733·3331··pse"·id="idm7331 
0003b520:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003b530:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003b540:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003b550:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003b560:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b570:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b580:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b590:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b5a0:·2d74·6172·6765·743d·2223·6964·6d37·3333··-target="#idm733 
0003b5b0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"· 
0003b5c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b5d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b5e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b5f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b600:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b610:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b620:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003b4d0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003b630:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003b4e0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003b640:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003b4f0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003b650:·2220·6964·3d22·6964·6d37·3333·3222·3e3c··"·id="idm7332"><0003b500:·2220·6964·3d22·6964·6d37·3333·3122·3e3c··"·id="idm7331"><
0003b660:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003b510:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003b670:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003b520:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003b680:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003b530:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003b690:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003b540:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003b6a0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003b550:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b6b0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003b560:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003b6c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b6d0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b6e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b6f0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b700:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b710:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b570:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b580:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003b720:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b730:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b740:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b750:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003b760:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003b770:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b780:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b790:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003b7a0:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if· 
0003b7b0:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003b7c0:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003b7d0:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
0003b7e0:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003b7f0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b800:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b810:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b820:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b830:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b840:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b850:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b860:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b870:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b880:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b890:·6d37·3333·3322·2074·6162·696e·6465·783d··m7333"·tabindex= 
0003b8a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b8b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b8c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b8d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b8e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b8f0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b900:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b910:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b920:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b930:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b940:·3733·3333·223e·3c74·6162·6c65·2063·6c61··7333"><table·cla 
0003b950:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b960:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b970:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b980:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b990:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b9a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b590:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b9b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b9c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b5a0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003b5b0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003b9d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b5c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b9e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t0003b5d0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003b5e0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003b5f0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b600:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003b610:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c
 0003b620:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b630:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b640:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b650:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b660:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b670:·6964·6d37·3333·3222·2074·6162·696e·6465··idm7332"·tabinde
 0003b680:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b690:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b6a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b6b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b6c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b6d0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003b6e0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003b6f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b700:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b710:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
 0003b720:·3333·3222·3e3c·7461·626c·6520·636c·6173··332"><table·clas
 0003b730:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b740:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b750:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b760:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b770:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b780:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b790:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b7a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b7b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b7c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b7d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b7e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b7f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b800:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
Max diff block lines reached; 1507651/1544801 bytes (97.60%) of diff not shown.
131 KB
html2text {}
    
Offset 135, 19 lines modifiedOffset 135, 21 lines modified
135 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)135 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
136 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3136 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5137 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
139 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79139 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
140 ············_\x8c_\x8i_\x8s············6.1.1140 ············_\x8c_\x8i_\x8s············6.1.1
141 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2141 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 147 package·install·aide
143 [[packages]] 
144 name·=·"aide" 
145 version·=·"*" 
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
151 #·Remediation·is·applicable·only·in·certain·platforms153 #·Remediation·is·applicable·only·in·certain·platforms
152 if·rpm·--quiet·-q·kernel;·then154 if·rpm·--quiet·-q·kernel;·then
Offset 191, 14 lines modifiedOffset 193, 26 lines modified
191 ··-·PCI-DSSv4-11.5.2193 ··-·PCI-DSSv4-11.5.2
192 ··-·enable_strategy194 ··-·enable_strategy
193 ··-·low_complexity195 ··-·low_complexity
194 ··-·low_disruption196 ··-·low_disruption
195 ··-·medium_severity197 ··-·medium_severity
196 ··-·no_reboot_needed198 ··-·no_reboot_needed
197 ··-·package_aide_installed199 ··-·package_aide_installed
 200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 205 package·--add=aide
 206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 207 [[packages]]
 208 name·=·"aide"
 209 version·=·"*"
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
203 dnf·install·aide215 dnf·install·aide
Offset 210, 28 lines modifiedOffset 224, 14 lines modified
210 include·install_aide224 include·install_aide
  
211 class·install_aide·{225 class·install_aide·{
212 ··package·{·'aide':226 ··package·{·'aide':
213 ····ensure·=>·'installed',227 ····ensure·=>·'installed',
214 ··}228 ··}
215 }229 }
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
221 package·install·aide 
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
227 package·--add=aide 
228 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*230 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
229 Run·the·following·command·to·generate·a·new·database:231 Run·the·following·command·to·generate·a·new·database:
230 $·sudo·/usr/sbin/aide·--init232 $·sudo·/usr/sbin/aide·--init
231 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the233 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
232 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these234 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
233 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their235 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
234 integrity.·The·newly-generated·database·can·be·installed·as·follows:236 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 386, 26 lines modifiedOffset 386, 26 lines modified
386 apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be386 apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be
387 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.387 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
388 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition388 Rationale:··The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition
389 ············should·be·restricted.389 ············should·be·restricted.
390 Severity: ··medium390 Severity: ··medium
391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_boot
392 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28392 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
394 [[customizations.filesystem]] 
395 mountpoint·=·"/boot" 
396 size·=·1073741824 
397 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
398 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low394 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
399 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high395 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
400 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false396 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
401 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable397 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
402 part·/boot398 part·/boot
 399 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 400 [[customizations.filesystem]]
 401 mountpoint·=·"/boot"
 402 size·=·1073741824
403 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*403 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
404 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at404 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at
405 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such405 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such
406 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the406 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
407 mountpoint·can·instead·be·configured·later.407 mountpoint·can·instead·be·configured·later.
408 ············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more408 ············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more
409 Rationale:··restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill409 Rationale:··restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill
Offset 419, 102 lines modifiedOffset 419, 102 lines modified
419 ···························7.6419 ···························7.6
420 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3420 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
421 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)421 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
422 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4422 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
423 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227423 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
424 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28424 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
425 ············_\x8c_\x8i_\x8s············1.1.2.3.1425 ············_\x8c_\x8i_\x8s············1.1.2.3.1
426 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
427 [[customizations.filesystem]] 
428 mountpoint·=·"/home" 
429 size·=·1073741824 
430 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8426 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 128109/133780 bytes (95.76%) of diff not shown.
215 KB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-anssi_bp28_minimal.html
    
Offset 14855, 295 lines modifiedOffset 14855, 295 lines modified
0003a060:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003a060:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003a070:·2223·6964·6d31·3035·3432·2220·7461·6269··"#idm10542"·tabi0003a070:·2223·6964·6d31·3035·3432·2220·7461·6269··"#idm10542"·tabi
0003a080:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003a080:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003a090:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003a090:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003a0a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003a0a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003a0b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003a0b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003a0c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003a0c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003a0d0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003a0d0:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
 0003a0e0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003a0f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003a100:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003a110:·7073·6522·2069·643d·2269·646d·3130·3534··pse"·id="idm1054
 0003a120:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 0003a130:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003a140:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003a150:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003a160:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003a170:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003a180:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003a190:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003a0e0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003a0f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003a100:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003a110:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003a120:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0003a130:·3035·3432·223e·3c70·7265·3e3c·636f·6465··0542"><pre><code 
0003a140:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003a150:·616d·6520·3d20·2264·6e66·2d61·7574·6f6d··ame·=·"dnf-autom 
0003a160:·6174·6963·220a·7665·7273·696f·6e20·3d20··atic".version·=· 
0003a170:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
0003a180:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003a190:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003a1a0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003a1b0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003a1c0:·7267·6574·3d22·2369·646d·3130·3534·3322··rget="#idm10543" 
0003a1d0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003a1e0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003a1f0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003a200:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003a210:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003a220:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003a230:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003a240:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003a250:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003a260:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003a270:·6964·3d22·6964·6d31·3035·3433·223e·3c74··id="idm10543"><t 
0003a280:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003a290:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003a2a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003a2b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003a2c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003a2d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003a1a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003a2e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003a1b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003a2f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003a300:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003a310:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003a320:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003a330:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003a340:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003a350:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003a360:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003a370:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003a380:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003a390:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003a3a0:·6e20·706c·6174·666f·726d·730a·6966·2021··n·platforms.if·! 
0003a3b0:·2028·207b·2072·706d·202d·2d71·7569·6574···(·{·rpm·--quiet 
0003a3c0:·202d·7120·6b65·726e·656c·203b·7d20·2661···-q·kernel·;}·&a 
0003a3d0:·6d70·3b26·616d·703b·207b·2072·706d·202d··mp;&amp;·{·rpm·- 
0003a3e0:·2d71·7569·6574·202d·7120·7270·6d2d·6f73··-quiet·-q·rpm-os 
0003a3f0:·7472·6565·203b·7d20·2661·6d70·3b26·616d··tree·;}·&amp;&am 
0003a400:·703b·207b·2072·706d·202d·2d71·7569·6574··p;·{·rpm·--quiet 
0003a410:·202d·7120·626f·6f74·6320·3b7d·2026·616d···-q·bootc·;}·&am 
0003a420:·703b·2661·6d70·3b20·7b20·2120·7270·6d20··p;&amp;·{·!·rpm· 
0003a430:·2d2d·7175·6965·7420·2d71·206f·7065·6e73··--quiet·-q·opens 
0003a440:·6869·6674·2d6b·7562·656c·6574·203b·7d20··hift-kubelet·;}· 
0003a450:·293b·2074·6865·6e0a·0a69·6620·2120·7270··);·then..if·!·rp 
0003a460:·6d20·2d71·202d·2d71·7569·6574·2022·646e··m·-q·--quiet·"dn 
0003a470:·662d·6175·746f·6d61·7469·6322·203b·2074··f-automatic"·;·t 
0003a480:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
0003a490:·616c·6c20·2d79·2022·646e·662d·6175·746f··all·-y·"dnf-auto 
0003a4a0:·6d61·7469·6322·0a66·690a·0a65·6c73·650a··matic".fi..else. 
0003a4b0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
0003a4c0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
0003a4d0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
0003a4e0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
0003a4f0:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
0003a500:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003a510:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003a520:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003a530:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003a540:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
0003a550:·3035·3434·2220·7461·6269·6e64·6578·3d22··0544"·tabindex=" 
0003a560:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003a570:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003a580:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003a590:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003a5a0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003a5b0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003a5c0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003a5d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003a5e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003a5f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1 
0003a600:·3035·3434·223e·3c74·6162·6c65·2063·6c61··0544"><table·cla 
0003a610:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003a620:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003a630:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003a640:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003a650:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003a660:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003a670:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003a680:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003a1c0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003a690:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003a6a0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003a6b0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003a6c0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003a6d0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003a6e0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003a6f0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
0003a700:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
0003a710:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
0003a720:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
0003a730:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
0003a740:·6f0a·2020·7461·6773·3a0a·2020·2d20·656e··o.··tags:.··-·en 
0003a750:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.·· 
0003a760:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity 
0003a770:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt 
0003a780:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s 
Max diff block lines reached; 163256/202614 bytes (80.57%) of diff not shown.
17.0 KB
html2text {}
    
Offset 101, 19 lines modifiedOffset 101, 21 lines modified
101 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade101 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
102 ············suitable·for·automatic,·regular·execution.102 ············suitable·for·automatic,·regular·execution.
103 Severity: ··medium103 Severity: ··medium
104 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed104 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
105 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2105 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
106 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080106 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
107 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61107 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 113 package·install·dnf-automatic
109 [[packages]] 
110 name·=·"dnf-automatic" 
111 version·=·"*" 
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
117 #·Remediation·is·applicable·only·in·certain·platforms119 #·Remediation·is·applicable·only·in·certain·platforms
118 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-120 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 153, 14 lines modifiedOffset 155, 26 lines modified
153 ··tags:155 ··tags:
154 ··-·enable_strategy156 ··-·enable_strategy
155 ··-·low_complexity157 ··-·low_complexity
156 ··-·low_disruption158 ··-·low_disruption
157 ··-·medium_severity159 ··-·medium_severity
158 ··-·no_reboot_needed160 ··-·no_reboot_needed
159 ··-·package_dnf-automatic_installed161 ··-·package_dnf-automatic_installed
 162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 167 package·--add=dnf-automatic
 168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 169 [[packages]]
 170 name·=·"dnf-automatic"
 171 version·=·"*"
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
165 dnf·install·dnf-automatic177 dnf·install·dnf-automatic
Offset 172, 28 lines modifiedOffset 186, 14 lines modified
172 include·install_dnf-automatic186 include·install_dnf-automatic
  
173 class·install_dnf-automatic·{187 class·install_dnf-automatic·{
174 ··package·{·'dnf-automatic':188 ··package·{·'dnf-automatic':
175 ····ensure·=>·'installed',189 ····ensure·=>·'installed',
176 ··}190 ··}
177 }191 }
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 package·install·dnf-automatic 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·--add=dnf-automatic 
190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
191 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed193 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
192 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/194 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
193 automatic.conf.195 automatic.conf.
194 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation196 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
195 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and197 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
196 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in198 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 9273, 14 lines modifiedOffset 9273, 21 lines modified
9273 If·the·system·does·not·need·to·act·as·a·DHCP·server,·the·kea·package·can·be·uninstalled.9273 If·the·system·does·not·need·to·act·as·a·DHCP·server,·the·kea·package·can·be·uninstalled.
9274 Rationale:··Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally9274 Rationale:··Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally
9275 ············reactivated·and·disrupt·network·operation.9275 ············reactivated·and·disrupt·network·operation.
9276 Severity: ··medium9276 Severity: ··medium
9277 Rule·ID:····xccdf_org.ssgproject.content_rule_package_kea_removed9277 Rule·ID:····xccdf_org.ssgproject.content_rule_package_kea_removed
9278 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R629278 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R62
9279 ············_\x8c_\x8i_\x8s···2.1.39279 ············_\x8c_\x8i_\x8s···2.1.3
 9280 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 9281 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9282 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9283 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9284 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 9285 package·remove·kea
9280 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89286 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9281 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9287 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9282 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9288 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9283 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9289 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9284 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable9290 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
9285 #·CAUTION:·This·remediation·script·will·remove·kea9291 #·CAUTION:·This·remediation·script·will·remove·kea
Offset 9304, 14 lines modifiedOffset 9311, 21 lines modified
9304 ··tags:9311 ··tags:
9305 ··-·disable_strategy9312 ··-·disable_strategy
9306 ··-·low_complexity9313 ··-·low_complexity
9307 ··-·low_disruption9314 ··-·low_disruption
9308 ··-·medium_severity9315 ··-·medium_severity
9309 ··-·no_reboot_needed9316 ··-·no_reboot_needed
9310 ··-·package_kea_removed9317 ··-·package_kea_removed
 9318 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 9319 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9320 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9321 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9322 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 9323 package·--remove=kea
9311 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89324 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9312 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9325 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9313 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9326 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9314 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9327 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9315 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable9328 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
9316 dnf·remove·kea9329 dnf·remove·kea
Offset 9323, 28 lines modifiedOffset 9337, 14 lines modified
9323 include·remove_kea9337 include·remove_kea
  
Max diff block lines reached; 12258/17366 bytes (70.59%) of diff not shown.
4.26 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis.html
    
Offset 15225, 279 lines modifiedOffset 15225, 279 lines modified
0003b780:·2d74·6172·6765·743d·2223·6964·6d37·3333··-target="#idm7330003b780:·2d74·6172·6765·743d·2223·6964·6d37·3333··-target="#idm733
0003b790:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·0003b790:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
0003b7a0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b7a0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b7b0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b7b0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b7c0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b7c0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b7d0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b7d0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b7e0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b7e0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b7f0:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003b800:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003b810:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b820:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b830:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b840:·643d·2269·646d·3733·3331·223e·3c70·7265··d="idm7331"><pre 
0003b850:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003b860:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003b870:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003b880:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b890:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b8a0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b8b0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b8c0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b8d0:·743d·2223·6964·6d37·3333·3222·2074·6162··t="#idm7332"·tab 
0003b8e0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b8f0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b900:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b910:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b920:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b930:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003b940:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<0003b7f0:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...<
0003b950:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003b800:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b960:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003b810:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b970:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003b820:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b980:·6964·6d37·3333·3222·3e3c·7461·626c·6520··idm7332"><table·0003b830:·6964·6d37·3333·3122·3e3c·7461·626c·6520··idm7331"><table·
0003b990:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003b840:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b9a0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003b850:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b9b0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b860:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b9c0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b870:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003b9d0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b880:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003b9e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b890:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003b9f0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003b8a0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003ba00:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b8b0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003ba10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b8c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003ba20:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b8d0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003ba30:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b8e0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003ba40:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003b8f0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003ba50:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003b900:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003ba60:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003b910:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003ba70:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b920:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b930:·3e0a·7061·636b·6167·6520·696e·7374·616c··>.package·instal
0003ba80:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003ba90:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003baa0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003bab0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·-- 
0003bac0:·7175·6965·7420·2d71·206b·6572·6e65·6c3b··quiet·-q·kernel; 
0003bad0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003bae0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
0003baf0:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf 
0003bb00:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003bb10:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
0003bb20:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003bb30:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003bb40:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003bb50:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003bb60:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr0003b940:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></
0003bb70:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003b950:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003bb80:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003b960:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003bb90:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003b970:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003bba0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003b980:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003bbb0:·6172·6765·743d·2223·6964·6d37·3333·3322··arget="#idm7333"0003b990:·2d74·6172·6765·743d·2223·6964·6d37·3333··-target="#idm733
0003bbc0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b9a0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
0003bbd0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b9b0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003bbe0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b9c0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003bbf0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b9d0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003bc00:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b9e0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003bc10:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b9f0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003ba00:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003ba10:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003ba20:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003ba30:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003ba40:·2220·6964·3d22·6964·6d37·3333·3222·3e3c··"·id="idm7332"><
 0003ba50:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003ba60:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003bc20:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003bc30:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003bc40:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003bc50:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003bc60:·6522·2069·643d·2269·646d·3733·3333·223e··e"·id="idm7333"> 
0003bc70:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003bc80:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003bc90:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003bca0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003ba70:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003bcb0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003bcc0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003bcd0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003bce0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003bcf0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bd00:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003bd10:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals0003ba80:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003ba90:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003baa0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003bab0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003bac0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003bad0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bae0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003baf0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003bb00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003bb10:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003bb20:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003bb30:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003bb40:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia
 0003bb50:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab
 0003bb60:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa
 0003bb70:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if·
 0003bb80:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k
 0003bb90:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if·
 0003bba0:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003bbb0:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 0003bbc0:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·-
 0003bbd0:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 0003bbe0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003bbf0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003bc00:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003bc10:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003bc20:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 0003bc30:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003bc40:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003bc50:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
Max diff block lines reached; 4073200/4110350 bytes (99.10%) of diff not shown.
350 KB
html2text {}
    
Offset 126, 19 lines modifiedOffset 126, 21 lines modified
126 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)126 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
127 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3127 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
131 ············_\x8c_\x8i_\x8s············6.1.1131 ············_\x8c_\x8i_\x8s············6.1.1
132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 138 package·install·aide
134 [[packages]] 
135 name·=·"aide" 
136 version·=·"*" 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 #·Remediation·is·applicable·only·in·certain·platforms144 #·Remediation·is·applicable·only·in·certain·platforms
143 if·rpm·--quiet·-q·kernel;·then145 if·rpm·--quiet·-q·kernel;·then
Offset 182, 14 lines modifiedOffset 184, 26 lines modified
182 ··-·PCI-DSSv4-11.5.2184 ··-·PCI-DSSv4-11.5.2
183 ··-·enable_strategy185 ··-·enable_strategy
184 ··-·low_complexity186 ··-·low_complexity
185 ··-·low_disruption187 ··-·low_disruption
186 ··-·medium_severity188 ··-·medium_severity
187 ··-·no_reboot_needed189 ··-·no_reboot_needed
188 ··-·package_aide_installed190 ··-·package_aide_installed
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 196 package·--add=aide
 197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 198 [[packages]]
 199 name·=·"aide"
 200 version·=·"*"
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
194 dnf·install·aide206 dnf·install·aide
Offset 201, 28 lines modifiedOffset 215, 14 lines modified
201 include·install_aide215 include·install_aide
  
202 class·install_aide·{216 class·install_aide·{
203 ··package·{·'aide':217 ··package·{·'aide':
204 ····ensure·=>·'installed',218 ····ensure·=>·'installed',
205 ··}219 ··}
206 }220 }
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
212 package·install·aide 
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
218 package·--add=aide 
219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
220 Run·the·following·command·to·generate·a·new·database:222 Run·the·following·command·to·generate·a·new·database:
221 $·sudo·/usr/sbin/aide·--init223 $·sudo·/usr/sbin/aide·--init
222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:224 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz225 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
224 To·initiate·a·manual·check,·run·the·following·command:226 To·initiate·a·manual·check,·run·the·following·command:
225 $·sudo·/usr/sbin/aide·--check227 $·sudo·/usr/sbin/aide·--check
Offset 740, 14 lines modifiedOffset 740, 39 lines modified
740 »       echo·"to·see·what·package·to·(re)install"·>&2740 »       echo·"to·see·what·package·to·(re)install"·>&2
  
741 »       false··#·end·with·an·error·code741 »       false··#·end·with·an·error·code
742 elif·test·"$rc"·!=·0;·then742 elif·test·"$rc"·!=·0;·then
743 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2743 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
744 »       false··#·end·with·an·error·code744 »       false··#·end·with·an·error·code
745 fi745 fi
 746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 747 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 748 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 749 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 750 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 751 ---
 752 apiVersion:·machineconfiguration.openshift.io/v1
 753 kind:·MachineConfig
 754 spec:
 755 ··config:
 756 ····ignition:
 757 ······version:·3.1.0
 758 ····systemd:
 759 ······units:
 760 ········-·name:·configure-crypto-policy.service
 761 ··········enabled:·true
 762 ··········contents:·|
 763 ············[Unit]
 764 ············Before=kubelet.service
 765 ············[Service]
 766 ············Type=oneshot
 767 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 768 ············RemainAfterExit=yes
 769 ············[Install]
 770 ············WantedBy=multi-user.target
746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8771 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
747 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low772 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
748 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low773 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
749 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false774 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
750 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict775 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
751 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable776 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
752 ··set_fact:777 ··set_fact:
Offset 792, 39 lines modifiedOffset 817, 14 lines modified
792 ··-·PCI-DSSv4-2.2.7817 ··-·PCI-DSSv4-2.2.7
793 ··-·configure_crypto_policy818 ··-·configure_crypto_policy
794 ··-·high_severity819 ··-·high_severity
795 ··-·low_complexity820 ··-·low_complexity
796 ··-·low_disruption821 ··-·low_disruption
797 ··-·no_reboot_needed822 ··-·no_reboot_needed
Max diff block lines reached; 353136/358015 bytes (98.64%) of diff not shown.
2.56 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis_server_l1.html
    
Offset 15187, 278 lines modifiedOffset 15187, 278 lines modified
0003b520:·6574·3d22·2369·646d·3733·3331·2220·7461··et="#idm7331"·ta0003b520:·6574·3d22·2369·646d·3733·3331·2220·7461··et="#idm7331"·ta
0003b530:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b530:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b540:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b540:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b550:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b550:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b560:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b560:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b570:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b570:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b580:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b580:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b590:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003b5a0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003b5b0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b5c0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b5d0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b5e0:·6d37·3333·3122·3e3c·7072·653e·3c63·6f64··m7331"><pre><cod 
0003b5f0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003b600:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003b610:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003b620:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b630:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b640:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b650:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b660:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b670:·646d·3733·3332·2220·7461·6269·6e64·6578··dm7332"·tabindex 
0003b680:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b690:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b6a0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b6b0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b6c0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b6d0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b6e0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b0003b590:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
0003b6f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003b5a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b700:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003b5b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b710:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm730003b5c0:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73
0003b720:·3332·223e·3c74·6162·6c65·2063·6c61·7373··32"><table·class0003b5d0:·3331·223e·3c74·6162·6c65·2063·6c61·7373··31"><table·class
0003b730:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003b5e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b740:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003b5f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b750:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003b600:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b760:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003b610:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b770:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003b620:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b780:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b630:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b790:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b640:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b7a0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003b650:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b7b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b660:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b7c0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003b670:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b7d0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b680:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003b7e0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003b690:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003b7f0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003b6a0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b800:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003b6b0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b810:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re0003b6c0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003b6d0:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
0003b820:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b830:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b840:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b850:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
0003b860:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
0003b870:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b880:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b890:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
0003b8a0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b8b0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b8c0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b8d0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b8e0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b8f0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b900:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003b6e0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
0003b910:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003b6f0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003b920:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003b700:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003b930:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003b710:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003b940:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b720:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003b950:·3d22·2369·646d·3733·3333·2220·7461·6269··="#idm7333"·tabi0003b730:·6574·3d22·2369·646d·3733·3332·2220·7461··et="#idm7332"·ta
0003b960:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b740:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b970:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b750:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b980:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b760:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b990:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b770:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b9a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b780:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b9b0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b790:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b9c0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b9d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b9e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b9f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003ba00:·3d22·6964·6d37·3333·3322·3e3c·7461·626c··="idm7333"><tabl 
0003ba10:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003ba20:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003ba30:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003ba40:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003ba50:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003ba60:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003ba70:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003ba80:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b7a0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003b7b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b7c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b7d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b7e0:·2269·646d·3733·3332·223e·3c74·6162·6c65··"idm7332"><table
 0003b7f0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003b800:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003b810:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003b820:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b830:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003b840:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b850:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b860:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003b870:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b880:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003b890:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003b8a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003b8b0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003ba90:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b8c0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003baa0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003bab0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003bac0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003bad0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003bae0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003baf0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bb00:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
0003bb10:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
0003bb20:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
0003bb30:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
0003bb40:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
0003bb50:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003bb60:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003bb70:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI 
0003bb80:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.·· 
0003bb90:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5 
0003bba0:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st 
0003bbb0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c 
0003bbc0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo 
0003bbd0:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··- 
0003bbe0:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity 
Max diff block lines reached; 2401249/2438261 bytes (98.48%) of diff not shown.
239 KB
html2text {}
    
Offset 120, 19 lines modifiedOffset 120, 21 lines modified
120 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)120 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
125 ············_\x8c_\x8i_\x8s············6.1.1125 ············_\x8c_\x8i_\x8s············6.1.1
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 132 package·install·aide
128 [[packages]] 
129 name·=·"aide" 
130 version·=·"*" 
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
136 #·Remediation·is·applicable·only·in·certain·platforms138 #·Remediation·is·applicable·only·in·certain·platforms
137 if·rpm·--quiet·-q·kernel;·then139 if·rpm·--quiet·-q·kernel;·then
Offset 176, 14 lines modifiedOffset 178, 26 lines modified
176 ··-·PCI-DSSv4-11.5.2178 ··-·PCI-DSSv4-11.5.2
177 ··-·enable_strategy179 ··-·enable_strategy
178 ··-·low_complexity180 ··-·low_complexity
179 ··-·low_disruption181 ··-·low_disruption
180 ··-·medium_severity182 ··-·medium_severity
181 ··-·no_reboot_needed183 ··-·no_reboot_needed
182 ··-·package_aide_installed184 ··-·package_aide_installed
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 190 package·--add=aide
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 192 [[packages]]
 193 name·=·"aide"
 194 version·=·"*"
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
188 dnf·install·aide200 dnf·install·aide
Offset 195, 28 lines modifiedOffset 209, 14 lines modified
195 include·install_aide209 include·install_aide
  
196 class·install_aide·{210 class·install_aide·{
197 ··package·{·'aide':211 ··package·{·'aide':
198 ····ensure·=>·'installed',212 ····ensure·=>·'installed',
199 ··}213 ··}
200 }214 }
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
206 package·install·aide 
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
212 package·--add=aide 
213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
214 Run·the·following·command·to·generate·a·new·database:216 Run·the·following·command·to·generate·a·new·database:
215 $·sudo·/usr/sbin/aide·--init217 $·sudo·/usr/sbin/aide·--init
216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
218 To·initiate·a·manual·check,·run·the·following·command:220 To·initiate·a·manual·check,·run·the·following·command:
219 $·sudo·/usr/sbin/aide·--check221 $·sudo·/usr/sbin/aide·--check
Offset 734, 14 lines modifiedOffset 734, 39 lines modified
734 »       echo·"to·see·what·package·to·(re)install"·>&2734 »       echo·"to·see·what·package·to·(re)install"·>&2
  
735 »       false··#·end·with·an·error·code735 »       false··#·end·with·an·error·code
736 elif·test·"$rc"·!=·0;·then736 elif·test·"$rc"·!=·0;·then
737 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2737 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
738 »       false··#·end·with·an·error·code738 »       false··#·end·with·an·error·code
739 fi739 fi
 740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 745 ---
 746 apiVersion:·machineconfiguration.openshift.io/v1
 747 kind:·MachineConfig
 748 spec:
 749 ··config:
 750 ····ignition:
 751 ······version:·3.1.0
 752 ····systemd:
 753 ······units:
 754 ········-·name:·configure-crypto-policy.service
 755 ··········enabled:·true
 756 ··········contents:·|
 757 ············[Unit]
 758 ············Before=kubelet.service
 759 ············[Service]
 760 ············Type=oneshot
 761 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 762 ············RemainAfterExit=yes
 763 ············[Install]
 764 ············WantedBy=multi-user.target
740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8765 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low766 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low767 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false768 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict769 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
745 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable770 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
746 ··set_fact:771 ··set_fact:
Offset 786, 39 lines modifiedOffset 811, 14 lines modified
786 ··-·PCI-DSSv4-2.2.7811 ··-·PCI-DSSv4-2.2.7
787 ··-·configure_crypto_policy812 ··-·configure_crypto_policy
788 ··-·high_severity813 ··-·high_severity
789 ··-·low_complexity814 ··-·low_complexity
790 ··-·low_disruption815 ··-·low_disruption
791 ··-·no_reboot_needed816 ··-·no_reboot_needed
Max diff block lines reached; 240119/244998 bytes (98.01%) of diff not shown.
2.25 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis_workstation_l1.html
    
Offset 15178, 278 lines modifiedOffset 15178, 278 lines modified
0003b490:·6765·743d·2223·6964·6d37·3333·3122·2074··get="#idm7331"·t0003b490:·6765·743d·2223·6964·6d37·3333·3122·2074··get="#idm7331"·t
0003b4a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b4a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b4b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b4b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b4c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b4c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b4d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b4d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b4e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b4e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b4f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b4f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b500:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003b510:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003b520:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b530:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b540:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b550:·646d·3733·3331·223e·3c70·7265·3e3c·636f··dm7331"><pre><co 
0003b560:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003b570:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003b580:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003b590:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b5a0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b5b0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b5c0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b5d0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b5e0:·6964·6d37·3333·3222·2074·6162·696e·6465··idm7332"·tabinde 
0003b5f0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b600:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b610:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b620:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b630:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b640:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b650:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><0003b500:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003b660:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b510:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b670:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b520:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b680:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003b530:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003b690:·3333·3222·3e3c·7461·626c·6520·636c·6173··332"><table·clas0003b540:·3333·3122·3e3c·7461·626c·6520·636c·6173··331"><table·clas
0003b6a0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b550:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b6b0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b560:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b6c0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b570:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b6d0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b580:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b6e0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b590:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b6f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b700:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b710:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b720:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b730:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b740:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b750:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b760:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b770:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b780:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b790:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b7a0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b7b0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b7c0:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003b7d0:·7420·2d71·206b·6572·6e65·6c3b·2074·6865··t·-q·kernel;·the 
0003b7e0:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003b7f0:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003b800:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins 
0003b810:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003b820:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003b830:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b840:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b850:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b860:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b870:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b880:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b890:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b8a0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b8b0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b8c0:·743d·2223·6964·6d37·3333·3322·2074·6162··t="#idm7333"·tab 
0003b8d0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b8e0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b8f0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b900:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b910:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b920:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b930:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b940:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b950:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b960:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b970:·643d·2269·646d·3733·3333·223e·3c74·6162··d="idm7333"><tab 
0003b980:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b990:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b9a0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b9b0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b9c0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b9d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b9e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b9f0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003ba00:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b5a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003ba10:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003ba20:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b5b0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b5c0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003ba30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b5d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003ba40:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003ba50:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003ba60:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003ba70:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003ba80:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f 
0003ba90:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f 
0003baa0:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage 
0003bab0:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:. 
0003bac0:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003bad0:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5 
0003bae0:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC 
0003baf0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.· 
0003bb00:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11. 
0003bb10:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s 
0003bb20:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_ 
0003bb30:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l 
0003bb40:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.·· 
0003bb50:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit 
0003bb60:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_ 
0003bb70:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa 
0003bb80:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe 
0003bb90:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur 
0003bba0:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal 
0003bbb0:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.· 
0003bbc0:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.·· 
0003bbd0:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present 
0003bbe0:·0a20·2077·6865·6e3a·2027·226b·6572·6e65··.··when:·'"kerne 
0003bbf0:·6c22·2069·6e20·616e·7369·626c·655f·6661··l"·in·ansible_fa 
0003bc00:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.··0003b5e0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b5f0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b600:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b610:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b620:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003b630:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003b640:·636b·6167·6520·696e·7374·616c·6c20·6169··ckage·install·ai
Max diff block lines reached; 2103888/2140900 bytes (98.27%) of diff not shown.
212 KB
html2text {}
    
Offset 118, 19 lines modifiedOffset 118, 21 lines modified
118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
123 ············_\x8c_\x8i_\x8s············6.1.1123 ············_\x8c_\x8i_\x8s············6.1.1
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 130 package·install·aide
126 [[packages]] 
127 name·=·"aide" 
128 version·=·"*" 
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
134 #·Remediation·is·applicable·only·in·certain·platforms136 #·Remediation·is·applicable·only·in·certain·platforms
135 if·rpm·--quiet·-q·kernel;·then137 if·rpm·--quiet·-q·kernel;·then
Offset 174, 14 lines modifiedOffset 176, 26 lines modified
174 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
175 ··-·enable_strategy177 ··-·enable_strategy
176 ··-·low_complexity178 ··-·low_complexity
177 ··-·low_disruption179 ··-·low_disruption
178 ··-·medium_severity180 ··-·medium_severity
179 ··-·no_reboot_needed181 ··-·no_reboot_needed
180 ··-·package_aide_installed182 ··-·package_aide_installed
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 188 package·--add=aide
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 190 [[packages]]
 191 name·=·"aide"
 192 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
186 dnf·install·aide198 dnf·install·aide
Offset 193, 28 lines modifiedOffset 207, 14 lines modified
193 include·install_aide207 include·install_aide
  
194 class·install_aide·{208 class·install_aide·{
195 ··package·{·'aide':209 ··package·{·'aide':
196 ····ensure·=>·'installed',210 ····ensure·=>·'installed',
197 ··}211 ··}
198 }212 }
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
204 package·install·aide 
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
210 package·--add=aide 
211 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
212 Run·the·following·command·to·generate·a·new·database:214 Run·the·following·command·to·generate·a·new·database:
213 $·sudo·/usr/sbin/aide·--init215 $·sudo·/usr/sbin/aide·--init
214 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
215 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
216 To·initiate·a·manual·check,·run·the·following·command:218 To·initiate·a·manual·check,·run·the·following·command:
217 $·sudo·/usr/sbin/aide·--check219 $·sudo·/usr/sbin/aide·--check
Offset 732, 14 lines modifiedOffset 732, 39 lines modified
732 »       echo·"to·see·what·package·to·(re)install"·>&2732 »       echo·"to·see·what·package·to·(re)install"·>&2
  
733 »       false··#·end·with·an·error·code733 »       false··#·end·with·an·error·code
734 elif·test·"$rc"·!=·0;·then734 elif·test·"$rc"·!=·0;·then
735 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2735 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
736 »       false··#·end·with·an·error·code736 »       false··#·end·with·an·error·code
737 fi737 fi
 738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 739 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 740 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 741 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 742 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 743 ---
 744 apiVersion:·machineconfiguration.openshift.io/v1
 745 kind:·MachineConfig
 746 spec:
 747 ··config:
 748 ····ignition:
 749 ······version:·3.1.0
 750 ····systemd:
 751 ······units:
 752 ········-·name:·configure-crypto-policy.service
 753 ··········enabled:·true
 754 ··········contents:·|
 755 ············[Unit]
 756 ············Before=kubelet.service
 757 ············[Service]
 758 ············Type=oneshot
 759 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 760 ············RemainAfterExit=yes
 761 ············[Install]
 762 ············WantedBy=multi-user.target
738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
739 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low764 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
740 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low765 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
741 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false766 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
742 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict767 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
743 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable768 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
744 ··set_fact:769 ··set_fact:
Offset 784, 39 lines modifiedOffset 809, 14 lines modified
784 ··-·PCI-DSSv4-2.2.7809 ··-·PCI-DSSv4-2.2.7
785 ··-·configure_crypto_policy810 ··-·configure_crypto_policy
786 ··-·high_severity811 ··-·high_severity
787 ··-·low_complexity812 ··-·low_complexity
788 ··-·low_disruption813 ··-·low_disruption
789 ··-·no_reboot_needed814 ··-·no_reboot_needed
Max diff block lines reached; 212591/217470 bytes (97.76%) of diff not shown.
4.13 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-cis_workstation_l2.html
    
Offset 15216, 279 lines modifiedOffset 15216, 279 lines modified
0003b6f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b6f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b700:·646d·3733·3331·2220·7461·6269·6e64·6578··dm7331"·tabindex0003b700:·646d·3733·3331·2220·7461·6269·6e64·6578··dm7331"·tabindex
0003b710:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b710:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b720:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b720:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b730:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b730:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b740:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b740:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b750:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b750:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b760:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b760:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
0003b770:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b780:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b790:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b7a0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b7b0:·7365·2220·6964·3d22·6964·6d37·3333·3122··se"·id="idm7331" 
0003b7c0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
0003b7d0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b7e0:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b7f0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003b800:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b810:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b820:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b830:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b840:·7461·7267·6574·3d22·2369·646d·3733·3332··target="#idm7332 
0003b850:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b860:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b870:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b880:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b890:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b8a0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b8b0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b8c0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b770:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b8d0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b780:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b8e0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b790:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b8f0:·2069·643d·2269·646d·3733·3332·223e·3c74···id="idm7332"><t0003b7a0:·2069·643d·2269·646d·3733·3331·223e·3c74···id="idm7331"><t
0003b900:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b7b0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b910:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b7c0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b920:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b7d0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b930:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b7e0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b940:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b7f0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b950:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003b800:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003b960:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b810:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b970:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003b820:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b980:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b830:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b990:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b840:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b9a0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b850:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b9b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b860:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b9c0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b870:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b9d0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b880:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003b9e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b890:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b8a0:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i
 0003b8b0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co
0003b9f0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003ba00:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003ba10:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003ba20:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r 
0003ba30:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003ba40:·726e·656c·3b20·7468·656e·0a0a·6966·2021··rnel;·then..if·! 
0003ba50:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003ba60:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003ba70:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y 
0003ba80:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003ba90:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003baa0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003bab0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003bac0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003bad0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003bae0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003b8c0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003baf0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003b8d0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003bb00:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003b8e0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003bb10:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003b8f0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003bb20:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b900:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003bb30:·3733·3333·2220·7461·6269·6e64·6578·3d22··7333"·tabindex="0003b910:·646d·3733·3332·2220·7461·6269·6e64·6578··dm7332"·tabindex
0003bb40:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b920:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003bb50:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b930:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003bb60:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b940:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003bb70:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b950:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003bb80:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b960:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003bb90:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·0003b970:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003bba0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003b980:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003b990:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b9a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b9b0:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73
 0003b9c0:·3332·223e·3c74·6162·6c65·2063·6c61·7373··32"><table·class
 0003b9d0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003bbb0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003bbc0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003bbd0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003bbe0:·3333·3322·3e3c·7461·626c·6520·636c·6173··333"><table·clas 
0003bbf0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003bc00:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003bc10:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b9e0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003bc20:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003bc30:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003bc40:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003bc50:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003bc60:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003b9f0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003ba00:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003ba10:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003ba20:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003ba30:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003ba40:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003ba50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003ba60:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003ba70:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003ba80:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003ba90:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003bc70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003baa0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003bc80:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003bab0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
 0003bac0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003bad0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003bae0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003baf0:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet
 0003bb00:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then
 0003bb10:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003bb20:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003bb30:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst
 0003bb40:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003bb50:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003bb60:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003bb70:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003bb80:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003bb90:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 0003bba0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003bbb0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003bbc0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003bbd0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003bbe0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003bbf0:·3d22·2369·646d·3733·3333·2220·7461·6269··="#idm7333"·tabi
Max diff block lines reached; 3944839/3981989 bytes (99.07%) of diff not shown.
339 KB
html2text {}
    
Offset 124, 19 lines modifiedOffset 124, 21 lines modified
124 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)124 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
125 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3125 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
127 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199127 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
128 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79128 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
129 ············_\x8c_\x8i_\x8s············6.1.1129 ············_\x8c_\x8i_\x8s············6.1.1
130 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2130 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 136 package·install·aide
132 [[packages]] 
133 name·=·"aide" 
134 version·=·"*" 
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
140 #·Remediation·is·applicable·only·in·certain·platforms142 #·Remediation·is·applicable·only·in·certain·platforms
141 if·rpm·--quiet·-q·kernel;·then143 if·rpm·--quiet·-q·kernel;·then
Offset 180, 14 lines modifiedOffset 182, 26 lines modified
180 ··-·PCI-DSSv4-11.5.2182 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy183 ··-·enable_strategy
182 ··-·low_complexity184 ··-·low_complexity
183 ··-·low_disruption185 ··-·low_disruption
184 ··-·medium_severity186 ··-·medium_severity
185 ··-·no_reboot_needed187 ··-·no_reboot_needed
186 ··-·package_aide_installed188 ··-·package_aide_installed
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 194 package·--add=aide
 195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 196 [[packages]]
 197 name·=·"aide"
 198 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
192 dnf·install·aide204 dnf·install·aide
Offset 199, 28 lines modifiedOffset 213, 14 lines modified
199 include·install_aide213 include·install_aide
  
200 class·install_aide·{214 class·install_aide·{
201 ··package·{·'aide':215 ··package·{·'aide':
202 ····ensure·=>·'installed',216 ····ensure·=>·'installed',
203 ··}217 ··}
204 }218 }
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
210 package·install·aide 
211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
216 package·--add=aide 
217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
218 Run·the·following·command·to·generate·a·new·database:220 Run·the·following·command·to·generate·a·new·database:
219 $·sudo·/usr/sbin/aide·--init221 $·sudo·/usr/sbin/aide·--init
220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
222 To·initiate·a·manual·check,·run·the·following·command:224 To·initiate·a·manual·check,·run·the·following·command:
223 $·sudo·/usr/sbin/aide·--check225 $·sudo·/usr/sbin/aide·--check
Offset 738, 14 lines modifiedOffset 738, 39 lines modified
738 »       echo·"to·see·what·package·to·(re)install"·>&2738 »       echo·"to·see·what·package·to·(re)install"·>&2
  
739 »       false··#·end·with·an·error·code739 »       false··#·end·with·an·error·code
740 elif·test·"$rc"·!=·0;·then740 elif·test·"$rc"·!=·0;·then
741 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2741 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
742 »       false··#·end·with·an·error·code742 »       false··#·end·with·an·error·code
743 fi743 fi
 744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 745 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 746 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 747 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 748 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 749 ---
 750 apiVersion:·machineconfiguration.openshift.io/v1
 751 kind:·MachineConfig
 752 spec:
 753 ··config:
 754 ····ignition:
 755 ······version:·3.1.0
 756 ····systemd:
 757 ······units:
 758 ········-·name:·configure-crypto-policy.service
 759 ··········enabled:·true
 760 ··········contents:·|
 761 ············[Unit]
 762 ············Before=kubelet.service
 763 ············[Service]
 764 ············Type=oneshot
 765 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 766 ············RemainAfterExit=yes
 767 ············[Install]
 768 ············WantedBy=multi-user.target
744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8769 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
745 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low770 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
746 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low771 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
747 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false772 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
748 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict773 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
749 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable774 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
750 ··set_fact:775 ··set_fact:
Offset 790, 39 lines modifiedOffset 815, 14 lines modified
790 ··-·PCI-DSSv4-2.2.7815 ··-·PCI-DSSv4-2.2.7
791 ··-·configure_crypto_policy816 ··-·configure_crypto_policy
792 ··-·high_severity817 ··-·high_severity
793 ··-·low_complexity818 ··-·low_complexity
794 ··-·low_disruption819 ··-·low_disruption
795 ··-·no_reboot_needed820 ··-·no_reboot_needed
Max diff block lines reached; 341913/346792 bytes (98.59%) of diff not shown.
1.66 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-e8.html
    
Offset 16187, 178 lines modifiedOffset 16187, 178 lines modified
0003f3a0:·7461·7267·6574·3d22·2369·646d·3830·3431··target="#idm80410003f3a0:·7461·7267·6574·3d22·2369·646d·3830·3431··target="#idm8041
0003f3b0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003f3b0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003f3c0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003f3c0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003f3d0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003f3d0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003f3e0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003f3e0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003f3f0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003f3f0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003f400:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003f400:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003f410:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003f420:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003f430:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003f440:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003f450:·7365·2220·6964·3d22·6964·6d38·3034·3122··se"·id="idm8041" 
0003f460:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003f470:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003f410:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s
 0003f420:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003f430:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003f440:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003f450:·6c61·7073·6522·2069·643d·2269·646d·3830··lapse"·id="idm80
 0003f460:·3431·223e·3c74·6162·6c65·2063·6c61·7373··41"><table·class
 0003f470:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003f480:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003f480:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003f490:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003f490:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003f4a0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003f4b0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003f4a0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003f4b0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003f4c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003f4d0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003f4e0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003f4c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003f4f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003f500:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003f4d0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003f4e0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003f4f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003f500:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003f510:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003f510:·7472·7565·3c2f·7464·3e3c·2f74·723e·3c74··true</td></tr><t
0003f520:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003f520:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003f530:·683e·3c74·643e·7265·7374·7269·6374·3c2f··h><td>restrict</0003f530:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
0003f540:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003f540:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003f550:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam0003f550:·653e·3c70·7265·3e3c·636f·6465·3e2d·2d2d··e><pre><code>---
0003f560:·653a·2058·4343·4446·2056·616c·7565·2076··e:·XCCDF·Value·v 
0003f570:·6172·5f73·7973·7465·6d5f·6372·7970·746f··ar_system_crypto 
0003f580:·5f70·6f6c·6963·7920·2320·7072·6f6d·6f74··_policy·#·promot 
0003f590:·6520·746f·2076·6172·6961·626c·650a·2020··e·to·variable.·· 
0003f5a0:·7365·745f·6661·6374·3a0a·2020·2020·7661··set_fact:.····va0003f560:·0a61·7069·5665·7273·696f·6e3a·206d·6163··.apiVersion:·mac
 0003f570:·6869·6e65·636f·6e66·6967·7572·6174·696f··hineconfiguratio
 0003f580:·6e2e·6f70·656e·7368·6966·742e·696f·2f76··n.openshift.io/v
 0003f590:·310a·6b69·6e64·3a20·4d61·6368·696e·6543··1.kind:·MachineC
 0003f5a0:·6f6e·6669·670a·7370·6563·3a0a·2020·636f··onfig.spec:.··co
 0003f5b0:·6e66·6967·3a0a·2020·2020·6967·6e69·7469··nfig:.····igniti
 0003f5c0:·6f6e·3a0a·2020·2020·2020·7665·7273·696f··on:.······versio
 0003f5d0:·6e3a·2033·2e31·2e30·0a20·2020·2073·7973··n:·3.1.0.····sys
 0003f5e0:·7465·6d64·3a0a·2020·2020·2020·756e·6974··temd:.······unit
 0003f5f0:·733a·0a20·2020·2020·2020·202d·206e·616d··s:.········-·nam
 0003f600:·653a·2063·6f6e·6669·6775·7265·2d63·7279··e:·configure-cry
 0003f610:·7074·6f2d·706f·6c69·6379·2e73·6572·7669··pto-policy.servi
 0003f620:·6365·0a20·2020·2020·2020·2020·2065·6e61··ce.··········ena
 0003f630:·626c·6564·3a20·7472·7565·0a20·2020·2020··bled:·true.·····
 0003f640:·2020·2020·2063·6f6e·7465·6e74·733a·207c·······contents:·|
 0003f650:·0a20·2020·2020·2020·2020·2020·205b·556e··.············[Un
 0003f660:·6974·5d0a·2020·2020·2020·2020·2020·2020··it].············
 0003f670:·4265·666f·7265·3d6b·7562·656c·6574·2e73··Before=kubelet.s
 0003f680:·6572·7669·6365·0a20·2020·2020·2020·2020··ervice.·········
 0003f690:·2020·205b·5365·7276·6963·655d·0a20·2020·····[Service].···
 0003f6a0:·2020·2020·2020·2020·2054·7970·653d·6f6e···········Type=on
 0003f6b0:·6573·686f·740a·2020·2020·2020·2020·2020··eshot.··········
 0003f6c0:·2020·4578·6563·5374·6172·743d·7570·6461····ExecStart=upda
 0003f6d0:·7465·2d63·7279·7074·6f2d·706f·6c69·6369··te-crypto-polici
 0003f6e0:·6573·202d·2d73·6574·207b·7b2e·7661·725f··es·--set·{{.var_
0003f5b0:·725f·7379·7374·656d·5f63·7279·7074·6f5f··r_system_crypto_0003f6f0:·7379·7374·656d·5f63·7279·7074·6f5f·706f··system_crypto_po
 0003f700:·6c69·6379·7d7d·0a20·2020·2020·2020·2020··licy}}.·········
 0003f710:·2020·2052·656d·6169·6e41·6674·6572·4578·····RemainAfterEx
 0003f720:·6974·3d79·6573·0a20·2020·2020·2020·2020··it=yes.·········
 0003f730:·2020·205b·496e·7374·616c·6c5d·0a20·2020·····[Install].···
 0003f740:·2020·2020·2020·2020·2057·616e·7465·6442···········WantedB
 0003f750:·793d·6d75·6c74·692d·7573·6572·2e74·6172··y=multi-user.tar
 0003f760:·6765·740a·3c2f·636f·6465·3e3c·2f70·7265··get.</code></pre
 0003f770:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003f780:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003f790:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003f7a0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003f7b0:·7267·6574·3d22·2369·646d·3830·3432·2220··rget="#idm8042"·
 0003f7c0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003f7d0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003f7e0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003f7f0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003f800:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003f810:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003f820:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe
 0003f830:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003f840:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003f850:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003f860:·2220·6964·3d22·6964·6d38·3034·3222·3e3c··"·id="idm8042"><
 0003f870:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003f880:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003f890:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003f8a0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003f8b0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003f8c0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003f8d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003f8e0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003f8f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003f900:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003f910:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003f920:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003f930:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003f940:·3c74·643e·7265·7374·7269·6374·3c2f·7464··<td>restrict</td
 0003f950:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003f960:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name:
 0003f970:·2058·4343·4446·2056·616c·7565·2076·6172···XCCDF·Value·var
0003f5c0:·706f·6c69·6379·3a20·2121·7374·7220·3c61··policy:·!!str·<a 
0003f5d0:·6262·7220·7469·746c·653d·2266·726f·6d20··bbr·title="from· 
0003f5e0:·5072·6f66·696c·652f·7265·6669·6e65·2d76··Profile/refine-v 
0003f5f0:·616c·7565·3a20·7863·6364·665f·6f72·672e··alue:·xccdf_org. 
0003f600:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte 
0003f610:·6e74·5f76·616c·7565·5f76·6172·5f73·7973··nt_value_var_sys 
0003f620:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic 
0003f630:·7922·3e44·4546·4155·4c54·3c2f·6162·6272··y">DEFAULT</abbr 
0003f640:·3e0a·2020·7461·6773·3a0a·2020·2020·2d20··>.··tags:.····-· 
0003f650:·616c·7761·7973·0a0a·2d20·6e61·6d65·3a20··always..-·name:· 
0003f660:·436f·6e66·6967·7572·6520·5379·7374·656d··Configure·System 
0003f670:·2043·7279·7074·6f67·7261·7068·7920·506f···Cryptography·Po 
0003f680:·6c69·6379·0a20·206c·696e·6569·6e66·696c··licy.··lineinfil 
0003f690:·653a·0a20·2020·2070·6174·683a·202f·6574··e:.····path:·/et 
0003f6a0:·632f·6372·7970·746f·2d70·6f6c·6963·6965··c/crypto-policie 
0003f6b0:·732f·636f·6e66·6967·0a20·2020·2072·6567··s/config.····reg 
0003f6c0:·6578·703a·205e·283f·2123·2928·5c53·2b29··exp:·^(?!#)(\S+) 
Max diff block lines reached; 1578954/1602166 bytes (98.55%) of diff not shown.
138 KB
html2text {}
    
Offset 360, 14 lines modifiedOffset 360, 39 lines modified
360 »       echo·"to·see·what·package·to·(re)install"·>&2360 »       echo·"to·see·what·package·to·(re)install"·>&2
  
361 »       false··#·end·with·an·error·code361 »       false··#·end·with·an·error·code
362 elif·test·"$rc"·!=·0;·then362 elif·test·"$rc"·!=·0;·then
363 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2363 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
364 »       false··#·end·with·an·error·code364 »       false··#·end·with·an·error·code
365 fi365 fi
 366 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 367 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 368 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 369 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 370 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 371 ---
 372 apiVersion:·machineconfiguration.openshift.io/v1
 373 kind:·MachineConfig
 374 spec:
 375 ··config:
 376 ····ignition:
 377 ······version:·3.1.0
 378 ····systemd:
 379 ······units:
 380 ········-·name:·configure-crypto-policy.service
 381 ··········enabled:·true
 382 ··········contents:·|
 383 ············[Unit]
 384 ············Before=kubelet.service
 385 ············[Service]
 386 ············Type=oneshot
 387 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 388 ············RemainAfterExit=yes
 389 ············[Install]
 390 ············WantedBy=multi-user.target
366 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
367 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low392 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
368 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low393 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
369 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false394 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
370 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict395 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
371 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable396 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
372 ··set_fact:397 ··set_fact:
Offset 412, 39 lines modifiedOffset 437, 14 lines modified
412 ··-·PCI-DSSv4-2.2.7437 ··-·PCI-DSSv4-2.2.7
413 ··-·configure_crypto_policy438 ··-·configure_crypto_policy
414 ··-·high_severity439 ··-·high_severity
415 ··-·low_complexity440 ··-·low_complexity
416 ··-·low_disruption441 ··-·low_disruption
417 ··-·no_reboot_needed442 ··-·no_reboot_needed
418 ··-·restrict_strategy443 ··-·restrict_strategy
419 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
420 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
421 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
422 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
423 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
424 --- 
425 apiVersion:·machineconfiguration.openshift.io/v1 
426 kind:·MachineConfig 
427 spec: 
428 ··config: 
429 ····ignition: 
430 ······version:·3.1.0 
431 ····systemd: 
432 ······units: 
433 ········-·name:·configure-crypto-policy.service 
434 ··········enabled:·true 
435 ··········contents:·| 
436 ············[Unit] 
437 ············Before=kubelet.service 
438 ············[Service] 
439 ············Type=oneshot 
440 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
441 ············RemainAfterExit=yes 
442 ············[Install] 
443 ············WantedBy=multi-user.target 
444 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*444 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
445 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.445 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
446 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.446 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
447 Severity: ··medium447 Severity: ··medium
448 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy448 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
449 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453449 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
450 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)450 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 1420, 14 lines modifiedOffset 1420, 38 lines modified
1420 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"1420 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
1421 fi1421 fi
1422 fi1422 fi
  
1423 else1423 else
1424 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1424 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1425 fi1425 fi
 1426 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1427 ---
 1428 apiVersion:·machineconfiguration.openshift.io/v1
 1429 kind:·MachineConfig
 1430 spec:
 1431 ··config:
 1432 ····ignition:
 1433 ······version:·3.1.0
 1434 ····storage:
 1435 ······files:
 1436 ······-·contents:
 1437 ··········source:
 1438 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1439 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1440 ········mode:·0644
 1441 ········path:·/etc/pam.d/password-auth
 1442 ········overwrite:·true
 1443 ······-·contents:
 1444 ··········source:
 1445 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1446 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1447 ········mode:·0644
 1448 ········path:·/etc/pam.d/system-auth
 1449 ········overwrite:·true
1426 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81450 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1427 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1451 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1428 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1452 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1429 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1453 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1430 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure1454 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
1431 -·name:·Gather·the·package·facts1455 -·name:·Gather·the·package·facts
1432 ··package_facts:1456 ··package_facts:
Offset 1566, 38 lines modifiedOffset 1590, 14 lines modified
1566 ··-·PCI-DSSv4-8.3.11590 ··-·PCI-DSSv4-8.3.1
1567 ··-·configure_strategy1591 ··-·configure_strategy
1568 ··-·high_severity1592 ··-·high_severity
1569 ··-·low_complexity1593 ··-·low_complexity
1570 ··-·medium_disruption1594 ··-·medium_disruption
1571 ··-·no_empty_passwords1595 ··-·no_empty_passwords
1572 ··-·no_reboot_needed1596 ··-·no_reboot_needed
1573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
Max diff block lines reached; 119935/141230 bytes (84.92%) of diff not shown.
2.4 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-hipaa.html
    
Offset 16952, 178 lines modifiedOffset 16952, 178 lines modified
00042370:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00042370:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00042380:·3830·3431·2220·7461·6269·6e64·6578·3d22··8041"·tabindex="00042380:·3830·3431·2220·7461·6269·6e64·6578·3d22··8041"·tabindex="
00042390:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00042390:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
000423a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="000423a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
000423b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac000423b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
000423c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal000423c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
000423d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme000423d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
000423e0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·000423e0:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
000423f0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
00042400:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
00042410:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
00042420:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
00042430:·3034·3122·3e3c·7461·626c·6520·636c·6173··041"><table·clas 
00042440:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00042450:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00042460:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00042470:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00042480:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><000423f0:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
 00042400:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00042410:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00042420:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00042430:·646d·3830·3431·223e·3c74·6162·6c65·2063··dm8041"><table·c
 00042440:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 00042450:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 00042460:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 00042470:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 00042480:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 00042490:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 000424a0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 000424b0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
00042490:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>000424c0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 000424d0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 000424e0:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t
000424a0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
000424b0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
000424c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
000424d0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
000424e0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
000424f0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy000424f0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
00042500:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri00042500:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
00042510:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta00042510:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
00042520:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-00042520:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
00042530:·206e·616d·653a·2058·4343·4446·2056·616c···name:·XCCDF·Val 
00042540:·7565·2076·6172·5f73·7973·7465·6d5f·6372··ue·var_system_cr 
00042550:·7970·746f·5f70·6f6c·6963·7920·2320·7072··ypto_policy·#·pr 
00042560:·6f6d·6f74·6520·746f·2076·6172·6961·626c··omote·to·variabl 
00042570:·650a·2020·7365·745f·6661·6374·3a0a·2020··e.··set_fact:.··00042530:·3e2d·2d2d·0a61·7069·5665·7273·696f·6e3a··>---.apiVersion:
 00042540:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur
 00042550:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift.
 00042560:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach
 00042570:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:.
 00042580:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig
 00042590:·6e69·7469·6f6e·3a0a·2020·2020·2020·7665··nition:.······ve
 000425a0:·7273·696f·6e3a·2033·2e31·2e30·0a20·2020··rsion:·3.1.0.···
 000425b0:·2073·7973·7465·6d64·3a0a·2020·2020·2020···systemd:.······
 000425c0:·756e·6974·733a·0a20·2020·2020·2020·202d··units:.········-
 000425d0:·206e·616d·653a·2063·6f6e·6669·6775·7265···name:·configure
 000425e0:·2d63·7279·7074·6f2d·706f·6c69·6379·2e73··-crypto-policy.s
 000425f0:·6572·7669·6365·0a20·2020·2020·2020·2020··ervice.·········
 00042600:·2065·6e61·626c·6564·3a20·7472·7565·0a20···enabled:·true.·
 00042610:·2020·2020·2020·2020·2063·6f6e·7465·6e74···········content
 00042620:·733a·207c·0a20·2020·2020·2020·2020·2020··s:·|.···········
 00042630:·205b·556e·6974·5d0a·2020·2020·2020·2020···[Unit].········
 00042640:·2020·2020·4265·666f·7265·3d6b·7562·656c······Before=kubel
 00042650:·6574·2e73·6572·7669·6365·0a20·2020·2020··et.service.·····
 00042660:·2020·2020·2020·205b·5365·7276·6963·655d·········[Service]
 00042670:·0a20·2020·2020·2020·2020·2020·2054·7970··.············Typ
 00042680:·653d·6f6e·6573·686f·740a·2020·2020·2020··e=oneshot.······
 00042690:·2020·2020·2020·4578·6563·5374·6172·743d········ExecStart=
 000426a0:·7570·6461·7465·2d63·7279·7074·6f2d·706f··update-crypto-po
 000426b0:·6c69·6369·6573·202d·2d73·6574·207b·7b2e··licies·--set·{{.
00042580:·2020·7661·725f·7379·7374·656d·5f63·7279····var_system_cry000426c0:·7661·725f·7379·7374·656d·5f63·7279·7074··var_system_crypt
 000426d0:·6f5f·706f·6c69·6379·7d7d·0a20·2020·2020··o_policy}}.·····
 000426e0:·2020·2020·2020·2052·656d·6169·6e41·6674·········RemainAft
 000426f0:·6572·4578·6974·3d79·6573·0a20·2020·2020··erExit=yes.·····
 00042700:·2020·2020·2020·205b·496e·7374·616c·6c5d·········[Install]
 00042710:·0a20·2020·2020·2020·2020·2020·2057·616e··.············Wan
 00042720:·7465·6442·793d·6d75·6c74·692d·7573·6572··tedBy=multi-user
 00042730:·2e74·6172·6765·740a·3c2f·636f·6465·3e3c··.target.</code><
 00042740:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 00042750:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 00042760:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 00042770:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 00042780:·612d·7461·7267·6574·3d22·2369·646d·3830··a-target="#idm80
 00042790:·3432·2220·7461·6269·6e64·6578·3d22·3022··42"·tabindex="0"
 000427a0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 000427b0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 000427c0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 000427d0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 000427e0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 000427f0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
 00042800:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00042810:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00042820:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00042830:·6170·7365·2220·6964·3d22·6964·6d38·3034··apse"·id="idm804
 00042840:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 00042850:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 00042860:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 00042870:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 00042880:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 00042890:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 000428a0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 000428b0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 000428c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 000428d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 000428e0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 000428f0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 00042900:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 00042910:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
 00042920:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00042930:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
 00042940:·616d·653a·2058·4343·4446·2056·616c·7565··ame:·XCCDF·Value
 00042950:·2076·6172·5f73·7973·7465·6d5f·6372·7970···var_system_cryp
 00042960:·746f·5f70·6f6c·6963·7920·2320·7072·6f6d··to_policy·#·prom
 00042970:·6f74·6520·746f·2076·6172·6961·626c·650a··ote·to·variable.
 00042980:·2020·7365·745f·6661·6374·3a0a·2020·2020····set_fact:.····
 00042990:·7661·725f·7379·7374·656d·5f63·7279·7074··var_system_crypt
00042590:·7074·6f5f·706f·6c69·6379·3a20·2121·7374··pto_policy:·!!st000429a0:·6f5f·706f·6c69·6379·3a20·2121·7374·7220··o_policy:·!!str·
000425a0:·7220·3c61·6262·7220·7469·746c·653d·2266··r·<abbr·title="f000429b0:·3c61·6262·7220·7469·746c·653d·2266·726f··<abbr·title="fro
000425b0:·726f·6d20·4265·6e63·686d·6172·6b2f·5661··rom·Benchmark/Va000429c0:·6d20·4265·6e63·686d·6172·6b2f·5661·6c75··m·Benchmark/Valu
000425c0:·6c75·653a·2078·6363·6466·5f6f·7267·2e73··lue:·xccdf_org.s000429d0:·653a·2078·6363·6466·5f6f·7267·2e73·7367··e:·xccdf_org.ssg
000425d0:·7367·7072·6f6a·6563·742e·636f·6e74·656e··sgproject.conten000429e0:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
000425e0:·745f·7661·6c75·655f·7661·725f·7379·7374··t_value_var_syst000429f0:·7661·6c75·655f·7661·725f·7379·7374·656d··value_var_system
000425f0:·656d·5f63·7279·7074·6f5f·706f·6c69·6379··em_crypto_policy00042a00:·5f63·7279·7074·6f5f·706f·6c69·6379·223e··_crypto_policy">
00042600:·223e·4445·4641·554c·543c·2f61·6262·723e··">DEFAULT</abbr>00042a10:·4445·4641·554c·543c·2f61·6262·723e·0a20··DEFAULT</abbr>.·
00042610:·0a20·2074·6167·733a·0a20·2020·202d·2061··.··tags:.····-·a00042a20:·2074·6167·733a·0a20·2020·202d·2061·6c77···tags:.····-·alw
00042620:·6c77·6179·730a·0a2d·206e·616d·653a·2043··lways..-·name:·C00042a30:·6179·730a·0a2d·206e·616d·653a·2043·6f6e··ays..-·name:·Con
Max diff block lines reached; 2306504/2329716 bytes (99.00%) of diff not shown.
185 KB
html2text {}
    
Offset 550, 14 lines modifiedOffset 550, 39 lines modified
550 »       echo·"to·see·what·package·to·(re)install"·>&2550 »       echo·"to·see·what·package·to·(re)install"·>&2
  
551 »       false··#·end·with·an·error·code551 »       false··#·end·with·an·error·code
552 elif·test·"$rc"·!=·0;·then552 elif·test·"$rc"·!=·0;·then
553 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2553 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
554 »       false··#·end·with·an·error·code554 »       false··#·end·with·an·error·code
555 fi555 fi
 556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 561 ---
 562 apiVersion:·machineconfiguration.openshift.io/v1
 563 kind:·MachineConfig
 564 spec:
 565 ··config:
 566 ····ignition:
 567 ······version:·3.1.0
 568 ····systemd:
 569 ······units:
 570 ········-·name:·configure-crypto-policy.service
 571 ··········enabled:·true
 572 ··········contents:·|
 573 ············[Unit]
 574 ············Before=kubelet.service
 575 ············[Service]
 576 ············Type=oneshot
 577 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 578 ············RemainAfterExit=yes
 579 ············[Install]
 580 ············WantedBy=multi-user.target
556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8581 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low582 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low583 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false584 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict585 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
561 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable586 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
562 ··set_fact:587 ··set_fact:
Offset 602, 39 lines modifiedOffset 627, 14 lines modified
602 ··-·PCI-DSSv4-2.2.7627 ··-·PCI-DSSv4-2.2.7
603 ··-·configure_crypto_policy628 ··-·configure_crypto_policy
604 ··-·high_severity629 ··-·high_severity
605 ··-·low_complexity630 ··-·low_complexity
606 ··-·low_disruption631 ··-·low_disruption
607 ··-·no_reboot_needed632 ··-·no_reboot_needed
608 ··-·restrict_strategy633 ··-·restrict_strategy
609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
614 --- 
615 apiVersion:·machineconfiguration.openshift.io/v1 
616 kind:·MachineConfig 
617 spec: 
618 ··config: 
619 ····ignition: 
620 ······version:·3.1.0 
621 ····systemd: 
622 ······units: 
623 ········-·name:·configure-crypto-policy.service 
624 ··········enabled:·true 
625 ··········contents:·| 
626 ············[Unit] 
627 ············Before=kubelet.service 
628 ············[Service] 
629 ············Type=oneshot 
630 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
631 ············RemainAfterExit=yes 
632 ············[Install] 
633 ············WantedBy=multi-user.target 
634 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*634 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
635 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.635 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
636 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.636 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
637 Severity: ··medium637 Severity: ··medium
638 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy638 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
639 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453639 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
640 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)640 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 723, 29 lines modifiedOffset 723, 29 lines modified
723 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)723 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)
724 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4724 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4
725 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1725 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
726 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227726 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
727 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800727 ············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
728 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71728 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
729 ············_\x8c_\x8i_\x8s············1.1.2.7.1729 ············_\x8c_\x8i_\x8s············1.1.2.7.1
730 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
731 [[customizations.filesystem]] 
732 mountpoint·=·"/var/log/audit" 
733 size·=·10737418240 
734 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8730 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
735 logvol·/var/log/audit·10240731 logvol·/var/log/audit·10240
736 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8732 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
737 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low733 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
738 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high734 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
739 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false735 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
740 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable736 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
741 part·/var/log/audit737 part·/var/log/audit
 738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 739 [[customizations.filesystem]]
 740 mountpoint·=·"/var/log/audit"
 741 size·=·10737418240
742 Group  ·GNOME·Desktop·Environment·  Group·contains·1·rule742 Group  ·GNOME·Desktop·Environment·  Group·contains·1·rule
743 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.743 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
744 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.744 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
745 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.745 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
746 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*746 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1333, 18 lines modifiedOffset 1333, 21 lines modified
1333 Rule·ID:····xccdf_org.ssgproject.content_rule_service_debug-shell_disabled1333 Rule·ID:····xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
1334 ············_\x8c_\x8u_\x8i····3.4.51334 ············_\x8c_\x8u_\x8i····3.4.5
1335 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-0022351335 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
1336 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1336 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1337 ············_\x8n_\x8i_\x8s_\x8t···CM-61337 ············_\x8n_\x8i_\x8s_\x8t···CM-6
1338 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.11338 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
1339 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271339 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1341 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1342 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1343 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1344 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
Max diff block lines reached; 183140/189476 bytes (96.66%) of diff not shown.
2.69 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ism_o.html
    
Offset 15203, 279 lines modifiedOffset 15203, 279 lines modified
0003b620:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b620:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b630:·6d37·3333·3122·2074·6162·696e·6465·783d··m7331"·tabindex=0003b630:·6d37·3333·3122·2074·6162·696e·6465·783d··m7331"·tabindex=
0003b640:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b640:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b650:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b650:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b660:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b660:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b670:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b670:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b680:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b680:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b690:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script·
0003b690:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0003b6a0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003b6b0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b6c0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b6d0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b6e0:·6522·2069·643d·2269·646d·3733·3331·223e··e"·id="idm7331"> 
0003b6f0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003b700:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003b710:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·= 
0003b720:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003b730:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b740:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b750:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b760:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b770:·6172·6765·743d·2223·6964·6d37·3333·3222··arget="#idm7332" 
0003b780:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b790:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b7a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b7b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b7c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b7d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b7e0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003b7f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003b6a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003b800:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003b6b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b810:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003b6c0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b820:·6964·3d22·6964·6d37·3333·3222·3e3c·7461··id="idm7332"><ta0003b6d0:·6964·3d22·6964·6d37·3333·3122·3e3c·7461··id="idm7331"><ta
0003b830:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003b6e0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003b840:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003b6f0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003b850:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003b700:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003b860:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003b710:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003b870:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003b720:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003b880:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003b730:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003b890:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b740:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b8a0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003b750:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003b8b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b760:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003b8c0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003b770:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003b8d0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003b780:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003b8e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b790:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b8f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0003b7a0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003b900:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t0003b7b0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003b910:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003b7c0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b7d0:·636f·6465·3e0a·7061·636b·6167·6520·696e··code>.package·in
 0003b7e0:·7374·616c·6c20·6169·6465·0a3c·2f63·6f64··stall·aide.</cod
0003b920:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0003b930:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0003b940:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0003b950:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp 
0003b960:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker 
0003b970:·6e65·6c3b·2074·6865·6e0a·0a69·6620·2120··nel;·then..if·!· 
0003b980:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
0003b990:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.··· 
0003b9a0:·2064·6e66·2069·6e73·7461·6c6c·202d·7920···dnf·install·-y· 
0003b9b0:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else. 
0003b9c0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
0003b9d0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
0003b9e0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
0003b9f0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
0003ba00:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
0003ba10:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b7f0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
0003ba20:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003b800:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
0003ba30:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003b810:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003ba40:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003b820:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
0003ba50:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003b830:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003ba60:·3333·3322·2074·6162·696e·6465·783d·2230··333"·tabindex="00003b840:·6d37·3333·3222·2074·6162·696e·6465·783d··m7332"·tabindex=
0003ba70:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b850:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003ba80:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b860:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003ba90:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b870:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003baa0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b880:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bab0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b890:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003bac0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s0003b8a0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
 0003b8b0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003b8c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b8d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b8e0:·6170·7365·2220·6964·3d22·6964·6d37·3333··apse"·id="idm733
 0003b8f0:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 0003b900:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003bad0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003bae0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003baf0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003bb00:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73 
0003bb10:·3333·223e·3c74·6162·6c65·2063·6c61·7373··33"><table·class 
0003bb20:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003bb30:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003bb40:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003b910:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003bb50:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003bb60:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003bb70:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bb80:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003bb90:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003bba0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bbb0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003b920:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003b930:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003b940:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003b950:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b960:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b970:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b980:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003b990:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003b9a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003b9b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b9c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003b9d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003b9e0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003b9f0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003ba00:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003ba10:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003ba20:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet·
 0003ba30:·2d71·206b·6572·6e65·6c3b·2074·6865·6e0a··-q·kernel;·then.
 0003ba40:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 0003ba50:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th
 0003ba60:·656e·0a20·2020·2064·6e66·2069·6e73·7461··en.····dnf·insta
 0003ba70:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi.
 0003ba80:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 0003ba90:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 0003baa0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 0003bab0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 0003bac0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
 0003bad0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003bae0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
Max diff block lines reached; 2540256/2577406 bytes (98.56%) of diff not shown.
233 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 21 lines modified
122 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)122 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
123 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3123 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
126 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ············_\x8c_\x8i_\x8s············6.1.1127 ············_\x8c_\x8i_\x8s············6.1.1
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 134 package·install·aide
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms140 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel;·then141 if·rpm·--quiet·-q·kernel;·then
Offset 178, 14 lines modifiedOffset 180, 26 lines modified
178 ··-·PCI-DSSv4-11.5.2180 ··-·PCI-DSSv4-11.5.2
179 ··-·enable_strategy181 ··-·enable_strategy
180 ··-·low_complexity182 ··-·low_complexity
181 ··-·low_disruption183 ··-·low_disruption
182 ··-·medium_severity184 ··-·medium_severity
183 ··-·no_reboot_needed185 ··-·no_reboot_needed
184 ··-·package_aide_installed186 ··-·package_aide_installed
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 192 package·--add=aide
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 194 [[packages]]
 195 name·=·"aide"
 196 version·=·"*"
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
190 dnf·install·aide202 dnf·install·aide
Offset 197, 28 lines modifiedOffset 211, 14 lines modified
197 include·install_aide211 include·install_aide
  
198 class·install_aide·{212 class·install_aide·{
199 ··package·{·'aide':213 ··package·{·'aide':
200 ····ensure·=>·'installed',214 ····ensure·=>·'installed',
201 ··}215 ··}
202 }216 }
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
208 package·install·aide 
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
214 package·--add=aide 
215 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules217 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
216 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.218 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
217 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.219 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
218 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.220 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 234, 31 lines modifiedOffset 234, 31 lines modified
234 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode234 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
235 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877235 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
236 ············_\x8i_\x8s_\x8m······1446236 ············_\x8i_\x8s_\x8m······1446
237 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1237 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
238 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12238 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
239 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1239 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
240 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176240 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
242 [customizations] 
243 fips·=·true 
244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
245 #·Remediation·is·applicable·only·in·certain·platforms242 #·Remediation·is·applicable·only·in·certain·platforms
246 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then243 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
247 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then244 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
248 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF245 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
249 kargs·=·["fips=1"]246 kargs·=·["fips=1"]
250 EOF247 EOF
251 fi248 fi
  
252 else249 else
253 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'250 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
254 fi251 fi
 252 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 253 [customizations]
 254 fips·=·true
255 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*255 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
256 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:256 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
257 #·cat·/proc/sys/crypto/fips_enabled257 #·cat·/proc/sys/crypto/fips_enabled
258 1258 1
259 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.259 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
260 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.260 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
261 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.261 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 310, 14 lines modifiedOffset 310, 39 lines modified
310 »       echo·"to·see·what·package·to·(re)install"·>&2310 »       echo·"to·see·what·package·to·(re)install"·>&2
  
311 »       false··#·end·with·an·error·code311 »       false··#·end·with·an·error·code
312 elif·test·"$rc"·!=·0;·then312 elif·test·"$rc"·!=·0;·then
313 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2313 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
314 »       false··#·end·with·an·error·code314 »       false··#·end·with·an·error·code
315 fi315 fi
 316 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 317 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 318 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 229575/238227 bytes (96.37%) of diff not shown.
2.69 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ism_o_secret.html
    
Offset 15207, 279 lines modifiedOffset 15207, 279 lines modified
0003b660:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b660:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b670:·3733·3331·2220·7461·6269·6e64·6578·3d22··7331"·tabindex="0003b670:·3733·3331·2220·7461·6269·6e64·6578·3d22··7331"·tabindex="
0003b680:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b680:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b690:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b690:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b6a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b6a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b6b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b6b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b6c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b6c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b6d0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·0003b6d0:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
0003b6e0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0003b6f0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b700:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b710:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b720:·2220·6964·3d22·6964·6d37·3333·3122·3e3c··"·id="idm7331">< 
0003b730:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
0003b740:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
0003b750:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=· 
0003b760:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
0003b770:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b780:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b790:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b7a0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b7b0:·7267·6574·3d22·2369·646d·3733·3332·2220··rget="#idm7332"· 
0003b7c0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b7d0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b7e0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b7f0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b800:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b810:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b820:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003b830:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b6e0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b840:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b6f0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b850:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b700:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b860:·643d·2269·646d·3733·3332·223e·3c74·6162··d="idm7332"><tab0003b710:·643d·2269·646d·3733·3331·223e·3c74·6162··d="idm7331"><tab
0003b870:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b720:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b880:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b730:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b890:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b740:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003b8a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b750:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003b8b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b760:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003b8c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b770:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b8d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003b780:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003b8e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003b790:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003b8f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b7a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b900:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003b7b0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b910:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b7c0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b920:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b7d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b930:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b7e0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b940:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003b7f0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003b950:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b800:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b810:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins
 0003b820:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code
0003b960:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0003b970:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0003b980:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0003b990:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm 
0003b9a0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern 
0003b9b0:·656c·3b20·7468·656e·0a0a·6966·2021·2072··el;·then..if·!·r 
0003b9c0:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003b9d0:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003b9e0:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·" 
0003b9f0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003ba00:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003ba10:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003ba20:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003ba30:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003ba40:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003ba50:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003b830:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003ba60:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003b840:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003ba70:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003b850:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003ba80:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003b860:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003ba90:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm730003b870:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003baa0:·3333·2220·7461·6269·6e64·6578·3d22·3022··33"·tabindex="0"0003b880:·3733·3332·2220·7461·6269·6e64·6578·3d22··7332"·tabindex="
0003bab0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b890:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003bac0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b8a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003bad0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b8b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003bae0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b8c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003baf0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b8d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b8e0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 0003b8f0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003b900:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b910:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b920:·7073·6522·2069·643d·2269·646d·3733·3332··pse"·id="idm7332
 0003b930:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b940:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003bb00:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003bb10:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003bb20:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bb30:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bb40:·6170·7365·2220·6964·3d22·6964·6d37·3333··apse"·id="idm733 
0003bb50:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class= 
0003bb60:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bb70:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bb80:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b950:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003bb90:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003bba0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003bbb0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003bbc0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bbd0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bbe0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bbf0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003b960:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b970:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b980:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b990:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b9a0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b9b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b9c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b9d0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b9e0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b9f0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003ba00:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003ba10:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003ba20:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 0003ba30:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 0003ba40:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 0003ba50:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 0003ba60:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 0003ba70:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then..
 0003ba80:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003ba90:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003baa0:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal
 0003bab0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003bac0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003bad0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003bae0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003baf0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003bb00:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 0003bb10:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003bb20:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
Max diff block lines reached; 2540532/2577682 bytes (98.56%) of diff not shown.
233 KB
html2text {}
    
Offset 123, 19 lines modifiedOffset 123, 21 lines modified
123 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)123 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
124 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3124 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
128 ············_\x8c_\x8i_\x8s············6.1.1128 ············_\x8c_\x8i_\x8s············6.1.1
129 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2129 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 135 package·install·aide
131 [[packages]] 
132 name·=·"aide" 
133 version·=·"*" 
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
139 #·Remediation·is·applicable·only·in·certain·platforms141 #·Remediation·is·applicable·only·in·certain·platforms
140 if·rpm·--quiet·-q·kernel;·then142 if·rpm·--quiet·-q·kernel;·then
Offset 179, 14 lines modifiedOffset 181, 26 lines modified
179 ··-·PCI-DSSv4-11.5.2181 ··-·PCI-DSSv4-11.5.2
180 ··-·enable_strategy182 ··-·enable_strategy
181 ··-·low_complexity183 ··-·low_complexity
182 ··-·low_disruption184 ··-·low_disruption
183 ··-·medium_severity185 ··-·medium_severity
184 ··-·no_reboot_needed186 ··-·no_reboot_needed
185 ··-·package_aide_installed187 ··-·package_aide_installed
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 package·--add=aide
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 195 [[packages]]
 196 name·=·"aide"
 197 version·=·"*"
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
191 dnf·install·aide203 dnf·install·aide
Offset 198, 28 lines modifiedOffset 212, 14 lines modified
198 include·install_aide212 include·install_aide
  
199 class·install_aide·{213 class·install_aide·{
200 ··package·{·'aide':214 ··package·{·'aide':
201 ····ensure·=>·'installed',215 ····ensure·=>·'installed',
202 ··}216 ··}
203 }217 }
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
209 package·install·aide 
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
215 package·--add=aide 
216 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules218 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
217 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.219 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
218 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.220 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
219 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.221 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
220 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*222 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 235, 31 lines modifiedOffset 235, 31 lines modified
235 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode235 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
236 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877236 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
237 ············_\x8i_\x8s_\x8m······1446237 ············_\x8i_\x8s_\x8m······1446
238 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1238 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
239 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12239 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
240 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1240 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
241 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176241 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
242 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
243 [customizations] 
244 fips·=·true 
245 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8242 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
246 #·Remediation·is·applicable·only·in·certain·platforms243 #·Remediation·is·applicable·only·in·certain·platforms
247 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then244 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
248 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then245 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
249 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF246 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
250 kargs·=·["fips=1"]247 kargs·=·["fips=1"]
251 EOF248 EOF
252 fi249 fi
  
253 else250 else
254 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'251 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
255 fi252 fi
 253 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 254 [customizations]
 255 fips·=·true
256 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*256 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
257 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:257 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
258 #·cat·/proc/sys/crypto/fips_enabled258 #·cat·/proc/sys/crypto/fips_enabled
259 1259 1
260 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.260 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
261 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.261 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
262 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.262 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 311, 14 lines modifiedOffset 311, 39 lines modified
311 »       echo·"to·see·what·package·to·(re)install"·>&2311 »       echo·"to·see·what·package·to·(re)install"·>&2
  
312 »       false··#·end·with·an·error·code312 »       false··#·end·with·an·error·code
313 elif·test·"$rc"·!=·0;·then313 elif·test·"$rc"·!=·0;·then
314 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2314 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
315 »       false··#·end·with·an·error·code315 »       false··#·end·with·an·error·code
316 fi316 fi
 317 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 318 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 319 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 229575/238227 bytes (96.37%) of diff not shown.
2.69 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ism_o_top_secret.html
    
Offset 15205, 278 lines modifiedOffset 15205, 278 lines modified
0003b640:·6574·3d22·2369·646d·3733·3331·2220·7461··et="#idm7331"·ta0003b640:·6574·3d22·2369·646d·3733·3331·2220·7461··et="#idm7331"·ta
0003b650:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b650:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b660:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b660:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b670:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b670:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b680:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b680:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b690:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b690:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b6a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b6a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b6b0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003b6c0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003b6d0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b6e0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b6f0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b700:·6d37·3333·3122·3e3c·7072·653e·3c63·6f64··m7331"><pre><cod 
0003b710:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003b720:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003b730:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003b740:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b750:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b760:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b770:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b780:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b790:·646d·3733·3332·2220·7461·6269·6e64·6578··dm7332"·tabindex 
0003b7a0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b7b0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b7c0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b7d0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b7e0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b7f0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b800:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b0003b6b0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
0003b810:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003b6c0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b820:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003b6d0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b830:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm730003b6e0:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73
0003b840:·3332·223e·3c74·6162·6c65·2063·6c61·7373··32"><table·class0003b6f0:·3331·223e·3c74·6162·6c65·2063·6c61·7373··31"><table·class
0003b850:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003b700:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b860:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003b710:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b870:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003b720:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b880:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003b730:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b890:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003b740:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b8a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b750:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b8b0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b760:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b8c0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003b770:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b8d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b780:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b8e0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003b790:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b8f0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b7a0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003b900:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003b7b0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003b910:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003b7c0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b920:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003b7d0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b930:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re0003b7e0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003b7f0:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
0003b940:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b950:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b960:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b970:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
0003b980:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
0003b990:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b9a0:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b9b0:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
0003b9c0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b9d0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b9e0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b9f0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003ba00:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003ba10:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003ba20:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003b800:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
0003ba30:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003b810:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003ba40:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003b820:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003ba50:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003b830:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003ba60:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b840:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003ba70:·3d22·2369·646d·3733·3333·2220·7461·6269··="#idm7333"·tabi0003b850:·6574·3d22·2369·646d·3733·3332·2220·7461··et="#idm7332"·ta
0003ba80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b860:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003ba90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b870:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003baa0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b880:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003bab0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b890:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003bac0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b8a0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003bad0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b8b0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003bae0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003baf0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003bb00:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003bb10:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003bb20:·3d22·6964·6d37·3333·3322·3e3c·7461·626c··="idm7333"><tabl 
0003bb30:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003bb40:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003bb50:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003bb60:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003bb70:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003bb80:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003bb90:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003bba0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b8c0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003b8d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b8e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b8f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b900:·2269·646d·3733·3332·223e·3c74·6162·6c65··"idm7332"><table
 0003b910:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003b920:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003b930:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003b940:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b950:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003b960:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b970:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b980:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003b990:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b9a0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003b9b0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003b9c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003b9d0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bbb0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b9e0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bbc0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003bbd0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003bbe0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003bbf0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003bc00:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003bc10:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bc20:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
0003bc30:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
0003bc40:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
0003bc50:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
0003bc60:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
0003bc70:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003bc80:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003bc90:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI 
0003bca0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.·· 
0003bcb0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5 
0003bcc0:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st 
0003bcd0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c 
0003bce0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo 
0003bcf0:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··- 
0003bd00:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity 
Max diff block lines reached; 2540532/2577544 bytes (98.56%) of diff not shown.
233 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 21 lines modified
122 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)122 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
123 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3123 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
126 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ············_\x8c_\x8i_\x8s············6.1.1127 ············_\x8c_\x8i_\x8s············6.1.1
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 134 package·install·aide
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms140 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel;·then141 if·rpm·--quiet·-q·kernel;·then
Offset 178, 14 lines modifiedOffset 180, 26 lines modified
178 ··-·PCI-DSSv4-11.5.2180 ··-·PCI-DSSv4-11.5.2
179 ··-·enable_strategy181 ··-·enable_strategy
180 ··-·low_complexity182 ··-·low_complexity
181 ··-·low_disruption183 ··-·low_disruption
182 ··-·medium_severity184 ··-·medium_severity
183 ··-·no_reboot_needed185 ··-·no_reboot_needed
184 ··-·package_aide_installed186 ··-·package_aide_installed
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 192 package·--add=aide
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 194 [[packages]]
 195 name·=·"aide"
 196 version·=·"*"
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
190 dnf·install·aide202 dnf·install·aide
Offset 197, 28 lines modifiedOffset 211, 14 lines modified
197 include·install_aide211 include·install_aide
  
198 class·install_aide·{212 class·install_aide·{
199 ··package·{·'aide':213 ··package·{·'aide':
200 ····ensure·=>·'installed',214 ····ensure·=>·'installed',
201 ··}215 ··}
202 }216 }
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
208 package·install·aide 
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
214 package·--add=aide 
215 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules217 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
216 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.218 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
217 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.219 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
218 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.220 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 234, 31 lines modifiedOffset 234, 31 lines modified
234 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode234 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
235 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877235 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
236 ············_\x8i_\x8s_\x8m······1446236 ············_\x8i_\x8s_\x8m······1446
237 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1237 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
238 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12238 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
239 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1239 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
240 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176240 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
242 [customizations] 
243 fips·=·true 
244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
245 #·Remediation·is·applicable·only·in·certain·platforms242 #·Remediation·is·applicable·only·in·certain·platforms
246 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then243 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
247 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then244 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
248 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF245 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
249 kargs·=·["fips=1"]246 kargs·=·["fips=1"]
250 EOF247 EOF
251 fi248 fi
  
252 else249 else
253 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'250 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
254 fi251 fi
 252 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 253 [customizations]
 254 fips·=·true
255 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*255 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
256 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:256 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
257 #·cat·/proc/sys/crypto/fips_enabled257 #·cat·/proc/sys/crypto/fips_enabled
258 1258 1
259 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.259 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
260 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.260 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
261 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.261 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 310, 14 lines modifiedOffset 310, 39 lines modified
310 »       echo·"to·see·what·package·to·(re)install"·>&2310 »       echo·"to·see·what·package·to·(re)install"·>&2
  
311 »       false··#·end·with·an·error·code311 »       false··#·end·with·an·error·code
312 elif·test·"$rc"·!=·0;·then312 elif·test·"$rc"·!=·0;·then
313 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2313 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
314 »       false··#·end·with·an·error·code314 »       false··#·end·with·an·error·code
315 fi315 fi
 316 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 317 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 318 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 229575/238227 bytes (96.37%) of diff not shown.
3.13 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-ospp.html
    
Offset 15157, 62 lines modifiedOffset 15157, 62 lines modified
0003b340:·6574·3d22·2369·646d·3738·3339·2220·7461··et="#idm7839"·ta0003b340:·6574·3d22·2369·646d·3738·3339·2220·7461··et="#idm7839"·ta
0003b350:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b350:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b360:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b360:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b370:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b370:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b380:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b380:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b390:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b390:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b3a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b3a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b3b0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003b3c0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003b3d0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b3e0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b3f0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b400:·6d37·3833·3922·3e3c·7072·653e·3c63·6f64··m7839"><pre><cod 
0003b410:·653e·0a5b·6375·7374·6f6d·697a·6174·696f··e>.[customizatio 
0003b420:·6e73·5d0a·6669·7073·203d·2074·7275·650a··ns].fips·=·true. 
0003b430:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b440:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b450:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b460:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b470:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b480:·3d22·2369·646d·3738·3430·2220·7461·6269··="#idm7840"·tabi 
0003b490:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b4a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b4b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b4c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b4d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b4e0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003b4f0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</0003b3b0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
0003b500:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b3c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b510:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b3d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b520:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b3e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b530:·646d·3738·3430·223e·3c70·7265·3e3c·636f··dm7840"><pre><co0003b3f0:·2269·646d·3738·3339·223e·3c70·7265·3e3c··"idm7839"><pre><
0003b540:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation0003b400:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
0003b550:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o0003b410:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
0003b560:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p0003b420:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
0003b570:·6c61·7466·6f72·6d73·0a69·6620·2820·2120··latforms.if·(·!·0003b430:·2070·6c61·7466·6f72·6d73·0a69·6620·2820···platforms.if·(·
0003b580:·2820·5b20·2224·7b63·6f6e·7461·696e·6572··(·[·"${container0003b440:·2120·2820·5b20·2224·7b63·6f6e·7461·696e··!·(·[·"${contain
0003b590:·3a2d·7d22·203d·3d20·2262·7772·6170·2d6f··:-}"·==·"bwrap-o0003b450:·6572·3a2d·7d22·203d·3d20·2262·7772·6170··er:-}"·==·"bwrap
0003b5a0:·7362·7569·6c64·2220·5d20·2920·2661·6d70··sbuild"·]·)·&amp0003b460:·2d6f·7362·7569·6c64·2220·5d20·2920·2661··-osbuild"·]·)·&a
0003b5b0:·3b26·616d·703b·2072·706d·202d·2d71·7569··;&amp;·rpm·--qui0003b470:·6d70·3b26·616d·703b·2072·706d·202d·2d71··mp;&amp;·rpm·--q
0003b5c0:·6574·202d·7120·6b65·726e·656c·2029·3b20··et·-q·kernel·);·0003b480:·7569·6574·202d·7120·6b65·726e·656c·2029··uiet·-q·kernel·)
0003b5d0:·7468·656e·0a0a·6966·205b·5b20·2224·4f53··then..if·[[·"$OS0003b490:·3b20·7468·656e·0a0a·6966·205b·5b20·2224··;·then..if·[[·"$
0003b5e0:·4341·505f·424f·4f54·435f·4255·494c·4422··CAP_BOOTC_BUILD"0003b4a0:·4f53·4341·505f·424f·4f54·435f·4255·494c··OSCAP_BOOTC_BUIL
0003b5f0:·203d·3d20·2259·4553·2220·5d5d·3b20·7468···==·"YES"·]];·th0003b4b0:·4422·203d·3d20·2259·4553·2220·5d5d·3b20··D"·==·"YES"·]];·
0003b600:·656e·0a09·6361·7420·2667·743b·202f·7573··en..cat·&gt;·/us0003b4c0:·7468·656e·0a09·6361·7420·2667·743b·202f··then..cat·&gt;·/
0003b610:·722f·6c69·622f·626f·6f74·632f·6b61·7267··r/lib/bootc/karg0003b4d0:·7573·722f·6c69·622f·626f·6f74·632f·6b61··usr/lib/bootc/ka
0003b620:·732e·642f·3031·2d66·6970·732e·746f·6d6c··s.d/01-fips.toml0003b4e0:·7267·732e·642f·3031·2d66·6970·732e·746f··rgs.d/01-fips.to
0003b630:·2026·6c74·3b26·6c74·3b20·454f·460a·6b61···&lt;&lt;·EOF.ka0003b4f0:·6d6c·2026·6c74·3b26·6c74·3b20·454f·460a··ml·&lt;&lt;·EOF.
0003b640:·7267·7320·3d20·5b22·6669·7073·3d31·225d··rgs·=·["fips=1"]0003b500:·6b61·7267·7320·3d20·5b22·6669·7073·3d31··kargs·=·["fips=1
0003b650:·0a45·4f46·0a66·690a·0a65·6c73·650a·2020··.EOF.fi..else.··0003b510:·225d·0a45·4f46·0a66·690a·0a65·6c73·650a··"].EOF.fi..else.
0003b660:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech0003b520:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
0003b670:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i0003b530:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
0003b680:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable0003b540:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
0003b690:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do0003b550:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
0003b6a0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></0003b560:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
 0003b570:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b580:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b590:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003b5a0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003b5b0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
 0003b5c0:·3834·3022·2074·6162·696e·6465·783d·2230··840"·tabindex="0
 0003b5d0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003b5e0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003b5f0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003b600:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003b610:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003b620:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003b630:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003b640:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b650:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b660:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b670:·2069·643d·2269·646d·3738·3430·223e·3c70···id="idm7840"><p
 0003b680:·7265·3e3c·636f·6465·3e0a·5b63·7573·746f··re><code>.[custo
 0003b690:·6d69·7a61·7469·6f6e·735d·0a66·6970·7320··mizations].fips·
 0003b6a0:·3d20·7472·7565·0a3c·2f63·6f64·653e·3c2f··=·true.</code></
0003b6b0:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>0003b6b0:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>
0003b6c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod0003b6c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod
0003b6d0:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><0003b6d0:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><
0003b6e0:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-0003b6e0:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-
0003b6f0:·6964·3d22·6368·696c·6472·656e·2d78·6363··id="children-xcc0003b6f0:·6964·3d22·6368·696c·6472·656e·2d78·6363··id="children-xcc
0003b700:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec0003b700:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
0003b710:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_0003b710:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15477, 251 lines modifiedOffset 15477, 251 lines modified
0003c740:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003c740:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003c750:·2223·6964·6d37·3935·3522·2074·6162·696e··"#idm7955"·tabin0003c750:·2223·6964·6d37·3935·3522·2074·6162·696e··"#idm7955"·tabin
0003c760:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003c760:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003c770:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003c770:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003c780:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003c780:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003c790:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003c790:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003c7a0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003c7a0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003c7b0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003c7b0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
 0003c7c0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 0003c7d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003c7e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003c7f0:·7365·2220·6964·3d22·6964·6d37·3935·3522··se"·id="idm7955"
 0003c800:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003c810:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003c820:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003c830:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003c840:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003c850:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003c860:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003c870:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003c7c0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003c7d0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003c7e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003c7f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003c800:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
0003c810:·3535·223e·3c70·7265·3e3c·636f·6465·3e0a··55"><pre><code>. 
0003c820:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003c830:·6520·3d20·2263·7279·7074·6f2d·706f·6c69··e·=·"crypto-poli 
0003c840:·6369·6573·220a·7665·7273·696f·6e20·3d20··cies".version·=· 
0003c850:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
0003c860:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003c870:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003c880:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003c890:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003c8a0:·7267·6574·3d22·2369·646d·3739·3536·2220··rget="#idm7956"· 
0003c8b0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003c8c0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003c8d0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003c8e0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003c8f0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003c900:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003c910:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003c920:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003c930:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
Max diff block lines reached; 2883701/2924603 bytes (98.60%) of diff not shown.
350 KB
html2text {}
    
Offset 109, 31 lines modifiedOffset 109, 31 lines modified
109 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode109 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
110 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877110 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
111 ············_\x8i_\x8s_\x8m······1446111 ············_\x8i_\x8s_\x8m······1446
112 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1112 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
113 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12113 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
114 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1114 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176115 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
117 [customizations] 
118 fips·=·true 
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
120 #·Remediation·is·applicable·only·in·certain·platforms117 #·Remediation·is·applicable·only·in·certain·platforms
121 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then118 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
122 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then119 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
123 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF120 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
124 kargs·=·["fips=1"]121 kargs·=·["fips=1"]
125 EOF122 EOF
126 fi123 fi
  
127 else124 else
128 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'125 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
129 fi126 fi
 127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 128 [customizations]
 129 fips·=·true
130 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules130 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules
131 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:131 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
132 ····*·GnuTLS·library132 ····*·GnuTLS·library
133 ····*·OpenSSL·library133 ····*·OpenSSL·library
134 ····*·NSS·library134 ····*·NSS·library
135 ····*·OpenJDK135 ····*·OpenJDK
136 ····*·Libkrb5136 ····*·Libkrb5
Offset 145, 19 lines modifiedOffset 145, 21 lines modified
145 $·sudo·dnf·install·crypto-policies145 $·sudo·dnf·install·crypto-policies
146 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.146 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
147 Severity: ··medium147 Severity: ··medium
148 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed148 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
149 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123149 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
150 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1150 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
151 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174151 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 157 package·install·crypto-policies
153 [[packages]] 
154 name·=·"crypto-policies" 
155 version·=·"*" 
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
161 if·!·rpm·-q·--quiet·"crypto-policies"·;·then163 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 175, 14 lines modifiedOffset 177, 26 lines modified
175 ··tags:177 ··tags:
176 ··-·enable_strategy178 ··-·enable_strategy
177 ··-·low_complexity179 ··-·low_complexity
178 ··-·low_disruption180 ··-·low_disruption
179 ··-·medium_severity181 ··-·medium_severity
180 ··-·no_reboot_needed182 ··-·no_reboot_needed
181 ··-·package_crypto-policies_installed183 ··-·package_crypto-policies_installed
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 package·--add=crypto-policies
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 191 [[packages]]
 192 name·=·"crypto-policies"
 193 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
187 dnf·install·crypto-policies199 dnf·install·crypto-policies
Offset 194, 28 lines modifiedOffset 208, 14 lines modified
194 include·install_crypto-policies208 include·install_crypto-policies
  
195 class·install_crypto-policies·{209 class·install_crypto-policies·{
196 ··package·{·'crypto-policies':210 ··package·{·'crypto-policies':
197 ····ensure·=>·'installed',211 ····ensure·=>·'installed',
198 ··}212 ··}
199 }213 }
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
205 package·install·crypto-policies 
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
211 package·--add=crypto-policies 
212 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
213 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:215 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
214 $·sudo·update-crypto-policies·--set·FIPS:OSPP216 $·sudo·update-crypto-policies·--set·FIPS:OSPP
215 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.217 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
216 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.218 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
217 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.219 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
218 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.220 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 245, 14 lines modifiedOffset 245, 39 lines modified
245 »       echo·"to·see·what·package·to·(re)install"·>&2245 »       echo·"to·see·what·package·to·(re)install"·>&2
  
246 »       false··#·end·with·an·error·code246 »       false··#·end·with·an·error·code
247 elif·test·"$rc"·!=·0;·then247 elif·test·"$rc"·!=·0;·then
248 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2248 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
249 »       false··#·end·with·an·error·code249 »       false··#·end·with·an·error·code
250 fi250 fi
 251 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 252 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 253 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 349857/358402 bytes (97.62%) of diff not shown.
2.69 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-pci-dss.html
    
Offset 16715, 278 lines modifiedOffset 16715, 278 lines modified
000414a0:·6574·3d22·2369·646d·3733·3331·2220·7461··et="#idm7331"·ta000414a0:·6574·3d22·2369·646d·3733·3331·2220·7461··et="#idm7331"·ta
000414b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=000414b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
000414c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex000414c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
000414d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t000414d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
000414e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t000414e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
000414f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="000414f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00041500:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00041500:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00041510:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
00041520:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
00041530:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00041540:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00041550:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00041560:·6d37·3333·3122·3e3c·7072·653e·3c63·6f64··m7331"><pre><cod 
00041570:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
00041580:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
00041590:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
000415a0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
000415b0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
000415c0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
000415d0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
000415e0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
000415f0:·646d·3733·3332·2220·7461·6269·6e64·6578··dm7332"·tabindex 
00041600:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00041610:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00041620:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00041630:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
00041640:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
00041650:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
00041660:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b00041510:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
00041670:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00041520:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00041680:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00041530:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00041690:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm7300041540:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73
000416a0:·3332·223e·3c74·6162·6c65·2063·6c61·7373··32"><table·class00041550:·3331·223e·3c74·6162·6c65·2063·6c61·7373··31"><table·class
000416b0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00041560:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
000416c0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00041570:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
000416d0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde00041580:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
000416e0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00041590:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
000416f0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t000415a0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00041700:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><000415b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00041710:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio000415c0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00041720:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</000415d0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00041730:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>000415e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00041740:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>000415f0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
00041750:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><00041600:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
00041760:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00041610:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
00041770:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<00041620:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
00041780:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table00041630:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
00041790:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re00041640:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 00041650:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
000417a0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
000417b0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
000417c0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
000417d0:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
000417e0:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
000417f0:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
00041800:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
00041810:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
00041820:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
00041830:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
00041840:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
00041850:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
00041860:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
00041870:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
00041880:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d00041660:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
00041890:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn00041670:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
000418a0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da00041680:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
000418b0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla00041690:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
000418c0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target000416a0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
000418d0:·3d22·2369·646d·3733·3333·2220·7461·6269··="#idm7333"·tabi000416b0:·6574·3d22·2369·646d·3733·3332·2220·7461··et="#idm7332"·ta
000418e0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b000416c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
000418f0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa000416d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00041900:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit000416e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00041910:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·000416f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00041920:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00041700:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00041930:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An00041710:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00041940:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
00041950:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00041960:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
00041970:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
00041980:·3d22·6964·6d37·3333·3322·3e3c·7461·626c··="idm7333"><tabl 
00041990:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
000419a0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
000419b0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
000419c0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
000419d0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
000419e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
000419f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00041a00:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00041720:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 00041730:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00041740:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00041750:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00041760:·2269·646d·3733·3332·223e·3c74·6162·6c65··"idm7332"><table
 00041770:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00041780:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00041790:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 000417a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 000417b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 000417c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 000417d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 000417e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 000417f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00041800:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00041810:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 00041820:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 00041830:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00041a10:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00041840:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
00041a20:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00041a30:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00041a40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00041a50:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00041a60:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00041a70:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00041a80:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
00041a90:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
00041aa0:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
00041ab0:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
00041ac0:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
00041ad0:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
00041ae0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
00041af0:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI 
00041b00:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.·· 
00041b10:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5 
00041b20:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st 
00041b30:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c 
00041b40:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo 
00041b50:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··- 
00041b60:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity 
Max diff block lines reached; 2555693/2592705 bytes (98.57%) of diff not shown.
222 KB
html2text {}
    
Offset 516, 19 lines modifiedOffset 516, 21 lines modified
516 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)516 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
517 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3517 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
518 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5518 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
519 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199519 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
520 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79520 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
521 ············_\x8c_\x8i_\x8s············6.1.1521 ············_\x8c_\x8i_\x8s············6.1.1
522 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2522 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
523 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8523 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 524 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 525 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 526 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 527 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 528 package·install·aide
524 [[packages]] 
525 name·=·"aide" 
526 version·=·"*" 
527 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
528 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
529 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low531 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
530 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false532 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
531 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable533 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
532 #·Remediation·is·applicable·only·in·certain·platforms534 #·Remediation·is·applicable·only·in·certain·platforms
533 if·rpm·--quiet·-q·kernel;·then535 if·rpm·--quiet·-q·kernel;·then
Offset 572, 14 lines modifiedOffset 574, 26 lines modified
572 ··-·PCI-DSSv4-11.5.2574 ··-·PCI-DSSv4-11.5.2
573 ··-·enable_strategy575 ··-·enable_strategy
574 ··-·low_complexity576 ··-·low_complexity
575 ··-·low_disruption577 ··-·low_disruption
576 ··-·medium_severity578 ··-·medium_severity
577 ··-·no_reboot_needed579 ··-·no_reboot_needed
578 ··-·package_aide_installed580 ··-·package_aide_installed
 581 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 582 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 583 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 584 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 585 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 586 package·--add=aide
 587 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 588 [[packages]]
 589 name·=·"aide"
 590 version·=·"*"
579 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8591 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
580 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low592 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
581 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low593 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
582 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false594 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
583 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable595 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
584 dnf·install·aide596 dnf·install·aide
Offset 591, 28 lines modifiedOffset 605, 14 lines modified
591 include·install_aide605 include·install_aide
  
592 class·install_aide·{606 class·install_aide·{
593 ··package·{·'aide':607 ··package·{·'aide':
594 ····ensure·=>·'installed',608 ····ensure·=>·'installed',
595 ··}609 ··}
596 }610 }
597 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
598 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
599 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
600 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
601 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
602 package·install·aide 
603 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
604 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
605 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
606 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
607 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
608 package·--add=aide 
609 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*611 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
610 Run·the·following·command·to·generate·a·new·database:612 Run·the·following·command·to·generate·a·new·database:
611 $·sudo·/usr/sbin/aide·--init613 $·sudo·/usr/sbin/aide·--init
612 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:614 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
613 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz615 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
614 To·initiate·a·manual·check,·run·the·following·command:616 To·initiate·a·manual·check,·run·the·following·command:
615 $·sudo·/usr/sbin/aide·--check617 $·sudo·/usr/sbin/aide·--check
Offset 952, 14 lines modifiedOffset 952, 39 lines modified
952 »       echo·"to·see·what·package·to·(re)install"·>&2952 »       echo·"to·see·what·package·to·(re)install"·>&2
  
953 »       false··#·end·with·an·error·code953 »       false··#·end·with·an·error·code
954 elif·test·"$rc"·!=·0;·then954 elif·test·"$rc"·!=·0;·then
955 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2955 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
956 »       false··#·end·with·an·error·code956 »       false··#·end·with·an·error·code
957 fi957 fi
 958 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 959 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 960 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 961 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 962 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 963 ---
 964 apiVersion:·machineconfiguration.openshift.io/v1
 965 kind:·MachineConfig
 966 spec:
 967 ··config:
 968 ····ignition:
 969 ······version:·3.1.0
 970 ····systemd:
 971 ······units:
 972 ········-·name:·configure-crypto-policy.service
 973 ··········enabled:·true
 974 ··········contents:·|
 975 ············[Unit]
 976 ············Before=kubelet.service
 977 ············[Service]
 978 ············Type=oneshot
 979 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 980 ············RemainAfterExit=yes
 981 ············[Install]
 982 ············WantedBy=multi-user.target
958 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8983 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
959 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low984 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
960 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low985 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
961 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false986 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
962 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict987 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
963 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable988 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
964 ··set_fact:989 ··set_fact:
Offset 1004, 39 lines modifiedOffset 1029, 14 lines modified
1004 ··-·PCI-DSSv4-2.2.71029 ··-·PCI-DSSv4-2.2.7
1005 ··-·configure_crypto_policy1030 ··-·configure_crypto_policy
1006 ··-·high_severity1031 ··-·high_severity
1007 ··-·low_complexity1032 ··-·low_complexity
1008 ··-·low_disruption1033 ··-·low_disruption
1009 ··-·no_reboot_needed1034 ··-·no_reboot_needed
Max diff block lines reached; 222390/227271 bytes (97.85%) of diff not shown.
4.49 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-stig.html
    
Offset 15212, 279 lines modifiedOffset 15212, 279 lines modified
0003b6b0:·7461·7267·6574·3d22·2369·646d·3733·3331··target="#idm73310003b6b0:·7461·7267·6574·3d22·2369·646d·3733·3331··target="#idm7331
0003b6c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b6c0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b6d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b6d0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b6e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b6e0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b6f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b6f0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b700:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b700:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b710:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b710:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b720:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003b730:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003b740:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b750:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b760:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b770:·3d22·6964·6d37·3333·3122·3e3c·7072·653e··="idm7331"><pre> 
0003b780:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003b790:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003b7a0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003b7b0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b7c0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b7d0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b7e0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b7f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b800:·3d22·2369·646d·3733·3332·2220·7461·6269··="#idm7332"·tabi 
0003b810:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b820:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b830:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b840:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b850:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b860:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003b870:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</0003b720:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</
0003b880:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b730:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b890:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b740:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b8a0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b750:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b8b0:·646d·3733·3332·223e·3c74·6162·6c65·2063··dm7332"><table·c0003b760:·646d·3733·3331·223e·3c74·6162·6c65·2063··dm7331"><table·c
0003b8c0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b770:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b8d0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b780:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b8e0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b790:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b8f0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b7a0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b900:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b7b0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b910:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b920:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b930:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b940:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b950:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b960:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b970:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b980:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b990:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b9a0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b9b0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003b9c0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003b9d0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003b9e0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q 
0003b9f0:·7569·6574·202d·7120·6b65·726e·656c·3b20··uiet·-q·kernel;· 
0003ba00:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003ba10:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003ba20:·203b·2074·6865·6e0a·2020·2020·646e·6620···;·then.····dnf· 
0003ba30:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003ba40:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003ba50:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003ba60:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003ba70:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003ba80:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003ba90:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003baa0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003bab0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003bac0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003bad0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003bae0:·7267·6574·3d22·2369·646d·3733·3333·2220··rget="#idm7333"· 
0003baf0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003bb00:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003bb10:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003bb20:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003bb30:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003bb40:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003bb50:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003bb60:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003bb70:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003bb80:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003bb90:·2220·6964·3d22·6964·6d37·3333·3322·3e3c··"·id="idm7333">< 
0003bba0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003bbb0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003bbc0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003bbd0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003bbe0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003bbf0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003bc00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bc10:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003bc20:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b7c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003bc30:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003b7d0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bc40:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003b7e0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003bc50:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b7f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bc60:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003bc70:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003bc80:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003bc90:·3e3c·636f·6465·3e2d·206e·616d·653a·2047··><code>-·name:·G 
0003bca0:·6174·6865·7220·7468·6520·7061·636b·6167··ather·the·packag 
0003bcb0:·6520·6661·6374·730a·2020·7061·636b·6167··e·facts.··packag 
0003bcc0:·655f·6661·6374·733a·0a20·2020·206d·616e··e_facts:.····man 
0003bcd0:·6167·6572·3a20·6175·746f·0a20·2074·6167··ager:·auto.··tag 
0003bce0:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10 
0003bcf0:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80 
0003bd00:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
0003bd10:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11. 
0003bd20:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4- 
0003bd30:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl 
0003bd40:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l 
0003bd50:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.·· 
0003bd60:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption 
0003bd70:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve 
0003bd80:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo 
0003bd90:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa 
0003bda0:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta 
0003bdb0:·6c6c·6564·0a0a·2d20·6e61·6d65·3a20·456e··lled..-·name:·En 
0003bdc0:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins 
0003bdd0:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package 
0003bde0:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide 
0003bdf0:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres 
0003be00:·656e·740a·2020·7768·656e·3a20·2722·6b65··ent.··when:·'"ke 
0003be10:·726e·656c·2220·696e·2061·6e73·6962·6c65··rnel"·in·ansible 
0003be20:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages'0003b800:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b810:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b820:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b830:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003b840:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003b850:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b860:·0a70·6163·6b61·6765·2069·6e73·7461·6c6c··.package·install
 0003b870:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p
Max diff block lines reached; 4216737/4253887 bytes (99.13%) of diff not shown.
444 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 21 lines modified
122 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)122 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
123 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3123 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
126 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ············_\x8c_\x8i_\x8s············6.1.1127 ············_\x8c_\x8i_\x8s············6.1.1
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 134 package·install·aide
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms140 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel;·then141 if·rpm·--quiet·-q·kernel;·then
Offset 178, 14 lines modifiedOffset 180, 26 lines modified
178 ··-·PCI-DSSv4-11.5.2180 ··-·PCI-DSSv4-11.5.2
179 ··-·enable_strategy181 ··-·enable_strategy
180 ··-·low_complexity182 ··-·low_complexity
181 ··-·low_disruption183 ··-·low_disruption
182 ··-·medium_severity184 ··-·medium_severity
183 ··-·no_reboot_needed185 ··-·no_reboot_needed
184 ··-·package_aide_installed186 ··-·package_aide_installed
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 192 package·--add=aide
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 194 [[packages]]
 195 name·=·"aide"
 196 version·=·"*"
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
190 dnf·install·aide202 dnf·install·aide
Offset 197, 28 lines modifiedOffset 211, 14 lines modified
197 include·install_aide211 include·install_aide
  
198 class·install_aide·{212 class·install_aide·{
199 ··package·{·'aide':213 ··package·{·'aide':
200 ····ensure·=>·'installed',214 ····ensure·=>·'installed',
201 ··}215 ··}
202 }216 }
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
208 package·install·aide 
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
214 package·--add=aide 
215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
216 Run·the·following·command·to·generate·a·new·database:218 Run·the·following·command·to·generate·a·new·database:
217 $·sudo·/usr/sbin/aide·--init219 $·sudo·/usr/sbin/aide·--init
218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
220 To·initiate·a·manual·check,·run·the·following·command:222 To·initiate·a·manual·check,·run·the·following·command:
221 $·sudo·/usr/sbin/aide·--check223 $·sudo·/usr/sbin/aide·--check
Offset 1956, 31 lines modifiedOffset 1956, 31 lines modified
1956 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode1956 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
1957 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008771957 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
1958 ············_\x8i_\x8s_\x8m······14461958 ············_\x8i_\x8s_\x8m······1446
1959 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11959 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1960 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121960 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1961 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11961 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1962 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761962 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1963 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1964 [customizations] 
1965 fips·=·true 
1966 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81963 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1967 #·Remediation·is·applicable·only·in·certain·platforms1964 #·Remediation·is·applicable·only·in·certain·platforms
1968 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then1965 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
1969 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1966 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1970 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1967 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1971 kargs·=·["fips=1"]1968 kargs·=·["fips=1"]
1972 EOF1969 EOF
1973 fi1970 fi
  
1974 else1971 else
1975 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1972 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1976 fi1973 fi
 1974 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1975 [customizations]
 1976 fips·=·true
1977 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1977 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1978 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·10·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1978 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·10·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1979 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1979 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1980 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1980 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1981 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1981 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
1982 Severity: ··high1982 Severity: ··high
1983 Rule·ID:····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled1983 Rule·ID:····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled
Offset 2015, 19 lines modifiedOffset 2015, 21 lines modified
2015 $·sudo·dnf·install·crypto-policies2015 $·sudo·dnf·install·crypto-policies
2016 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.2016 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
2017 Severity: ··medium2017 Severity: ··medium
2018 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed2018 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
2019 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-0031232019 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
2020 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.12020 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
2021 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001742021 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
2022 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82022 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 2023 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2024 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 446072/454407 bytes (98.17%) of diff not shown.
4.4 MB
./usr/share/doc/ssg-nondebian/ssg-cs10-guide-stig_gui.html
    
Offset 15207, 279 lines modifiedOffset 15207, 279 lines modified
0003b660:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm730003b660:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73
0003b670:·3331·2220·7461·6269·6e64·6578·3d22·3022··31"·tabindex="0"0003b670:·3331·2220·7461·6269·6e64·6578·3d22·3022··31"·tabindex="0"
0003b680:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b680:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003b690:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b690:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003b6a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b6a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003b6b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b6b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003b6c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b6c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003b6d0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003b6e0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003b6f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b700:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b710:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b720:·6964·3d22·6964·6d37·3333·3122·3e3c·7072··id="idm7331"><pr 
0003b730:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003b740:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003b750:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003b760:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003b770:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b780:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b790:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b7a0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b7b0:·6574·3d22·2369·646d·3733·3332·2220·7461··et="#idm7332"·ta 
0003b7c0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b7d0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b7e0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b7f0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b800:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b810:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b820:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...0003b6d0:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
0003b830:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b6e0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003b840:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b6f0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003b850:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b700:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003b860:·2269·646d·3733·3332·223e·3c74·6162·6c65··"idm7332"><table0003b710:·2269·646d·3733·3331·223e·3c74·6162·6c65··"idm7331"><table
0003b870:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003b720:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003b880:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003b730:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003b890:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003b740:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003b8a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003b750:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003b8b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003b760:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003b8c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003b770:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b8d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003b780:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003b8e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003b790:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b8f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b7a0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b900:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003b7b0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003b910:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003b7c0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003b920:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003b7d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003b930:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003b7e0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b940:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003b7f0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003b950:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003b800:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003b810:·653e·0a70·6163·6b61·6765·2069·6e73·7461··e>.package·insta
 0003b820:·6c6c·2061·6964·650a·3c2f·636f·6465·3e3c··ll·aide.</code><
0003b960:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003b970:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003b980:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003b990:·6174·666f·726d·730a·6966·2072·706d·202d··atforms.if·rpm·- 
0003b9a0:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel 
0003b9b0:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm 
0003b9c0:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid 
0003b9d0:·6522·203b·2074·6865·6e0a·2020·2020·646e··e"·;·then.····dn 
0003b9e0:·6620·696e·7374·616c·6c20·2d79·2022·6169··f·install·-y·"ai 
0003b9f0:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.··· 
0003ba00:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003ba10:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003ba20:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003ba30:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003ba40:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003ba50:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003b830:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0003ba60:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003b840:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0003ba70:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003b850:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0003ba80:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003b860:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0003ba90:·7461·7267·6574·3d22·2369·646d·3733·3333··target="#idm73330003b870:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73
0003baa0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b880:·3332·2220·7461·6269·6e64·6578·3d22·3022··32"·tabindex="0"
0003bab0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b890:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003bac0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b8a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003bad0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b8b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003bae0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b8c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003baf0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b8d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003b8e0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 0003b8f0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 0003b900:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b910:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b920:·6522·2069·643d·2269·646d·3733·3332·223e··e"·id="idm7332">
 0003b930:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b940:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003bb00:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003bb10:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003bb20:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003bb30:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003bb40:·7365·2220·6964·3d22·6964·6d37·3333·3322··se"·id="idm7333" 
0003bb50:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003bb60:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003bb70:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003bb80:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003b950:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003bb90:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003bba0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003bbb0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003bbc0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003bbd0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003bbe0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003bbf0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003b960:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b970:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b980:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b990:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b9a0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b9b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b9c0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b9d0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b9e0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b9f0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003ba00:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003ba10:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003ba20:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0003ba30:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0003ba40:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0003ba50:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0003ba60:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 0003ba70:·6b65·726e·656c·3b20·7468·656e·0a0a·6966··kernel;·then..if
 0003ba80:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie
 0003ba90:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then.
 0003baa0:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install·
 0003bab0:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el
 0003bac0:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
 0003bad0:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
 0003bae0:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
 0003baf0:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
 0003bb00:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
 0003bb10:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003bb20:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
Max diff block lines reached; 4130744/4167894 bytes (99.11%) of diff not shown.
435 KB
html2text {}
    
Offset 121, 19 lines modifiedOffset 121, 21 lines modified
121 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)121 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
126 ············_\x8c_\x8i_\x8s············6.1.1126 ············_\x8c_\x8i_\x8s············6.1.1
127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 133 package·install·aide
129 [[packages]] 
130 name·=·"aide" 
131 version·=·"*" 
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
137 #·Remediation·is·applicable·only·in·certain·platforms139 #·Remediation·is·applicable·only·in·certain·platforms
138 if·rpm·--quiet·-q·kernel;·then140 if·rpm·--quiet·-q·kernel;·then
Offset 177, 14 lines modifiedOffset 179, 26 lines modified
177 ··-·PCI-DSSv4-11.5.2179 ··-·PCI-DSSv4-11.5.2
178 ··-·enable_strategy180 ··-·enable_strategy
179 ··-·low_complexity181 ··-·low_complexity
180 ··-·low_disruption182 ··-·low_disruption
181 ··-·medium_severity183 ··-·medium_severity
182 ··-·no_reboot_needed184 ··-·no_reboot_needed
183 ··-·package_aide_installed185 ··-·package_aide_installed
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 191 package·--add=aide
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 193 [[packages]]
 194 name·=·"aide"
 195 version·=·"*"
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
189 dnf·install·aide201 dnf·install·aide
Offset 196, 28 lines modifiedOffset 210, 14 lines modified
196 include·install_aide210 include·install_aide
  
197 class·install_aide·{211 class·install_aide·{
198 ··package·{·'aide':212 ··package·{·'aide':
199 ····ensure·=>·'installed',213 ····ensure·=>·'installed',
200 ··}214 ··}
201 }215 }
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
207 package·install·aide 
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
213 package·--add=aide 
214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
215 Run·the·following·command·to·generate·a·new·database:217 Run·the·following·command·to·generate·a·new·database:
216 $·sudo·/usr/sbin/aide·--init218 $·sudo·/usr/sbin/aide·--init
217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz220 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
219 To·initiate·a·manual·check,·run·the·following·command:221 To·initiate·a·manual·check,·run·the·following·command:
220 $·sudo·/usr/sbin/aide·--check222 $·sudo·/usr/sbin/aide·--check
Offset 1955, 31 lines modifiedOffset 1955, 31 lines modified
1955 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode1955 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
1956 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008771956 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
1957 ············_\x8i_\x8s_\x8m······14461957 ············_\x8i_\x8s_\x8m······1446
1958 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11958 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1959 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121959 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1960 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11960 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1961 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761961 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1962 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1963 [customizations] 
1964 fips·=·true 
1965 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81962 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1966 #·Remediation·is·applicable·only·in·certain·platforms1963 #·Remediation·is·applicable·only·in·certain·platforms
1967 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then1964 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
1968 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1965 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1969 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1966 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1970 kargs·=·["fips=1"]1967 kargs·=·["fips=1"]
1971 EOF1968 EOF
1972 fi1969 fi
  
1973 else1970 else
1974 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1971 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1975 fi1972 fi
 1973 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1974 [customizations]
 1975 fips·=·true
1976 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1976 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1977 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·10·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1977 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·10·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1978 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1978 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1979 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1979 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1980 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1980 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
1981 Severity: ··high1981 Severity: ··high
1982 Rule·ID:····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled1982 Rule·ID:····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled
Offset 2014, 19 lines modifiedOffset 2014, 21 lines modified
2014 $·sudo·dnf·install·crypto-policies2014 $·sudo·dnf·install·crypto-policies
2015 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.2015 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
2016 Severity: ··medium2016 Severity: ··medium
2017 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed2017 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
2018 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-0031232018 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
2019 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.12019 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
2020 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001742020 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
2021 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82021 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 2022 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2023 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 436633/444968 bytes (98.13%) of diff not shown.
3.08 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_enhanced.html
    
Offset 15181, 283 lines modifiedOffset 15181, 283 lines modified
0003b4c0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b4c0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b4d0:·3d22·2369·646d·3834·3830·2220·7461·6269··="#idm8480"·tabi0003b4d0:·3d22·2369·646d·3834·3830·2220·7461·6269··="#idm8480"·tabi
0003b4e0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b4e0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b4f0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b4f0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b500:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b500:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b510:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b510:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b520:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b520:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b530:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003b530:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
0003b540:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003b550:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b560:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b570:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b580:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003b590:·3438·3022·3e3c·7072·653e·3c63·6f64·653e··480"><pre><code> 
0003b5a0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003b5b0:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003b5c0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003b5d0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b5e0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b5f0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b600:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b610:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b620:·3834·3831·2220·7461·6269·6e64·6578·3d22··8481"·tabindex=" 
0003b630:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b640:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b650:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b660:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b670:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b680:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b690:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0003b540:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
0003b6a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b550:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003b6b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b560:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003b6c0:·7073·6522·2069·643d·2269·646d·3834·3831··pse"·id="idm84810003b570:·7073·6522·2069·643d·2269·646d·3834·3830··pse"·id="idm8480
0003b6d0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b580:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003b6e0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b590:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003b6f0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b5a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003b700:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b5b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003b710:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b5c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003b720:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b5d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003b730:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b5e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b740:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b5f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003b750:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b600:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b760:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b610:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003b770:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b620:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b780:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b630:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003b790:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b640:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003b7a0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b650:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003b7b0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b660:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003b7c0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme0003b670:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003b680:·6765·2069·6e73·7461·6c6c·2061·6964·650a··ge·install·aide.
0003b7d0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b7e0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b7f0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b800:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003b810:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then.. 
0003b820:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b830:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b840:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal 
0003b850:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b860:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b870:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b880:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b890:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b8a0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b8b0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003b690:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003b8c0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003b6a0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003b8d0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003b6b0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003b8e0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003b6c0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003b8f0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b6d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b900:·2369·646d·3834·3832·2220·7461·6269·6e64··#idm8482"·tabind0003b6e0:·3d22·2369·646d·3834·3831·2220·7461·6269··="#idm8481"·tabi
0003b910:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b6f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b920:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b700:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b930:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b710:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b940:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b720:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b950:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b730:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b960:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003b740:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003b750:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003b760:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b770:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b780:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b790:·646d·3834·3831·223e·3c74·6162·6c65·2063··dm8481"><table·c
 0003b7a0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b970:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b980:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b990:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b9a0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b9b0:·6964·6d38·3438·3222·3e3c·7461·626c·6520··idm8482"><table· 
0003b9c0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b9d0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b9e0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b7b0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b7c0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b7d0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b7e0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b7f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b800:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003b9f0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003ba00:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003ba10:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003ba20:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003ba30:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003ba40:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003ba50:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003ba60:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003ba70:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003ba80:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003ba90:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003baa0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003bab0:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather· 
0003bac0:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact 
0003bad0:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact 
0003bae0:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:· 
0003baf0:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··- 
0003bb00:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003bb10:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE 
0003bb20:·4c2d·3039·2d36·3531·3031·300a·2020·2d20··L-09-651010.··-· 
0003bb30:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003bb40:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003bb50:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003bb60:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003bb70:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003bb80:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003bb90:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003bba0:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003bbb0:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003bbc0:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003bbd0:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003bbe0:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
Max diff block lines reached; 2956075/2993777 bytes (98.74%) of diff not shown.
227 KB
html2text {}
    
Offset 119, 19 lines modifiedOffset 119, 21 lines modified
119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
123 ············_\x8c_\x8i_\x8s············6.1.1123 ············_\x8c_\x8i_\x8s············6.1.1
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
125 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule125 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 131 package·install·aide
127 [[packages]] 
128 name·=·"aide" 
129 version·=·"*" 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
135 #·Remediation·is·applicable·only·in·certain·platforms137 #·Remediation·is·applicable·only·in·certain·platforms
136 if·rpm·--quiet·-q·kernel;·then138 if·rpm·--quiet·-q·kernel;·then
Offset 177, 14 lines modifiedOffset 179, 26 lines modified
177 ··-·PCI-DSSv4-11.5.2179 ··-·PCI-DSSv4-11.5.2
178 ··-·enable_strategy180 ··-·enable_strategy
179 ··-·low_complexity181 ··-·low_complexity
180 ··-·low_disruption182 ··-·low_disruption
181 ··-·medium_severity183 ··-·medium_severity
182 ··-·no_reboot_needed184 ··-·no_reboot_needed
183 ··-·package_aide_installed185 ··-·package_aide_installed
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 191 package·--add=aide
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 193 [[packages]]
 194 name·=·"aide"
 195 version·=·"*"
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
189 dnf·install·aide201 dnf·install·aide
Offset 196, 28 lines modifiedOffset 210, 14 lines modified
196 include·install_aide210 include·install_aide
  
197 class·install_aide·{211 class·install_aide·{
198 ··package·{·'aide':212 ··package·{·'aide':
199 ····ensure·=>·'installed',213 ····ensure·=>·'installed',
200 ··}214 ··}
201 }215 }
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
207 package·install·aide 
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
213 package·--add=aide 
214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
215 Run·the·following·command·to·generate·a·new·database:217 Run·the·following·command·to·generate·a·new·database:
216 $·sudo·/usr/sbin/aide·--init218 $·sudo·/usr/sbin/aide·--init
217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz220 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
219 To·initiate·a·manual·check,·run·the·following·command:221 To·initiate·a·manual·check,·run·the·following·command:
220 $·sudo·/usr/sbin/aide·--check222 $·sudo·/usr/sbin/aide·--check
Offset 368, 50 lines modifiedOffset 368, 50 lines modified
368 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3368 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
369 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)369 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
370 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4370 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
371 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227371 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
372 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28372 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
373 ············_\x8c_\x8i_\x8s············1.1.2.3.1373 ············_\x8c_\x8i_\x8s············1.1.2.3.1
374 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule374 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
376 [[customizations.filesystem]] 
377 mountpoint·=·"/home" 
378 size·=·1073741824 
379 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
380 logvol·/home·1024376 logvol·/home·1024
381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
382 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low378 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
383 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high379 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
384 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false380 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
385 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable381 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
386 part·/home382 part·/home
 383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 384 [[customizations.filesystem]]
 385 mountpoint·=·"/home"
 386 size·=·1073741824
387 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*387 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
388 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.388 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
389 Rationale:··Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.389 Rationale:··Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
390 Severity: ··unknown390 Severity: ··unknown
391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_srv391 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_srv
392 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28392 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
394 [[customizations.filesystem]] 
395 mountpoint·=·"/srv" 
396 size·=·1073741824 
397 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
398 logvol·/srv·1024394 logvol·/srv·1024
399 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8395 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
400 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low396 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
401 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high397 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
402 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false398 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
403 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable399 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 226845/232802 bytes (97.44%) of diff not shown.
3.19 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_high.html
    
Offset 15187, 282 lines modifiedOffset 15187, 282 lines modified
0003b520:·6765·743d·2223·6964·6d38·3438·3022·2074··get="#idm8480"·t0003b520:·6765·743d·2223·6964·6d38·3438·3022·2074··get="#idm8480"·t
0003b530:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b530:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b540:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b540:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b550:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b550:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b560:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b560:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b570:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b570:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b580:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b580:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b590:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003b5a0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003b5b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b5c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b5d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b5e0:·646d·3834·3830·223e·3c70·7265·3e3c·636f··dm8480"><pre><co 
0003b5f0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003b600:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003b610:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003b620:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b630:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b640:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b650:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b660:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b670:·6964·6d38·3438·3122·2074·6162·696e·6465··idm8481"·tabinde 
0003b680:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b690:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b6a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b6b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b6c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b6d0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b6e0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><0003b590:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003b6f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b5a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b700:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b5b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b710:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003b5c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003b720:·3438·3122·3e3c·7461·626c·6520·636c·6173··481"><table·clas0003b5d0:·3438·3022·3e3c·7461·626c·6520·636c·6173··480"><table·clas
0003b730:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b5e0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b740:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b5f0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b750:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b600:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b760:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b610:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b770:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b620:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b780:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b630:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b790:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003b640:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b7a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003b650:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b7b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b660:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b7c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b670:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b7d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b680:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b7e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b690:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b7f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003b6a0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003b800:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003b6b0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b810:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R0003b6c0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003b6d0:·636b·6167·6520·696e·7374·616c·6c20·6169··ckage·install·ai
0003b820:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b830:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b840:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b850:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003b860:·7420·2d71·206b·6572·6e65·6c3b·2074·6865··t·-q·kernel;·the 
0003b870:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003b880:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003b890:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins 
0003b8a0:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003b8b0:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003b8c0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b8d0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b8e0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b8f0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b900:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003b6e0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>
0003b910:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003b6f0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003b920:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003b700:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003b930:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003b710:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003b940:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b720:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003b950:·743d·2223·6964·6d38·3438·3222·2074·6162··t="#idm8482"·tab0003b730:·6765·743d·2223·6964·6d38·3438·3122·2074··get="#idm8481"·t
0003b960:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b740:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b970:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b750:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b980:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b760:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b990:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b770:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b9a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b780:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b9b0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003b790:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b9c0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b9d0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b9e0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b9f0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003ba00:·643d·2269·646d·3834·3832·223e·3c74·6162··d="idm8482"><tab 
0003ba10:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003ba20:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003ba30:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003ba40:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003ba50:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003ba60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003ba70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003ba80:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003b7a0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003b7b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b7c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b7d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b7e0:·3d22·6964·6d38·3438·3122·3e3c·7461·626c··="idm8481"><tabl
 0003b7f0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b800:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b810:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b820:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b830:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b840:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b850:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b860:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b870:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b880:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b890:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b8a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b8b0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003ba90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b8c0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003baa0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003bab0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003bac0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003bad0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003bae0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003baf0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bb00:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003bb10:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f 
0003bb20:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f 
0003bb30:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage 
0003bb40:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:. 
0003bb50:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003bb60:·330a·2020·2d20·4449·5341·2d53·5449·472d··3.··-·DISA-STIG- 
0003bb70:·5248·454c·2d30·392d·3635·3130·3130·0a20··RHEL-09-651010.· 
0003bb80:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0003bb90:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D 
0003bba0:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-· 
0003bbb0:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2 
0003bbc0:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0003bbd0:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0003bbe0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
Max diff block lines reached; 3067003/3104567 bytes (98.79%) of diff not shown.
236 KB
html2text {}
    
Offset 120, 19 lines modifiedOffset 120, 21 lines modified
120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
123 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79123 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
124 ············_\x8c_\x8i_\x8s············6.1.1124 ············_\x8c_\x8i_\x8s············6.1.1
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
126 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule126 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 132 package·install·aide
128 [[packages]] 
129 name·=·"aide" 
130 version·=·"*" 
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
136 #·Remediation·is·applicable·only·in·certain·platforms138 #·Remediation·is·applicable·only·in·certain·platforms
137 if·rpm·--quiet·-q·kernel;·then139 if·rpm·--quiet·-q·kernel;·then
Offset 178, 14 lines modifiedOffset 180, 26 lines modified
178 ··-·PCI-DSSv4-11.5.2180 ··-·PCI-DSSv4-11.5.2
179 ··-·enable_strategy181 ··-·enable_strategy
180 ··-·low_complexity182 ··-·low_complexity
181 ··-·low_disruption183 ··-·low_disruption
182 ··-·medium_severity184 ··-·medium_severity
183 ··-·no_reboot_needed185 ··-·no_reboot_needed
184 ··-·package_aide_installed186 ··-·package_aide_installed
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 192 package·--add=aide
 193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 194 [[packages]]
 195 name·=·"aide"
 196 version·=·"*"
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
190 dnf·install·aide202 dnf·install·aide
Offset 197, 28 lines modifiedOffset 211, 14 lines modified
197 include·install_aide211 include·install_aide
  
198 class·install_aide·{212 class·install_aide·{
199 ··package·{·'aide':213 ··package·{·'aide':
200 ····ensure·=>·'installed',214 ····ensure·=>·'installed',
201 ··}215 ··}
202 }216 }
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
208 package·install·aide 
209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
214 package·--add=aide 
215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
216 Run·the·following·command·to·generate·a·new·database:218 Run·the·following·command·to·generate·a·new·database:
217 $·sudo·/usr/sbin/aide·--init219 $·sudo·/usr/sbin/aide·--init
218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
220 To·initiate·a·manual·check,·run·the·following·command:222 To·initiate·a·manual·check,·run·the·following·command:
221 $·sudo·/usr/sbin/aide·--check223 $·sudo·/usr/sbin/aide·--check
Offset 881, 50 lines modifiedOffset 881, 50 lines modified
881 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3881 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
882 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)882 References:·_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
883 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4883 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
884 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227884 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
885 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28885 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
886 ············_\x8c_\x8i_\x8s············1.1.2.3.1886 ············_\x8c_\x8i_\x8s············1.1.2.3.1
887 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule887 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
889 [[customizations.filesystem]] 
890 mountpoint·=·"/home" 
891 size·=·1073741824 
892 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
893 logvol·/home·1024889 logvol·/home·1024
894 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
895 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
896 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high892 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
897 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false893 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
898 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable894 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
899 part·/home895 part·/home
 896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 897 [[customizations.filesystem]]
 898 mountpoint·=·"/home"
 899 size·=·1073741824
900 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*900 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
901 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.901 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
902 Rationale:··Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.902 Rationale:··Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
903 Severity: ··unknown903 Severity: ··unknown
904 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_srv904 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_srv
905 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28905 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
907 [[customizations.filesystem]] 
908 mountpoint·=·"/srv" 
909 size·=·1073741824 
910 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
911 logvol·/srv·1024907 logvol·/srv·1024
912 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8908 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
913 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low909 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
914 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high910 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
915 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false911 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
916 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable912 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
Max diff block lines reached; 235337/241294 bytes (97.53%) of diff not shown.
1.88 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_intermediary.html
    
Offset 15177, 283 lines modifiedOffset 15177, 283 lines modified
0003b480:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b480:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b490:·6964·6d38·3438·3022·2074·6162·696e·6465··idm8480"·tabinde0003b490:·6964·6d38·3438·3022·2074·6162·696e·6465··idm8480"·tabinde
0003b4a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b4a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b4b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b4b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b4c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b4c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b4d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b4d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b4e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b4e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b4f0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003b4f0:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
0003b500:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003b510:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b520:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b530:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b540:·7073·6522·2069·643d·2269·646d·3834·3830··pse"·id="idm8480 
0003b550:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003b560:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003b570:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003b580:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003b590:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b5a0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b5b0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b5c0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b5d0:·2d74·6172·6765·743d·2223·6964·6d38·3438··-target="#idm848 
0003b5e0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
0003b5f0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b600:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b610:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b620:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b630:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b640:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b650:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003b500:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003b660:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003b510:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003b670:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003b520:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003b680:·2220·6964·3d22·6964·6d38·3438·3122·3e3c··"·id="idm8481"><0003b530:·2220·6964·3d22·6964·6d38·3438·3022·3e3c··"·id="idm8480"><
0003b690:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003b540:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003b6a0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003b550:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003b6b0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003b560:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003b6c0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003b570:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003b6d0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003b580:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b6e0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003b590:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003b6f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b700:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b710:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b720:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b730:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b740:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b750:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b760:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b770:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b780:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003b790:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003b7a0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b7b0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b7c0:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003b7d0:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if· 
0003b7e0:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003b7f0:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003b800:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
0003b810:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003b820:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b830:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b840:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b850:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b860:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b870:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b880:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b890:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b8a0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b8b0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b8c0:·6d38·3438·3222·2074·6162·696e·6465·783d··m8482"·tabindex= 
0003b8d0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b8e0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b8f0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b900:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b910:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b920:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b930:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b940:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b950:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b960:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b970:·3834·3832·223e·3c74·6162·6c65·2063·6c61··8482"><table·cla 
0003b980:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b990:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b9a0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b9b0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b9c0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b9d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b9e0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b9f0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003ba00:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b5a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003ba10:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003ba20:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003ba30:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003b5b0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003b5c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b5d0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003ba40:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl0003b5e0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003b5f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b600:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003b610:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003b620:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b630:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003b640:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c
 0003b650:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003b660:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003b670:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003b680:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003b690:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003b6a0:·6964·6d38·3438·3122·2074·6162·696e·6465··idm8481"·tabinde
 0003b6b0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003b6c0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003b6d0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003b6e0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003b6f0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b700:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
 0003b710:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003b720:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b730:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b740:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 0003b750:·3438·3122·3e3c·7461·626c·6520·636c·6173··481"><table·clas
 0003b760:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b770:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b780:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b790:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b7a0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b7b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b7c0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003ba50:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003ba60:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
Max diff block lines reached; 1780850/1818552 bytes (97.93%) of diff not shown.
149 KB
html2text {}
    
Offset 135, 19 lines modifiedOffset 135, 21 lines modified
135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3135 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5136 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199137 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
138 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79138 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
139 ············_\x8c_\x8i_\x8s············6.1.1139 ············_\x8c_\x8i_\x8s············6.1.1
140 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2140 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
141 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule141 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 147 package·install·aide
143 [[packages]] 
144 name·=·"aide" 
145 version·=·"*" 
146 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
147 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
148 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
149 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
150 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
151 #·Remediation·is·applicable·only·in·certain·platforms153 #·Remediation·is·applicable·only·in·certain·platforms
152 if·rpm·--quiet·-q·kernel;·then154 if·rpm·--quiet·-q·kernel;·then
Offset 193, 14 lines modifiedOffset 195, 26 lines modified
193 ··-·PCI-DSSv4-11.5.2195 ··-·PCI-DSSv4-11.5.2
194 ··-·enable_strategy196 ··-·enable_strategy
195 ··-·low_complexity197 ··-·low_complexity
196 ··-·low_disruption198 ··-·low_disruption
197 ··-·medium_severity199 ··-·medium_severity
198 ··-·no_reboot_needed200 ··-·no_reboot_needed
199 ··-·package_aide_installed201 ··-·package_aide_installed
 202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 207 package·--add=aide
 208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 209 [[packages]]
 210 name·=·"aide"
 211 version·=·"*"
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low213 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low214 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false215 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable216 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
205 dnf·install·aide217 dnf·install·aide
Offset 212, 28 lines modifiedOffset 226, 14 lines modified
212 include·install_aide226 include·install_aide
  
213 class·install_aide·{227 class·install_aide·{
214 ··package·{·'aide':228 ··package·{·'aide':
215 ····ensure·=>·'installed',229 ····ensure·=>·'installed',
216 ··}230 ··}
217 }231 }
218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
223 package·install·aide 
224 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
225 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
226 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
227 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
228 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
229 package·--add=aide 
230 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*232 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
231 Run·the·following·command·to·generate·a·new·database:233 Run·the·following·command·to·generate·a·new·database:
232 $·sudo·/usr/sbin/aide·--init234 $·sudo·/usr/sbin/aide·--init
233 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the235 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
234 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these236 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
235 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their237 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
236 integrity.·The·newly-generated·database·can·be·installed·as·follows:238 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 407, 56 lines modifiedOffset 407, 56 lines modified
407 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3407 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
408 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)408 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
409 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4409 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
410 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227410 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
411 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28411 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
412 ············_\x8c_\x8i_\x8s············1.1.2.3.1412 ············_\x8c_\x8i_\x8s············1.1.2.3.1
413 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule413 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
414 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
415 [[customizations.filesystem]] 
416 mountpoint·=·"/home" 
417 size·=·1073741824 
418 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8414 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
419 logvol·/home·1024415 logvol·/home·1024
420 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8416 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
421 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low417 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
422 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high418 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
423 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false419 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
424 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable420 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
425 part·/home421 part·/home
 422 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 423 [[customizations.filesystem]]
 424 mountpoint·=·"/home"
 425 size·=·1073741824
426 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*426 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
427 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at427 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at
428 installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such428 installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such
429 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the429 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
430 mountpoint·can·instead·be·configured·later.430 mountpoint·can·instead·be·configured·later.
431 ············Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is431 ············Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is
432 Rationale:··mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and432 Rationale:··mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and
433 ············also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data433 ············also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data
434 ············storage.434 ············storage.
435 Severity: ··unknown435 Severity: ··unknown
436 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_srv436 Rule·ID:····xccdf_org.ssgproject.content_rule_partition_for_srv
437 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28437 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R28
438 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
439 [[customizations.filesystem]] 
440 mountpoint·=·"/srv" 
441 size·=·1073741824 
442 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8438 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 147022/152628 bytes (96.33%) of diff not shown.
504 KB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-anssi_bp28_minimal.html
    
Offset 14856, 295 lines modifiedOffset 14856, 295 lines modified
0003a070:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003a070:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003a080:·6964·6d31·3236·3731·2220·7461·6269·6e64··idm12671"·tabind0003a080:·6964·6d31·3236·3731·2220·7461·6269·6e64··idm12671"·tabind
0003a090:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003a090:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003a0a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003a0a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003a0b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003a0b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003a0c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003a0c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003a0d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003a0d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003a0e0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0003a0e0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
 0003a0f0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0003a0f0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003a100:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003a110:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003a120:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003a130:·6170·7365·2220·6964·3d22·6964·6d31·3236··apse"·id="idm126 
0003a140:·3731·223e·3c70·7265·3e3c·636f·6465·3e0a··71"><pre><code>. 
0003a150:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003a160:·6520·3d20·2264·6e66·2d61·7574·6f6d·6174··e·=·"dnf-automat 
0003a170:·6963·220a·7665·7273·696f·6e20·3d20·222a··ic".version·=·"* 
0003a180:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003a190:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003a1a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003a1b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003a1c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003a1d0:·6574·3d22·2369·646d·3132·3637·3222·2074··et="#idm12672"·t 
0003a1e0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003a1f0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003a200:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003a210:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003a220:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003a230:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003a240:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003a250:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003a260:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003a270:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003a280:·3d22·6964·6d31·3236·3732·223e·3c74·6162··="idm12672"><tab 
0003a290:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003a100:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003a2a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003a2b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003a2c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003a2d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003a110:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003a120:·6522·2069·643d·2269·646d·3132·3637·3122··e"·id="idm12671"
 0003a130:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003a140:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003a150:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003a160:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003a170:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003a180:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003a190:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003a1a0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003a2e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003a1b0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003a2f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003a300:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003a310:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003a320:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003a330:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003a340:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003a1c0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003a1d0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003a350:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003a360:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003a370:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003a380:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0003a390:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0003a3a0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0003a3b0:·706c·6174·666f·726d·730a·6966·2021·2028··platforms.if·!·( 
0003a3c0:·207b·2072·706d·202d·2d71·7569·6574·202d···{·rpm·--quiet·- 
0003a3d0:·7120·6b65·726e·656c·203b·7d20·2661·6d70··q·kernel·;}·&amp 
0003a3e0:·3b26·616d·703b·207b·2072·706d·202d·2d71··;&amp;·{·rpm·--q 
0003a3f0:·7569·6574·202d·7120·7270·6d2d·6f73·7472··uiet·-q·rpm-ostr 
0003a400:·6565·203b·7d20·2661·6d70·3b26·616d·703b··ee·;}·&amp;&amp; 
0003a410:·207b·2072·706d·202d·2d71·7569·6574·202d···{·rpm·--quiet·- 
0003a420:·7120·626f·6f74·6320·3b7d·2026·616d·703b··q·bootc·;}·&amp; 
0003a430:·2661·6d70·3b20·7b20·2120·7270·6d20·2d2d··&amp;·{·!·rpm·-- 
0003a440:·7175·6965·7420·2d71·206f·7065·6e73·6869··quiet·-q·openshi 
0003a450:·6674·2d6b·7562·656c·6574·203b·7d20·293b··ft-kubelet·;}·); 
0003a460:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003a470:·2d71·202d·2d71·7569·6574·2022·646e·662d··-q·--quiet·"dnf- 
0003a480:·6175·746f·6d61·7469·6322·203b·2074·6865··automatic"·;·the 
0003a490:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal 
0003a4a0:·6c20·2d79·2022·646e·662d·6175·746f·6d61··l·-y·"dnf-automa 
0003a4b0:·7469·6322·0a66·690a·0a65·6c73·650a·2020··tic".fi..else.·· 
0003a4c0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003a4d0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003a4e0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003a4f0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003a500:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003a510:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003a520:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003a530:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003a540:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003a550:·2d74·6172·6765·743d·2223·6964·6d31·3236··-target="#idm126 
0003a560:·3733·2220·7461·6269·6e64·6578·3d22·3022··73"·tabindex="0" 
0003a570:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003a580:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003a590:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003a5a0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003a5b0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003a5c0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003a5d0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003a5e0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003a5f0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003a600:·6170·7365·2220·6964·3d22·6964·6d31·3236··apse"·id="idm126 
0003a610:·3733·223e·3c74·6162·6c65·2063·6c61·7373··73"><table·class 
0003a620:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003a630:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003a640:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003a650:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003a660:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003a670:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003a680:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003a690:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003a6a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003a1e0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003a6b0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003a6c0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003a6d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003a6e0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003a6f0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003a700:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na 
0003a710:·6d65·3a20·4761·7468·6572·2074·6865·2070··me:·Gather·the·p 
0003a720:·6163·6b61·6765·2066·6163·7473·0a20·2070··ackage·facts.··p 
0003a730:·6163·6b61·6765·5f66·6163·7473·3a0a·2020··ackage_facts:.·· 
0003a740:·2020·6d61·6e61·6765·723a·2061·7574·6f0a····manager:·auto. 
0003a750:·2020·7461·6773·3a0a·2020·2d20·656e·6162····tags:.··-·enab 
0003a760:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-· 
0003a770:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.· 
0003a780:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio 
0003a790:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev 
0003a7a0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb 
Max diff block lines reached; 436306/475664 bytes (91.73%) of diff not shown.
39.4 KB
html2text {}
    
Offset 101, 19 lines modifiedOffset 101, 21 lines modified
101 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade101 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
102 ············suitable·for·automatic,·regular·execution.102 ············suitable·for·automatic,·regular·execution.
103 Severity: ··medium103 Severity: ··medium
104 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed104 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
105 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2105 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
106 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080106 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
107 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61107 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 113 package·install·dnf-automatic
109 [[packages]] 
110 name·=·"dnf-automatic" 
111 version·=·"*" 
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
117 #·Remediation·is·applicable·only·in·certain·platforms119 #·Remediation·is·applicable·only·in·certain·platforms
118 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-120 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 153, 14 lines modifiedOffset 155, 26 lines modified
153 ··tags:155 ··tags:
154 ··-·enable_strategy156 ··-·enable_strategy
155 ··-·low_complexity157 ··-·low_complexity
156 ··-·low_disruption158 ··-·low_disruption
157 ··-·medium_severity159 ··-·medium_severity
158 ··-·no_reboot_needed160 ··-·no_reboot_needed
159 ··-·package_dnf-automatic_installed161 ··-·package_dnf-automatic_installed
 162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 167 package·--add=dnf-automatic
 168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 169 [[packages]]
 170 name·=·"dnf-automatic"
 171 version·=·"*"
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
165 dnf·install·dnf-automatic177 dnf·install·dnf-automatic
Offset 172, 28 lines modifiedOffset 186, 14 lines modified
172 include·install_dnf-automatic186 include·install_dnf-automatic
  
173 class·install_dnf-automatic·{187 class·install_dnf-automatic·{
174 ··package·{·'dnf-automatic':188 ··package·{·'dnf-automatic':
175 ····ensure·=>·'installed',189 ····ensure·=>·'installed',
176 ··}190 ··}
177 }191 }
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
183 package·install·dnf-automatic 
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·--add=dnf-automatic 
190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
191 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed193 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
192 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/194 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
193 automatic.conf.195 automatic.conf.
194 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation196 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
195 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and197 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
196 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in198 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10205, 14 lines modifiedOffset 10205, 21 lines modified
10205 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,10205 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
10206 ···························A.9.1.210206 ···························A.9.1.2
10207 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)10207 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
10208 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-310208 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
10209 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R6210209 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R62
10210 ············_\x8c_\x8i_\x8s············2.1.310210 ············_\x8c_\x8i_\x8s············2.1.3
10211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.4,·2.210211 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.4,·2.2
 10212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 10213 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10214 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10215 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10216 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10217 package·remove·dhcp-server
10212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10213 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10214 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10215 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10216 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
10217 #·CAUTION:·This·remediation·script·will·remove·dhcp-server10223 #·CAUTION:·This·remediation·script·will·remove·dhcp-server
Offset 10241, 14 lines modifiedOffset 10248, 21 lines modified
10241 ··-·PCI-DSSv4-2.2.410248 ··-·PCI-DSSv4-2.2.4
10242 ··-·disable_strategy10249 ··-·disable_strategy
10243 ··-·low_complexity10250 ··-·low_complexity
10244 ··-·low_disruption10251 ··-·low_disruption
10245 ··-·medium_severity10252 ··-·medium_severity
10246 ··-·no_reboot_needed10253 ··-·no_reboot_needed
10247 ··-·package_dhcp_removed10254 ··-·package_dhcp_removed
 10255 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10256 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10257 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10258 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10259 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10260 package·--remove=dhcp-server
10248 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10249 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10262 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10250 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10263 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10251 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10264 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10252 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10265 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
10253 dnf·remove·dhcp-server10266 dnf·remove·dhcp-server
Offset 10260, 28 lines modifiedOffset 10274, 14 lines modified
10260 include·remove_dhcp-server10274 include·remove_dhcp-server
  
Max diff block lines reached; 35085/40284 bytes (87.09%) of diff not shown.
1.74 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ccn_advanced.html
    
Offset 15295, 189 lines modifiedOffset 15295, 189 lines modified
0003bbe0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003bbe0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003bbf0:·3932·3532·2220·7461·6269·6e64·6578·3d22··9252"·tabindex="0003bbf0:·3932·3532·2220·7461·6269·6e64·6578·3d22··9252"·tabindex="
0003bc00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003bc00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003bc10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003bc10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003bc20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003bc20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003bc30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003bc30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003bc40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003bc40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003bc50:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·0003bc50:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
0003bc60:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003bc70:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003bc80:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003bc90:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9 
0003bca0:·3235·3222·3e3c·7461·626c·6520·636c·6173··252"><table·clas 
0003bcb0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003bcc0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003bcd0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003bce0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003bcf0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003bc60:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
 0003bc70:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003bc80:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003bc90:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003bca0:·646d·3932·3532·223e·3c74·6162·6c65·2063··dm9252"><table·c
 0003bcb0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003bcc0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003bcd0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003bce0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003bcf0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003bd00:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bd10:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003bd20:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003bd00:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bd30:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bd40:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003bd50:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t
0003bd10:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003bd20:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003bd30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bd40:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003bd50:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003bd60:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bd60:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bd70:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003bd70:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003bd80:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003bd80:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003bd90:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003bd90:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003bda0:·3e2d·2d2d·0a61·7069·5665·7273·696f·6e3a··>---.apiVersion:
 0003bdb0:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur
 0003bdc0:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift.
 0003bdd0:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach
 0003bde0:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:.
 0003bdf0:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig
 0003be00:·6e69·7469·6f6e·3a0a·2020·2020·2020·7665··nition:.······ve
 0003be10:·7273·696f·6e3a·2033·2e31·2e30·0a20·2020··rsion:·3.1.0.···
 0003be20:·2073·7973·7465·6d64·3a0a·2020·2020·2020···systemd:.······
 0003be30:·756e·6974·733a·0a20·2020·2020·2020·202d··units:.········-
 0003be40:·206e·616d·653a·2063·6f6e·6669·6775·7265···name:·configure
 0003be50:·2d63·7279·7074·6f2d·706f·6c69·6379·2e73··-crypto-policy.s
 0003be60:·6572·7669·6365·0a20·2020·2020·2020·2020··ervice.·········
 0003be70:·2065·6e61·626c·6564·3a20·7472·7565·0a20···enabled:·true.·
 0003be80:·2020·2020·2020·2020·2063·6f6e·7465·6e74···········content
 0003be90:·733a·207c·0a20·2020·2020·2020·2020·2020··s:·|.···········
 0003bea0:·205b·556e·6974·5d0a·2020·2020·2020·2020···[Unit].········
 0003beb0:·2020·2020·4265·666f·7265·3d6b·7562·656c······Before=kubel
 0003bec0:·6574·2e73·6572·7669·6365·0a20·2020·2020··et.service.·····
 0003bed0:·2020·2020·2020·205b·5365·7276·6963·655d·········[Service]
 0003bee0:·0a20·2020·2020·2020·2020·2020·2054·7970··.············Typ
 0003bef0:·653d·6f6e·6573·686f·740a·2020·2020·2020··e=oneshot.······
 0003bf00:·2020·2020·2020·4578·6563·5374·6172·743d········ExecStart=
 0003bf10:·7570·6461·7465·2d63·7279·7074·6f2d·706f··update-crypto-po
 0003bf20:·6c69·6369·6573·202d·2d73·6574·207b·7b2e··licies·--set·{{.
 0003bf30:·7661·725f·7379·7374·656d·5f63·7279·7074··var_system_crypt
 0003bf40:·6f5f·706f·6c69·6379·7d7d·0a20·2020·2020··o_policy}}.·····
 0003bf50:·2020·2020·2020·2052·656d·6169·6e41·6674·········RemainAft
 0003bf60:·6572·4578·6974·3d79·6573·0a20·2020·2020··erExit=yes.·····
 0003bf70:·2020·2020·2020·205b·496e·7374·616c·6c5d·········[Install]
 0003bf80:·0a20·2020·2020·2020·2020·2020·2057·616e··.············Wan
 0003bf90:·7465·6442·793d·6d75·6c74·692d·7573·6572··tedBy=multi-user
 0003bfa0:·2e74·6172·6765·740a·3c2f·636f·6465·3e3c··.target.</code><
 0003bfb0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003bfc0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003bfd0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003bfe0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003bff0:·612d·7461·7267·6574·3d22·2369·646d·3932··a-target="#idm92
 0003c000:·3533·2220·7461·6269·6e64·6578·3d22·3022··53"·tabindex="0"
 0003c010:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003c020:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003c030:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003c040:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003c050:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c060:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
 0003c070:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003c080:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003c090:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003c0a0:·6170·7365·2220·6964·3d22·6964·6d39·3235··apse"·id="idm925
 0003c0b0:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=
 0003c0c0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003c0d0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003c0e0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003c0f0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003c100:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003c110:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003c120:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003c130:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c140:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003c150:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003c160:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003c170:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003c180:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
 0003c190:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003c1a0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
0003bda0:·206e·616d·653a·2058·4343·4446·2056·616c···name:·XCCDF·Val0003c1b0:·616d·653a·2058·4343·4446·2056·616c·7565··ame:·XCCDF·Value
0003bdb0:·7565·2076·6172·5f73·7973·7465·6d5f·6372··ue·var_system_cr0003c1c0:·2076·6172·5f73·7973·7465·6d5f·6372·7970···var_system_cryp
0003bdc0:·7970·746f·5f70·6f6c·6963·7920·2320·7072··ypto_policy·#·pr0003c1d0:·746f·5f70·6f6c·6963·7920·2320·7072·6f6d··to_policy·#·prom
0003bdd0:·6f6d·6f74·6520·746f·2076·6172·6961·626c··omote·to·variabl0003c1e0:·6f74·6520·746f·2076·6172·6961·626c·650a··ote·to·variable.
0003bde0:·650a·2020·7365·745f·6661·6374·3a0a·2020··e.··set_fact:.··0003c1f0:·2020·7365·745f·6661·6374·3a0a·2020·2020····set_fact:.····
 0003c200:·7661·725f·7379·7374·656d·5f63·7279·7074··var_system_crypt
 0003c210:·6f5f·706f·6c69·6379·3a20·2121·7374·7220··o_policy:·!!str·
 0003c220:·3c61·6262·7220·7469·746c·653d·2266·726f··<abbr·title="fro
 0003c230:·6d20·5072·6f66·696c·652f·7265·6669·6e65··m·Profile/refine
 0003c240:·2d76·616c·7565·3a20·7863·6364·665f·6f72··-value:·xccdf_or
 0003c250:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
 0003c260:·7465·6e74·5f76·616c·7565·5f76·6172·5f73··tent_value_var_s
 0003c270:·7973·7465·6d5f·6372·7970·746f·5f70·6f6c··ystem_crypto_pol
 0003c280:·6963·7922·3e44·4546·4155·4c54·3c2f·6162··icy">DEFAULT</ab
 0003c290:·6272·3e0a·2020·7461·6773·3a0a·2020·2020··br>.··tags:.····
 0003c2a0:·2d20·616c·7761·7973·0a0a·2d20·6e61·6d65··-·always..-·name
 0003c2b0:·3a20·436f·6e66·6967·7572·6520·5379·7374··:·Configure·Syst
 0003c2c0:·656d·2043·7279·7074·6f67·7261·7068·7920··em·Cryptography·
 0003c2d0:·506f·6c69·6379·0a20·206c·696e·6569·6e66··Policy.··lineinf
 0003c2e0:·696c·653a·0a20·2020·2070·6174·683a·202f··ile:.····path:·/
Max diff block lines reached; 1656757/1681487 bytes (98.53%) of diff not shown.
139 KB
html2text {}
    
Offset 139, 14 lines modifiedOffset 139, 39 lines modified
139 »       echo·"to·see·what·package·to·(re)install"·>&2139 »       echo·"to·see·what·package·to·(re)install"·>&2
  
140 »       false··#·end·with·an·error·code140 »       false··#·end·with·an·error·code
141 elif·test·"$rc"·!=·0;·then141 elif·test·"$rc"·!=·0;·then
142 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2142 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
143 »       false··#·end·with·an·error·code143 »       false··#·end·with·an·error·code
144 fi144 fi
 145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 150 ---
 151 apiVersion:·machineconfiguration.openshift.io/v1
 152 kind:·MachineConfig
 153 spec:
 154 ··config:
 155 ····ignition:
 156 ······version:·3.1.0
 157 ····systemd:
 158 ······units:
 159 ········-·name:·configure-crypto-policy.service
 160 ··········enabled:·true
 161 ··········contents:·|
 162 ············[Unit]
 163 ············Before=kubelet.service
 164 ············[Service]
 165 ············Type=oneshot
 166 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 167 ············RemainAfterExit=yes
 168 ············[Install]
 169 ············WantedBy=multi-user.target
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
150 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable175 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
151 ··set_fact:176 ··set_fact:
Offset 197, 39 lines modifiedOffset 222, 14 lines modified
197 ··-·PCI-DSSv4-2.2.7222 ··-·PCI-DSSv4-2.2.7
198 ··-·configure_crypto_policy223 ··-·configure_crypto_policy
199 ··-·high_severity224 ··-·high_severity
200 ··-·low_complexity225 ··-·low_complexity
201 ··-·low_disruption226 ··-·low_disruption
202 ··-·no_reboot_needed227 ··-·no_reboot_needed
203 ··-·restrict_strategy228 ··-·restrict_strategy
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
209 --- 
210 apiVersion:·machineconfiguration.openshift.io/v1 
211 kind:·MachineConfig 
212 spec: 
213 ··config: 
214 ····ignition: 
215 ······version:·3.1.0 
216 ····systemd: 
217 ······units: 
218 ········-·name:·configure-crypto-policy.service 
219 ··········enabled:·true 
220 ··········contents:·| 
221 ············[Unit] 
222 ············Before=kubelet.service 
223 ············[Service] 
224 ············Type=oneshot 
225 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
226 ············RemainAfterExit=yes 
227 ············[Install] 
228 ············WantedBy=multi-user.target 
229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
230 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.230 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
231 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.231 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
232 Severity: ··medium232 Severity: ··medium
233 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy233 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
234 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453234 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
235 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)235 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 1750, 19 lines modifiedOffset 1750, 21 lines modified
1750 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·c\x8cr\x8ry\x8yp\x8pt\x8ts\x8se\x8et\x8tu\x8up\x8p·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1750 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·c\x8cr\x8ry\x8yp\x8pt\x8ts\x8se\x8et\x8tu\x8up\x8p·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1751 The·cryptsetup·package·can·be·installed·with·the·following·command:1751 The·cryptsetup·package·can·be·installed·with·the·following·command:
1752 $·sudo·dnf·install·cryptsetup1752 $·sudo·dnf·install·cryptsetup
1753 Rationale:··LUKS·is·the·upcoming·standard·for·Linux·hard·disk·encryption.·By·providing·a·standard·on-disk·format,·it·does·not·only·facilitate·compatibility·among·distributions,·but·also·provide·secure·management·of·multiple·user·passwords.·In·contrast·to·existing·solution,·LUKS·stores·all·necessary·setup·information·in·the·partition·header,·enabling·the·user·to·transport·or·migrate·their·data·seamlessly.·LUKS·for·dm-crypt·is·implemented·in·cryptsetup.1753 Rationale:··LUKS·is·the·upcoming·standard·for·Linux·hard·disk·encryption.·By·providing·a·standard·on-disk·format,·it·does·not·only·facilitate·compatibility·among·distributions,·but·also·provide·secure·management·of·multiple·user·passwords.·In·contrast·to·existing·solution,·LUKS·stores·all·necessary·setup·information·in·the·partition·header,·enabling·the·user·to·transport·or·migrate·their·data·seamlessly.·LUKS·for·dm-crypt·is·implemented·in·cryptsetup.
1754 Severity: ··medium1754 Severity: ··medium
1755 Rule·ID:····xccdf_org.ssgproject.content_rule_package_cryptsetup-luks_installed1755 Rule·ID:····xccdf_org.ssgproject.content_rule_package_cryptsetup-luks_installed
1756 References:·_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·3.5.1.2,·3.5.1,·3.51756 References:·_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·3.5.1.2,·3.5.1,·3.5
1757 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81757 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1758 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1759 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1760 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1761 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1762 package·install·cryptsetup
1758 [[packages]] 
1759 name·=·"cryptsetup" 
1760 version·=·"*" 
1761 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1762 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1764 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1763 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1765 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1764 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1766 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1765 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1767 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1766 if·!·rpm·-q·--quiet·"cryptsetup"·;·then1768 if·!·rpm·-q·--quiet·"cryptsetup"·;·then
Offset 1783, 14 lines modifiedOffset 1785, 26 lines modified
1783 ··-·PCI-DSSv4-3.5.1.21785 ··-·PCI-DSSv4-3.5.1.2
1784 ··-·enable_strategy1786 ··-·enable_strategy
1785 ··-·low_complexity1787 ··-·low_complexity
1786 ··-·low_disruption1788 ··-·low_disruption
1787 ··-·medium_severity1789 ··-·medium_severity
1788 ··-·no_reboot_needed1790 ··-·no_reboot_needed
1789 ··-·package_cryptsetup-luks_installed1791 ··-·package_cryptsetup-luks_installed
 1792 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1793 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1794 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1795 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1796 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1797 package·--add=cryptsetup
 1798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1799 [[packages]]
 1800 name·=·"cryptsetup"
 1801 version·=·"*"
1790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81802 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1791 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1803 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1792 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1804 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 136620/142254 bytes (96.04%) of diff not shown.
1.28 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ccn_basic.html
    
Offset 15255, 189 lines modifiedOffset 15255, 189 lines modified
0003b960:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b960:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b970:·6d39·3235·3222·2074·6162·696e·6465·783d··m9252"·tabindex=0003b970:·6d39·3235·3222·2074·6162·696e·6465·783d··m9252"·tabindex=
0003b980:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b980:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b990:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b990:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b9a0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b9a0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b9b0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b9b0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b9c0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b9c0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b9d0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible0003b9d0:·6564·6961·7469·6f6e·204b·7562·6572·6e65··ediation·Kuberne
0003b9e0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b9f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003ba00:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003ba10:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003ba20:·3932·3532·223e·3c74·6162·6c65·2063·6c61··9252"><table·cla 
0003ba30:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003ba40:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003ba50:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003ba60:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003ba70:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b9e0:·7465·7320·736e·6970·7065·7420·e287·b23c··tes·snippet·...<
 0003b9f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003ba00:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003ba10:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003ba20:·6964·6d39·3235·3222·3e3c·7461·626c·6520··idm9252"><table·
 0003ba30:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003ba40:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003ba50:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003ba60:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003ba70:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003ba80:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003ba90:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003baa0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003ba80:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bab0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003bac0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003bad0:·3e3c·7464·3e74·7275·653c·2f74·643e·3c2f··><td>true</td></
0003ba90:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003baa0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003bab0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003bac0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003bad0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003bae0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg0003bae0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003baf0:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr0003baf0:·6567·793a·3c2f·7468·3e3c·7464·3e72·6573··egy:</th><td>res
0003bb00:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t0003bb00:·7472·6963·743c·2f74·643e·3c2f·7472·3e3c··trict</td></tr><
0003bb10:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003bb10:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003bb20:·653e·2d2d·2d0a·6170·6956·6572·7369·6f6e··e>---.apiVersion
 0003bb30:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu
 0003bb40:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift
 0003bb50:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac
 0003bb60:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:
 0003bb70:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i
 0003bb80:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v
 0003bb90:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··
 0003bba0:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····
 0003bbb0:·2075·6e69·7473·3a0a·2020·2020·2020·2020···units:.········
 0003bbc0:·2d20·6e61·6d65·3a20·636f·6e66·6967·7572··-·name:·configur
 0003bbd0:·652d·6372·7970·746f·2d70·6f6c·6963·792e··e-crypto-policy.
 0003bbe0:·7365·7276·6963·650a·2020·2020·2020·2020··service.········
 0003bbf0:·2020·656e·6162·6c65·643a·2074·7275·650a····enabled:·true.
 0003bc00:·2020·2020·2020·2020·2020·636f·6e74·656e············conten
 0003bc10:·7473·3a20·7c0a·2020·2020·2020·2020·2020··ts:·|.··········
 0003bc20:·2020·5b55·6e69·745d·0a20·2020·2020·2020····[Unit].·······
 0003bc30:·2020·2020·2042·6566·6f72·653d·6b75·6265·······Before=kube
 0003bc40:·6c65·742e·7365·7276·6963·650a·2020·2020··let.service.····
 0003bc50:·2020·2020·2020·2020·5b53·6572·7669·6365··········[Service
 0003bc60:·5d0a·2020·2020·2020·2020·2020·2020·5479··].············Ty
 0003bc70:·7065·3d6f·6e65·7368·6f74·0a20·2020·2020··pe=oneshot.·····
 0003bc80:·2020·2020·2020·2045·7865·6353·7461·7274·········ExecStart
 0003bc90:·3d75·7064·6174·652d·6372·7970·746f·2d70··=update-crypto-p
 0003bca0:·6f6c·6963·6965·7320·2d2d·7365·7420·7b7b··olicies·--set·{{
 0003bcb0:·2e76·6172·5f73·7973·7465·6d5f·6372·7970··.var_system_cryp
 0003bcc0:·746f·5f70·6f6c·6963·797d·7d0a·2020·2020··to_policy}}.····
 0003bcd0:·2020·2020·2020·2020·5265·6d61·696e·4166··········RemainAf
 0003bce0:·7465·7245·7869·743d·7965·730a·2020·2020··terExit=yes.····
 0003bcf0:·2020·2020·2020·2020·5b49·6e73·7461·6c6c··········[Install
 0003bd00:·5d0a·2020·2020·2020·2020·2020·2020·5761··].············Wa
 0003bd10:·6e74·6564·4279·3d6d·756c·7469·2d75·7365··ntedBy=multi-use
 0003bd20:·722e·7461·7267·6574·0a3c·2f63·6f64·653e··r.target.</code>
 0003bd30:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003bd40:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003bd50:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003bd60:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003bd70:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9
 0003bd80:·3235·3322·2074·6162·696e·6465·783d·2230··253"·tabindex="0
 0003bd90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003bda0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003bdb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003bdc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003bdd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003bde0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
 0003bdf0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003be00:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003be10:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003be20:·6c61·7073·6522·2069·643d·2269·646d·3932··lapse"·id="idm92
 0003be30:·3533·223e·3c74·6162·6c65·2063·6c61·7373··53"><table·class
 0003be40:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003be50:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003be60:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003be70:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003be80:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003be90:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003bea0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003beb0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003bec0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bed0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003bee0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003bef0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003bf00:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric
 0003bf10:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab
 0003bf20:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
0003bb20:·2d20·6e61·6d65·3a20·5843·4344·4620·5661··-·name:·XCCDF·Va0003bf30:·6e61·6d65·3a20·5843·4344·4620·5661·6c75··name:·XCCDF·Valu
0003bb30:·6c75·6520·7661·725f·7379·7374·656d·5f63··lue·var_system_c0003bf40:·6520·7661·725f·7379·7374·656d·5f63·7279··e·var_system_cry
0003bb40:·7279·7074·6f5f·706f·6c69·6379·2023·2070··rypto_policy·#·p0003bf50:·7074·6f5f·706f·6c69·6379·2023·2070·726f··pto_policy·#·pro
0003bb50:·726f·6d6f·7465·2074·6f20·7661·7269·6162··romote·to·variab0003bf60:·6d6f·7465·2074·6f20·7661·7269·6162·6c65··mote·to·variable
0003bb60:·6c65·0a20·2073·6574·5f66·6163·743a·0a20··le.··set_fact:.·0003bf70:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···
0003bb70:·2020·2076·6172·5f73·7973·7465·6d5f·6372·····var_system_cr0003bf80:·2076·6172·5f73·7973·7465·6d5f·6372·7970···var_system_cryp
0003bb80:·7970·746f·5f70·6f6c·6963·793a·2021·2173··ypto_policy:·!!s0003bf90:·746f·5f70·6f6c·6963·793a·2021·2173·7472··to_policy:·!!str
0003bb90:·7472·203c·6162·6272·2074·6974·6c65·3d22··tr·<abbr·title="0003bfa0:·203c·6162·6272·2074·6974·6c65·3d22·6672···<abbr·title="fr
0003bba0:·6672·6f6d·2050·726f·6669·6c65·2f72·6566··from·Profile/ref0003bfb0:·6f6d·2050·726f·6669·6c65·2f72·6566·696e··om·Profile/refin
0003bbb0:·696e·652d·7661·6c75·653a·2078·6363·6466··ine-value:·xccdf0003bfc0:·652d·7661·6c75·653a·2078·6363·6466·5f6f··e-value:·xccdf_o
0003bbc0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject.0003bfd0:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co
0003bbd0:·636f·6e74·656e·745f·7661·6c75·655f·7661··content_value_va0003bfe0:·6e74·656e·745f·7661·6c75·655f·7661·725f··ntent_value_var_
0003bbe0:·725f·7379·7374·656d·5f63·7279·7074·6f5f··r_system_crypto_0003bff0:·7379·7374·656d·5f63·7279·7074·6f5f·706f··system_crypto_po
0003bbf0:·706f·6c69·6379·223e·4445·4641·554c·543c··policy">DEFAULT<0003c000:·6c69·6379·223e·4445·4641·554c·543c·2f61··licy">DEFAULT</a
0003bc00:·2f61·6262·723e·0a20·2074·6167·733a·0a20··/abbr>.··tags:.·0003c010:·6262·723e·0a20·2074·6167·733a·0a20·2020··bbr>.··tags:.···
0003bc10:·2020·202d·2061·6c77·6179·730a·0a2d·206e·····-·always..-·n0003c020:·202d·2061·6c77·6179·730a·0a2d·206e·616d···-·always..-·nam
0003bc20:·616d·653a·2043·6f6e·6669·6775·7265·2053··ame:·Configure·S0003c030:·653a·2043·6f6e·6669·6775·7265·2053·7973··e:·Configure·Sys
0003bc30:·7973·7465·6d20·4372·7970·746f·6772·6170··ystem·Cryptograp0003c040:·7465·6d20·4372·7970·746f·6772·6170·6879··tem·Cryptography
0003bc40:·6879·2050·6f6c·6963·790a·2020·6c69·6e65··hy·Policy.··line0003c050:·2050·6f6c·6963·790a·2020·6c69·6e65·696e···Policy.··linein
0003bc50:·696e·6669·6c65·3a0a·2020·2020·7061·7468··infile:.····path0003c060:·6669·6c65·3a0a·2020·2020·7061·7468·3a20··file:.····path:·
Max diff block lines reached; 1217318/1242048 bytes (98.01%) of diff not shown.
93.3 KB
html2text {}
    
Offset 131, 14 lines modifiedOffset 131, 39 lines modified
131 »       echo·"to·see·what·package·to·(re)install"·>&2131 »       echo·"to·see·what·package·to·(re)install"·>&2
  
132 »       false··#·end·with·an·error·code132 »       false··#·end·with·an·error·code
133 elif·test·"$rc"·!=·0;·then133 elif·test·"$rc"·!=·0;·then
134 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2134 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
135 »       false··#·end·with·an·error·code135 »       false··#·end·with·an·error·code
136 fi136 fi
 137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 142 ---
 143 apiVersion:·machineconfiguration.openshift.io/v1
 144 kind:·MachineConfig
 145 spec:
 146 ··config:
 147 ····ignition:
 148 ······version:·3.1.0
 149 ····systemd:
 150 ······units:
 151 ········-·name:·configure-crypto-policy.service
 152 ··········enabled:·true
 153 ··········contents:·|
 154 ············[Unit]
 155 ············Before=kubelet.service
 156 ············[Service]
 157 ············Type=oneshot
 158 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 159 ············RemainAfterExit=yes
 160 ············[Install]
 161 ············WantedBy=multi-user.target
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
142 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable167 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
143 ··set_fact:168 ··set_fact:
Offset 189, 39 lines modifiedOffset 214, 14 lines modified
189 ··-·PCI-DSSv4-2.2.7214 ··-·PCI-DSSv4-2.2.7
190 ··-·configure_crypto_policy215 ··-·configure_crypto_policy
191 ··-·high_severity216 ··-·high_severity
192 ··-·low_complexity217 ··-·low_complexity
193 ··-·low_disruption218 ··-·low_disruption
194 ··-·no_reboot_needed219 ··-·no_reboot_needed
195 ··-·restrict_strategy220 ··-·restrict_strategy
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
201 --- 
202 apiVersion:·machineconfiguration.openshift.io/v1 
203 kind:·MachineConfig 
204 spec: 
205 ··config: 
206 ····ignition: 
207 ······version:·3.1.0 
208 ····systemd: 
209 ······units: 
210 ········-·name:·configure-crypto-policy.service 
211 ··········enabled:·true 
212 ··········contents:·| 
213 ············[Unit] 
214 ············Before=kubelet.service 
215 ············[Service] 
216 ············Type=oneshot 
217 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
218 ············RemainAfterExit=yes 
219 ············[Install] 
220 ············WantedBy=multi-user.target 
221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
222 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.222 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
223 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.223 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
224 Severity: ··medium224 Severity: ··medium
225 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy225 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
226 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453226 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
227 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)227 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 1116, 14 lines modifiedOffset 1116, 36 lines modified
1116 cat·<<EOF·>/etc/issue1116 cat·<<EOF·>/etc/issue
1117 $formatted1117 $formatted
1118 EOF1118 EOF
  
1119 else1119 else
1120 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1120 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1121 fi1121 fi
 1122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1123 ---
 1124 apiVersion:·machineconfiguration.openshift.io/v1
 1125 kind:·MachineConfig
 1126 metadata:
 1127 ··labels:
 1128 ····machineconfiguration.openshift.io/role:·master
 1129 ····machineconfiguration.openshift.io/role:·worker
 1130 ··name:·75-banner-etc-issue
 1131 spec:
 1132 ··config:
 1133 ····ignition:
 1134 ······version:·3.1.0
 1135 ····storage:
 1136 ······files:
 1137 ······-·contents:
 1138 ··········source:·data:,You%20are%20accessing%20a%20U.S.%20Government%20%28USG%29%20Information%20System%20%28IS%29%20that%20is%20%0Aprovided%20for%20USG-authorized%20use%20only.%20By%20using%20this%20IS%20%28which%20includes%20any%20%0Adevice%20attached%20to%20this%20IS%29%2C%20you%20consent%20to%20the%20following%20conditions%3A%0A%0A-The%20USG%20routinely%20intercepts%20and%20monitors%20communications%20on%20this%20IS%20for%20%0Apurposes%20including%2C%20but%20not%20limited%20to%2C%20penetration%20testing%2C%20COMSEC%20monitoring%2C%20%0Anetwork%20operations%20and%20defense%2C%20personnel%20misconduct%20%28PM%29%2C%20law%20enforcement%20%0A%28LE%29%2C%20and%20counterintelligence%20%28CI%29%20investigations.%0A%0A-At%20any%20time%2C%20the%20USG%20may%20inspect%20and%20seize%20data%20stored%20on%20this%20IS.%0A%0A-
 1139 Communications%20using%2C%20or%20data%20stored%20on%2C%20this%20IS%20are%20not%20private%2C%20are%20subject%20%0Ato%20routine%20monitoring%2C%20interception%2C%20and%20search%2C%20and%20may%20be%20disclosed%20or%20used%20%0Afor%20any%20USG-authorized%20purpose.%0A%0A-This%20IS%20includes%20security%20measures%20%28e.g.%2C%20authentication%20and%20access%20controls%29%20%0Ato%20protect%20USG%20interests--not%20for%20your%20personal%20benefit%20or%20privacy.%0A%0A-
 1140 Notwithstanding%20the%20above%2C%20using%20this%20IS%20does%20not%20constitute%20consent%20to%20PM%2C%20LE%20%0Aor%20CI%20investigative%20searching%20or%20monitoring%20of%20the%20content%20of%20privileged%20%0Acommunications%2C%20or%20work%20product%2C%20related%20to%20personal%20representation%20or%20services%20%0Aby%20attorneys%2C%20psychotherapists%2C%20or%20clergy%2C%20and%20their%20assistants.%20Such%20%0Acommunications%20and%20work%20product%20are%20private%20and%20confidential.%20See%20User%20%0AAgreement%20for%20details.
 1141 ········mode:·0644
 1142 ········path:·/etc/issue.d/legal-notice
 1143 ········overwrite:·true
1122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown1148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
1127 -·name:·Gather·the·package·facts1149 -·name:·Gather·the·package·facts
1128 ··package_facts:1150 ··package_facts:
Offset 1159, 36 lines modifiedOffset 1181, 14 lines modified
1159 ··-·NIST-800-53-AC-8(c)1181 ··-·NIST-800-53-AC-8(c)
1160 ··-·banner_etc_issue1182 ··-·banner_etc_issue
1161 ··-·low_complexity1183 ··-·low_complexity
1162 ··-·medium_disruption1184 ··-·medium_disruption
1163 ··-·medium_severity1185 ··-·medium_severity
1164 ··-·no_reboot_needed1186 ··-·no_reboot_needed
1165 ··-·unknown_strategy1187 ··-·unknown_strategy
1166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1167 --- 
1168 apiVersion:·machineconfiguration.openshift.io/v1 
Max diff block lines reached; 86711/95509 bytes (90.79%) of diff not shown.
1.7 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ccn_intermediate.html
    
Offset 15296, 189 lines modifiedOffset 15296, 189 lines modified
0003bbf0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003bbf0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003bc00:·3932·3532·2220·7461·6269·6e64·6578·3d22··9252"·tabindex="0003bc00:·3932·3532·2220·7461·6269·6e64·6578·3d22··9252"·tabindex="
0003bc10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003bc10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003bc20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003bc20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003bc30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003bc30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003bc40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003bc40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003bc50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003bc50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003bc60:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·0003bc60:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
0003bc70:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003bc80:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003bc90:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003bca0:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9 
0003bcb0:·3235·3222·3e3c·7461·626c·6520·636c·6173··252"><table·clas 
0003bcc0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003bcd0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003bce0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003bcf0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003bd00:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003bc70:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
 0003bc80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003bc90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003bca0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003bcb0:·646d·3932·3532·223e·3c74·6162·6c65·2063··dm9252"><table·c
 0003bcc0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003bcd0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003bce0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003bcf0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003bd00:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003bd10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bd20:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003bd30:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003bd10:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bd40:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bd50:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003bd60:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t
0003bd20:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003bd30:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003bd40:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bd50:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003bd60:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003bd70:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003bd70:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003bd80:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri0003bd80:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest
0003bd90:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta0003bd90:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></
0003bda0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-0003bda0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003bdb0:·3e2d·2d2d·0a61·7069·5665·7273·696f·6e3a··>---.apiVersion:
 0003bdc0:·206d·6163·6869·6e65·636f·6e66·6967·7572···machineconfigur
 0003bdd0:·6174·696f·6e2e·6f70·656e·7368·6966·742e··ation.openshift.
 0003bde0:·696f·2f76·310a·6b69·6e64·3a20·4d61·6368··io/v1.kind:·Mach
 0003bdf0:·696e·6543·6f6e·6669·670a·7370·6563·3a0a··ineConfig.spec:.
 0003be00:·2020·636f·6e66·6967·3a0a·2020·2020·6967····config:.····ig
 0003be10:·6e69·7469·6f6e·3a0a·2020·2020·2020·7665··nition:.······ve
 0003be20:·7273·696f·6e3a·2033·2e31·2e30·0a20·2020··rsion:·3.1.0.···
 0003be30:·2073·7973·7465·6d64·3a0a·2020·2020·2020···systemd:.······
 0003be40:·756e·6974·733a·0a20·2020·2020·2020·202d··units:.········-
 0003be50:·206e·616d·653a·2063·6f6e·6669·6775·7265···name:·configure
 0003be60:·2d63·7279·7074·6f2d·706f·6c69·6379·2e73··-crypto-policy.s
 0003be70:·6572·7669·6365·0a20·2020·2020·2020·2020··ervice.·········
 0003be80:·2065·6e61·626c·6564·3a20·7472·7565·0a20···enabled:·true.·
 0003be90:·2020·2020·2020·2020·2063·6f6e·7465·6e74···········content
 0003bea0:·733a·207c·0a20·2020·2020·2020·2020·2020··s:·|.···········
 0003beb0:·205b·556e·6974·5d0a·2020·2020·2020·2020···[Unit].········
 0003bec0:·2020·2020·4265·666f·7265·3d6b·7562·656c······Before=kubel
 0003bed0:·6574·2e73·6572·7669·6365·0a20·2020·2020··et.service.·····
 0003bee0:·2020·2020·2020·205b·5365·7276·6963·655d·········[Service]
 0003bef0:·0a20·2020·2020·2020·2020·2020·2054·7970··.············Typ
 0003bf00:·653d·6f6e·6573·686f·740a·2020·2020·2020··e=oneshot.······
 0003bf10:·2020·2020·2020·4578·6563·5374·6172·743d········ExecStart=
 0003bf20:·7570·6461·7465·2d63·7279·7074·6f2d·706f··update-crypto-po
 0003bf30:·6c69·6369·6573·202d·2d73·6574·207b·7b2e··licies·--set·{{.
 0003bf40:·7661·725f·7379·7374·656d·5f63·7279·7074··var_system_crypt
 0003bf50:·6f5f·706f·6c69·6379·7d7d·0a20·2020·2020··o_policy}}.·····
 0003bf60:·2020·2020·2020·2052·656d·6169·6e41·6674·········RemainAft
 0003bf70:·6572·4578·6974·3d79·6573·0a20·2020·2020··erExit=yes.·····
 0003bf80:·2020·2020·2020·205b·496e·7374·616c·6c5d·········[Install]
 0003bf90:·0a20·2020·2020·2020·2020·2020·2057·616e··.············Wan
 0003bfa0:·7465·6442·793d·6d75·6c74·692d·7573·6572··tedBy=multi-user
 0003bfb0:·2e74·6172·6765·740a·3c2f·636f·6465·3e3c··.target.</code><
 0003bfc0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 0003bfd0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 0003bfe0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 0003bff0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 0003c000:·612d·7461·7267·6574·3d22·2369·646d·3932··a-target="#idm92
 0003c010:·3533·2220·7461·6269·6e64·6578·3d22·3022··53"·tabindex="0"
 0003c020:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 0003c030:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 0003c040:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 0003c050:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 0003c060:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003c070:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
 0003c080:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003c090:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003c0a0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003c0b0:·6170·7365·2220·6964·3d22·6964·6d39·3235··apse"·id="idm925
 0003c0c0:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=
 0003c0d0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003c0e0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003c0f0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003c100:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003c110:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003c120:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003c130:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003c140:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003c150:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003c160:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003c170:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003c180:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003c190:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict
 0003c1a0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 0003c1b0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
0003bdb0:·206e·616d·653a·2058·4343·4446·2056·616c···name:·XCCDF·Val0003c1c0:·616d·653a·2058·4343·4446·2056·616c·7565··ame:·XCCDF·Value
0003bdc0:·7565·2076·6172·5f73·7973·7465·6d5f·6372··ue·var_system_cr0003c1d0:·2076·6172·5f73·7973·7465·6d5f·6372·7970···var_system_cryp
0003bdd0:·7970·746f·5f70·6f6c·6963·7920·2320·7072··ypto_policy·#·pr0003c1e0:·746f·5f70·6f6c·6963·7920·2320·7072·6f6d··to_policy·#·prom
0003bde0:·6f6d·6f74·6520·746f·2076·6172·6961·626c··omote·to·variabl0003c1f0:·6f74·6520·746f·2076·6172·6961·626c·650a··ote·to·variable.
0003bdf0:·650a·2020·7365·745f·6661·6374·3a0a·2020··e.··set_fact:.··0003c200:·2020·7365·745f·6661·6374·3a0a·2020·2020····set_fact:.····
 0003c210:·7661·725f·7379·7374·656d·5f63·7279·7074··var_system_crypt
 0003c220:·6f5f·706f·6c69·6379·3a20·2121·7374·7220··o_policy:·!!str·
 0003c230:·3c61·6262·7220·7469·746c·653d·2266·726f··<abbr·title="fro
 0003c240:·6d20·5072·6f66·696c·652f·7265·6669·6e65··m·Profile/refine
 0003c250:·2d76·616c·7565·3a20·7863·6364·665f·6f72··-value:·xccdf_or
 0003c260:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
 0003c270:·7465·6e74·5f76·616c·7565·5f76·6172·5f73··tent_value_var_s
 0003c280:·7973·7465·6d5f·6372·7970·746f·5f70·6f6c··ystem_crypto_pol
 0003c290:·6963·7922·3e44·4546·4155·4c54·3c2f·6162··icy">DEFAULT</ab
 0003c2a0:·6272·3e0a·2020·7461·6773·3a0a·2020·2020··br>.··tags:.····
 0003c2b0:·2d20·616c·7761·7973·0a0a·2d20·6e61·6d65··-·always..-·name
 0003c2c0:·3a20·436f·6e66·6967·7572·6520·5379·7374··:·Configure·Syst
 0003c2d0:·656d·2043·7279·7074·6f67·7261·7068·7920··em·Cryptography·
 0003c2e0:·506f·6c69·6379·0a20·206c·696e·6569·6e66··Policy.··lineinf
 0003c2f0:·696c·653a·0a20·2020·2070·6174·683a·202f··ile:.····path:·/
Max diff block lines reached; 1623471/1648201 bytes (98.50%) of diff not shown.
135 KB
html2text {}
    
Offset 139, 14 lines modifiedOffset 139, 39 lines modified
139 »       echo·"to·see·what·package·to·(re)install"·>&2139 »       echo·"to·see·what·package·to·(re)install"·>&2
  
140 »       false··#·end·with·an·error·code140 »       false··#·end·with·an·error·code
141 elif·test·"$rc"·!=·0;·then141 elif·test·"$rc"·!=·0;·then
142 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2142 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
143 »       false··#·end·with·an·error·code143 »       false··#·end·with·an·error·code
144 fi144 fi
 145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 150 ---
 151 apiVersion:·machineconfiguration.openshift.io/v1
 152 kind:·MachineConfig
 153 spec:
 154 ··config:
 155 ····ignition:
 156 ······version:·3.1.0
 157 ····systemd:
 158 ······units:
 159 ········-·name:·configure-crypto-policy.service
 160 ··········enabled:·true
 161 ··········contents:·|
 162 ············[Unit]
 163 ············Before=kubelet.service
 164 ············[Service]
 165 ············Type=oneshot
 166 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 167 ············RemainAfterExit=yes
 168 ············[Install]
 169 ············WantedBy=multi-user.target
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
150 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable175 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
151 ··set_fact:176 ··set_fact:
Offset 197, 39 lines modifiedOffset 222, 14 lines modified
197 ··-·PCI-DSSv4-2.2.7222 ··-·PCI-DSSv4-2.2.7
198 ··-·configure_crypto_policy223 ··-·configure_crypto_policy
199 ··-·high_severity224 ··-·high_severity
200 ··-·low_complexity225 ··-·low_complexity
201 ··-·low_disruption226 ··-·low_disruption
202 ··-·no_reboot_needed227 ··-·no_reboot_needed
203 ··-·restrict_strategy228 ··-·restrict_strategy
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
209 --- 
210 apiVersion:·machineconfiguration.openshift.io/v1 
211 kind:·MachineConfig 
212 spec: 
213 ··config: 
214 ····ignition: 
215 ······version:·3.1.0 
216 ····systemd: 
217 ······units: 
218 ········-·name:·configure-crypto-policy.service 
219 ··········enabled:·true 
220 ··········contents:·| 
221 ············[Unit] 
222 ············Before=kubelet.service 
223 ············[Service] 
224 ············Type=oneshot 
225 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
226 ············RemainAfterExit=yes 
227 ············[Install] 
228 ············WantedBy=multi-user.target 
229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
230 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.230 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
231 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.231 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
232 Severity: ··medium232 Severity: ··medium
233 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy233 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
234 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453234 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
235 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)235 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 2173, 14 lines modifiedOffset 2173, 36 lines modified
2173 cat·<<EOF·>/etc/issue2173 cat·<<EOF·>/etc/issue
2174 $formatted2174 $formatted
2175 EOF2175 EOF
  
2176 else2176 else
2177 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2177 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2178 fi2178 fi
 2179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2180 ---
 2181 apiVersion:·machineconfiguration.openshift.io/v1
 2182 kind:·MachineConfig
 2183 metadata:
 2184 ··labels:
 2185 ····machineconfiguration.openshift.io/role:·master
 2186 ····machineconfiguration.openshift.io/role:·worker
 2187 ··name:·75-banner-etc-issue
 2188 spec:
 2189 ··config:
 2190 ····ignition:
 2191 ······version:·3.1.0
 2192 ····storage:
 2193 ······files:
 2194 ······-·contents:
 2195 ··········source:·data:,You%20are%20accessing%20a%20U.S.%20Government%20%28USG%29%20Information%20System%20%28IS%29%20that%20is%20%0Aprovided%20for%20USG-authorized%20use%20only.%20By%20using%20this%20IS%20%28which%20includes%20any%20%0Adevice%20attached%20to%20this%20IS%29%2C%20you%20consent%20to%20the%20following%20conditions%3A%0A%0A-The%20USG%20routinely%20intercepts%20and%20monitors%20communications%20on%20this%20IS%20for%20%0Apurposes%20including%2C%20but%20not%20limited%20to%2C%20penetration%20testing%2C%20COMSEC%20monitoring%2C%20%0Anetwork%20operations%20and%20defense%2C%20personnel%20misconduct%20%28PM%29%2C%20law%20enforcement%20%0A%28LE%29%2C%20and%20counterintelligence%20%28CI%29%20investigations.%0A%0A-At%20any%20time%2C%20the%20USG%20may%20inspect%20and%20seize%20data%20stored%20on%20this%20IS.%0A%0A-
 2196 Communications%20using%2C%20or%20data%20stored%20on%2C%20this%20IS%20are%20not%20private%2C%20are%20subject%20%0Ato%20routine%20monitoring%2C%20interception%2C%20and%20search%2C%20and%20may%20be%20disclosed%20or%20used%20%0Afor%20any%20USG-authorized%20purpose.%0A%0A-This%20IS%20includes%20security%20measures%20%28e.g.%2C%20authentication%20and%20access%20controls%29%20%0Ato%20protect%20USG%20interests--not%20for%20your%20personal%20benefit%20or%20privacy.%0A%0A-
 2197 Notwithstanding%20the%20above%2C%20using%20this%20IS%20does%20not%20constitute%20consent%20to%20PM%2C%20LE%20%0Aor%20CI%20investigative%20searching%20or%20monitoring%20of%20the%20content%20of%20privileged%20%0Acommunications%2C%20or%20work%20product%2C%20related%20to%20personal%20representation%20or%20services%20%0Aby%20attorneys%2C%20psychotherapists%2C%20or%20clergy%2C%20and%20their%20assistants.%20Such%20%0Acommunications%20and%20work%20product%20are%20private%20and%20confidential.%20See%20User%20%0AAgreement%20for%20details.
 2198 ········mode:·0644
 2199 ········path:·/etc/issue.d/legal-notice
 2200 ········overwrite:·true
2179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown2205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
2184 -·name:·Gather·the·package·facts2206 -·name:·Gather·the·package·facts
2185 ··package_facts:2207 ··package_facts:
Offset 2216, 36 lines modifiedOffset 2238, 14 lines modified
2216 ··-·NIST-800-53-AC-8(c)2238 ··-·NIST-800-53-AC-8(c)
2217 ··-·banner_etc_issue2239 ··-·banner_etc_issue
2218 ··-·low_complexity2240 ··-·low_complexity
2219 ··-·medium_disruption2241 ··-·medium_disruption
2220 ··-·medium_severity2242 ··-·medium_severity
2221 ··-·no_reboot_needed2243 ··-·no_reboot_needed
2222 ··-·unknown_strategy2244 ··-·unknown_strategy
2223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2224 --- 
2225 apiVersion:·machineconfiguration.openshift.io/v1 
Max diff block lines reached; 129115/137913 bytes (93.62%) of diff not shown.
4.71 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis.html
    
Offset 15238, 283 lines modifiedOffset 15238, 283 lines modified
0003b850:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b850:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b860:·3d22·2369·646d·3834·3830·2220·7461·6269··="#idm8480"·tabi0003b860:·3d22·2369·646d·3834·3830·2220·7461·6269··="#idm8480"·tabi
0003b870:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b870:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b880:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b880:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b890:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b890:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b8a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b8a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b8b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b8b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b8c0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003b8c0:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
0003b8d0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003b8e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b8f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b900:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b910:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003b920:·3438·3022·3e3c·7072·653e·3c63·6f64·653e··480"><pre><code> 
0003b930:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003b940:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003b950:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003b960:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b970:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b980:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b990:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b9a0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b9b0:·3834·3831·2220·7461·6269·6e64·6578·3d22··8481"·tabindex=" 
0003b9c0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b9d0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b9e0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b9f0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003ba00:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003ba10:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003ba20:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0003b8d0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
0003ba30:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b8e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003ba40:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b8f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003ba50:·7073·6522·2069·643d·2269·646d·3834·3831··pse"·id="idm84810003b900:·7073·6522·2069·643d·2269·646d·3834·3830··pse"·id="idm8480
0003ba60:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b910:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003ba70:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b920:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003ba80:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b930:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003ba90:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b940:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003baa0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b950:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003bab0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b960:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003bac0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b970:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bad0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b980:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003bae0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b990:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003baf0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b9a0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003bb00:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b9b0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003bb10:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b9c0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003bb20:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b9d0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003bb30:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b9e0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003bb40:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b9f0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003bb50:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme0003ba00:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003ba10:·6765·2069·6e73·7461·6c6c·2061·6964·650a··ge·install·aide.
0003bb60:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003bb70:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003bb80:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003bb90:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003bba0:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then.. 
0003bbb0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003bbc0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003bbd0:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal 
0003bbe0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003bbf0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003bc00:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003bc10:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003bc20:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003bc30:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003bc40:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003ba20:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003bc50:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003ba30:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003bc60:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003ba40:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003bc70:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003ba50:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003bc80:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003ba60:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003bc90:·2369·646d·3834·3832·2220·7461·6269·6e64··#idm8482"·tabind0003ba70:·3d22·2369·646d·3834·3831·2220·7461·6269··="#idm8481"·tabi
0003bca0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003ba80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003bcb0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003ba90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003bcc0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003baa0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003bcd0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003bab0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003bce0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003bac0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 0003bad0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003bae0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003baf0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003bb00:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003bb10:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003bb20:·646d·3834·3831·223e·3c74·6162·6c65·2063··dm8481"><table·c
 0003bb30:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003bb40:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003bb50:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003bb60:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003bb70:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003bb80:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bb90:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003bba0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003bbb0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bbc0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003bbd0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003bbe0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003bbf0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003bc00:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003bc10:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003bcf0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003bc20:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
0003bd00:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003bd10:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003bd20:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bd30:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003bd40:·6964·6d38·3438·3222·3e3c·7461·626c·6520··idm8482"><table· 
0003bd50:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003bd60:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003bd70:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003bd80:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003bd90:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003bda0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bdb0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003bdc0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003bdd0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003bde0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003bc30:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003bc40:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003bc50:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q
 0003bc60:·7569·6574·202d·7120·6b65·726e·656c·3b20··uiet·-q·kernel;·
 0003bc70:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·-
 0003bc80:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide"
 0003bc90:·203b·2074·6865·6e0a·2020·2020·646e·6620···;·then.····dnf·
 0003bca0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003bcb0:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 0003bcc0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 0003bcd0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 0003bce0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 0003bcf0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 0003bd00:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
 0003bd10:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003bd20:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
Max diff block lines reached; 4501116/4538818 bytes (99.17%) of diff not shown.
386 KB
html2text {}
    
Offset 128, 19 lines modifiedOffset 128, 21 lines modified
128 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3128 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
129 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5129 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
130 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199130 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
131 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79131 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
132 ············_\x8c_\x8i_\x8s············6.1.1132 ············_\x8c_\x8i_\x8s············6.1.1
133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
134 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule134 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 140 package·install·aide
136 [[packages]] 
137 name·=·"aide" 
138 version·=·"*" 
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
144 #·Remediation·is·applicable·only·in·certain·platforms146 #·Remediation·is·applicable·only·in·certain·platforms
145 if·rpm·--quiet·-q·kernel;·then147 if·rpm·--quiet·-q·kernel;·then
Offset 186, 14 lines modifiedOffset 188, 26 lines modified
186 ··-·PCI-DSSv4-11.5.2188 ··-·PCI-DSSv4-11.5.2
187 ··-·enable_strategy189 ··-·enable_strategy
188 ··-·low_complexity190 ··-·low_complexity
189 ··-·low_disruption191 ··-·low_disruption
190 ··-·medium_severity192 ··-·medium_severity
191 ··-·no_reboot_needed193 ··-·no_reboot_needed
192 ··-·package_aide_installed194 ··-·package_aide_installed
 195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 200 package·--add=aide
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 202 [[packages]]
 203 name·=·"aide"
 204 version·=·"*"
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
198 dnf·install·aide210 dnf·install·aide
Offset 205, 28 lines modifiedOffset 219, 14 lines modified
205 include·install_aide219 include·install_aide
  
206 class·install_aide·{220 class·install_aide·{
207 ··package·{·'aide':221 ··package·{·'aide':
208 ····ensure·=>·'installed',222 ····ensure·=>·'installed',
209 ··}223 ··}
210 }224 }
211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
216 package·install·aide 
217 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
218 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
219 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
220 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
221 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
222 package·--add=aide 
223 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*225 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
224 Run·the·following·command·to·generate·a·new·database:226 Run·the·following·command·to·generate·a·new·database:
225 $·sudo·/usr/sbin/aide·--init227 $·sudo·/usr/sbin/aide·--init
226 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:228 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
227 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz229 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
228 To·initiate·a·manual·check,·run·the·following·command:230 To·initiate·a·manual·check,·run·the·following·command:
229 $·sudo·/usr/sbin/aide·--check231 $·sudo·/usr/sbin/aide·--check
Offset 765, 14 lines modifiedOffset 765, 39 lines modified
765 »       echo·"to·see·what·package·to·(re)install"·>&2765 »       echo·"to·see·what·package·to·(re)install"·>&2
  
766 »       false··#·end·with·an·error·code766 »       false··#·end·with·an·error·code
767 elif·test·"$rc"·!=·0;·then767 elif·test·"$rc"·!=·0;·then
768 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2768 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
769 »       false··#·end·with·an·error·code769 »       false··#·end·with·an·error·code
770 fi770 fi
 771 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 772 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 773 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 774 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 775 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 776 ---
 777 apiVersion:·machineconfiguration.openshift.io/v1
 778 kind:·MachineConfig
 779 spec:
 780 ··config:
 781 ····ignition:
 782 ······version:·3.1.0
 783 ····systemd:
 784 ······units:
 785 ········-·name:·configure-crypto-policy.service
 786 ··········enabled:·true
 787 ··········contents:·|
 788 ············[Unit]
 789 ············Before=kubelet.service
 790 ············[Service]
 791 ············Type=oneshot
 792 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 793 ············RemainAfterExit=yes
 794 ············[Install]
 795 ············WantedBy=multi-user.target
771 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8796 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
772 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low797 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
773 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low798 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
774 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false799 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
775 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict800 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
776 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable801 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
777 ··set_fact:802 ··set_fact:
Offset 823, 39 lines modifiedOffset 848, 14 lines modified
823 ··-·PCI-DSSv4-2.2.7848 ··-·PCI-DSSv4-2.2.7
824 ··-·configure_crypto_policy849 ··-·configure_crypto_policy
825 ··-·high_severity850 ··-·high_severity
826 ··-·low_complexity851 ··-·low_complexity
827 ··-·low_disruption852 ··-·low_disruption
828 ··-·no_reboot_needed853 ··-·no_reboot_needed
Max diff block lines reached; 390093/394993 bytes (98.76%) of diff not shown.
2.85 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_server_l1.html
    
Offset 15200, 283 lines modifiedOffset 15200, 283 lines modified
0003b5f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b5f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b600:·6d38·3438·3022·2074·6162·696e·6465·783d··m8480"·tabindex=0003b600:·6d38·3438·3022·2074·6162·696e·6465·783d··m8480"·tabindex=
0003b610:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b610:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b620:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b620:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b630:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b630:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b640:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b640:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b650:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b650:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b660:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script·
0003b660:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0003b670:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003b680:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b690:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b6a0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b6b0:·6522·2069·643d·2269·646d·3834·3830·223e··e"·id="idm8480"> 
0003b6c0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003b6d0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003b6e0:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·= 
0003b6f0:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003b700:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b710:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b720:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b730:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b740:·6172·6765·743d·2223·6964·6d38·3438·3122··arget="#idm8481" 
0003b750:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b760:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b770:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b780:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b790:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b7a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b7b0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003b7c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003b670:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003b7d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003b680:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b7e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003b690:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b7f0:·6964·3d22·6964·6d38·3438·3122·3e3c·7461··id="idm8481"><ta0003b6a0:·6964·3d22·6964·6d38·3438·3022·3e3c·7461··id="idm8480"><ta
0003b800:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003b6b0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003b810:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003b6c0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003b820:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003b6d0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003b830:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003b6e0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003b840:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003b6f0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003b850:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003b700:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003b860:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b870:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b880:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b890:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b8a0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b8b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b8c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b8d0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b8e0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b8f0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0003b900:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0003b910:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0003b920:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp 
0003b930:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker 
0003b940:·6e65·6c3b·2074·6865·6e0a·0a69·6620·2120··nel;·then..if·!· 
0003b950:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
0003b960:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.··· 
0003b970:·2064·6e66·2069·6e73·7461·6c6c·202d·7920···dnf·install·-y· 
0003b980:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else. 
0003b990:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
0003b9a0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
0003b9b0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
0003b9c0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
0003b9d0:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
0003b9e0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003b9f0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003ba00:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003ba10:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003ba20:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8 
0003ba30:·3438·3222·2074·6162·696e·6465·783d·2230··482"·tabindex="0 
0003ba40:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003ba50:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003ba60:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003ba70:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003ba80:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003ba90:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
0003baa0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003bab0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003bac0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003bad0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84 
0003bae0:·3832·223e·3c74·6162·6c65·2063·6c61·7373··82"><table·class 
0003baf0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003bb00:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003bb10:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003bb20:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003bb30:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003bb40:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003bb50:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003bb60:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003bb70:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b710:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bb80:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003bb90:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003bba0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003b720:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b730:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b740:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003bbb0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003b750:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003b760:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b770:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003b780:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003b790:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b7a0:·636f·6465·3e0a·7061·636b·6167·6520·696e··code>.package·in
 0003b7b0:·7374·616c·6c20·6169·6465·0a3c·2f63·6f64··stall·aide.</cod
 0003b7c0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b7d0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b7e0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
0003bbc0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003bbd0:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na 
0003bbe0:·6d65·3a20·4761·7468·6572·2074·6865·2070··me:·Gather·the·p 
0003bbf0:·6163·6b61·6765·2066·6163·7473·0a20·2070··ackage·facts.··p 
0003bc00:·6163·6b61·6765·5f66·6163·7473·3a0a·2020··ackage_facts:.·· 
0003bc10:·2020·6d61·6e61·6765·723a·2061·7574·6f0a····manager:·auto. 
0003bc20:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS 
0003bc30:·2d35·2e31·302e·312e·330a·2020·2d20·4449··-5.10.1.3.··-·DI 
0003bc40:·5341·2d53·5449·472d·5248·454c·2d30·392d··SA-STIG-RHEL-09- 
0003bc50:·3635·3130·3130·0a20·202d·204e·4953·542d··651010.··-·NIST- 
0003bc60:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
0003bc70:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
0003bc80:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
0003bc90:·342d·3131·2e35·2e32·0a20·202d·2065·6e61··4-11.5.2.··-·ena 
0003bca0:·626c·655f·7374·7261·7465·6779·0a20·202d··ble_strategy.··- 
0003bcb0:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity. 
0003bcc0:·2020·2d20·6c6f·775f·6469·7372·7570·7469····-·low_disrupti 
0003bcd0:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se 
0003bce0:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re 
0003bcf0:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-· 
0003bd00:·7061·636b·6167·655f·6169·6465·5f69·6e73··package_aide_ins 
0003bd10:·7461·6c6c·6564·0a0a·2d20·6e61·6d65·3a20··talled..-·name:· 
Max diff block lines reached; 2684764/2722466 bytes (98.62%) of diff not shown.
264 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 21 lines modified
122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
126 ············_\x8c_\x8i_\x8s············6.1.1126 ············_\x8c_\x8i_\x8s············6.1.1
127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule128 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 134 package·install·aide
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms140 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel;·then141 if·rpm·--quiet·-q·kernel;·then
Offset 180, 14 lines modifiedOffset 182, 26 lines modified
180 ··-·PCI-DSSv4-11.5.2182 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy183 ··-·enable_strategy
182 ··-·low_complexity184 ··-·low_complexity
183 ··-·low_disruption185 ··-·low_disruption
184 ··-·medium_severity186 ··-·medium_severity
185 ··-·no_reboot_needed187 ··-·no_reboot_needed
186 ··-·package_aide_installed188 ··-·package_aide_installed
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 194 package·--add=aide
 195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 196 [[packages]]
 197 name·=·"aide"
 198 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
192 dnf·install·aide204 dnf·install·aide
Offset 199, 28 lines modifiedOffset 213, 14 lines modified
199 include·install_aide213 include·install_aide
  
200 class·install_aide·{214 class·install_aide·{
201 ··package·{·'aide':215 ··package·{·'aide':
202 ····ensure·=>·'installed',216 ····ensure·=>·'installed',
203 ··}217 ··}
204 }218 }
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
210 package·install·aide 
211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
216 package·--add=aide 
217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
218 Run·the·following·command·to·generate·a·new·database:220 Run·the·following·command·to·generate·a·new·database:
219 $·sudo·/usr/sbin/aide·--init221 $·sudo·/usr/sbin/aide·--init
220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
222 To·initiate·a·manual·check,·run·the·following·command:224 To·initiate·a·manual·check,·run·the·following·command:
223 $·sudo·/usr/sbin/aide·--check225 $·sudo·/usr/sbin/aide·--check
Offset 759, 14 lines modifiedOffset 759, 39 lines modified
759 »       echo·"to·see·what·package·to·(re)install"·>&2759 »       echo·"to·see·what·package·to·(re)install"·>&2
  
760 »       false··#·end·with·an·error·code760 »       false··#·end·with·an·error·code
761 elif·test·"$rc"·!=·0;·then761 elif·test·"$rc"·!=·0;·then
762 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2762 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
763 »       false··#·end·with·an·error·code763 »       false··#·end·with·an·error·code
764 fi764 fi
 765 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 766 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 767 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 768 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 769 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 770 ---
 771 apiVersion:·machineconfiguration.openshift.io/v1
 772 kind:·MachineConfig
 773 spec:
 774 ··config:
 775 ····ignition:
 776 ······version:·3.1.0
 777 ····systemd:
 778 ······units:
 779 ········-·name:·configure-crypto-policy.service
 780 ··········enabled:·true
 781 ··········contents:·|
 782 ············[Unit]
 783 ············Before=kubelet.service
 784 ············[Service]
 785 ············Type=oneshot
 786 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 787 ············RemainAfterExit=yes
 788 ············[Install]
 789 ············WantedBy=multi-user.target
765 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
766 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low791 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
767 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low792 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
768 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false793 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
769 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict794 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
770 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable795 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
771 ··set_fact:796 ··set_fact:
Offset 817, 39 lines modifiedOffset 842, 14 lines modified
817 ··-·PCI-DSSv4-2.2.7842 ··-·PCI-DSSv4-2.2.7
818 ··-·configure_crypto_policy843 ··-·configure_crypto_policy
819 ··-·high_severity844 ··-·high_severity
820 ··-·low_complexity845 ··-·low_complexity
821 ··-·low_disruption846 ··-·low_disruption
822 ··-·no_reboot_needed847 ··-·no_reboot_needed
Max diff block lines reached; 265691/270591 bytes (98.19%) of diff not shown.
2.54 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_workstation_l1.html
    
Offset 15191, 283 lines modifiedOffset 15191, 283 lines modified
0003b560:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b560:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b570:·743d·2223·6964·6d38·3438·3022·2074·6162··t="#idm8480"·tab0003b570:·743d·2223·6964·6d38·3438·3022·2074·6162··t="#idm8480"·tab
0003b580:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b580:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b590:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b590:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b5a0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b5a0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b5b0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b5b0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b5c0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b5c0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b5d0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003b5d0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s
0003b5e0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003b5f0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b600:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b610:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b620:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b630:·3834·3830·223e·3c70·7265·3e3c·636f·6465··8480"><pre><code 
0003b640:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003b650:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003b660:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003b670:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b680:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b690:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b6a0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b6b0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b6c0:·6d38·3438·3122·2074·6162·696e·6465·783d··m8481"·tabindex= 
0003b6d0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b6e0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b6f0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b700:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b710:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b720:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003b730:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br0003b5e0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
0003b740:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003b5f0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b750:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b600:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003b760:·6170·7365·2220·6964·3d22·6964·6d38·3438··apse"·id="idm8480003b610:·6170·7365·2220·6964·3d22·6964·6d38·3438··apse"·id="idm848
0003b770:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=0003b620:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=
0003b780:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b630:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003b790:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b640:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003b7a0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b650:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003b7b0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b660:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003b7c0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b670:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003b7d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b680:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b7e0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003b690:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003b7f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b6a0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b800:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003b6b0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
0003b810:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003b6c0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
0003b820:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003b6d0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
0003b830:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003b6e0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
0003b840:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003b6f0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
0003b850:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003b700:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003b860:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem0003b710:·3c70·7265·3e3c·636f·6465·3e0a·7061·636b··<pre><code>.pack
 0003b720:·6167·6520·696e·7374·616c·6c20·6169·6465··age·install·aide
0003b870:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003b880:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003b890:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003b8a0:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet· 
0003b8b0:·2d71·206b·6572·6e65·6c3b·2074·6865·6e0a··-q·kernel;·then. 
0003b8c0:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q 
0003b8d0:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th 
0003b8e0:·656e·0a20·2020·2064·6e66·2069·6e73·7461··en.····dnf·insta 
0003b8f0:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi. 
0003b900:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b910:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b920:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b930:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b940:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b950:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di0003b730:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003b960:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·0003b740:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003b970:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat0003b750:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003b980:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap0003b760:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003b990:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b770:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b9a0:·2223·6964·6d38·3438·3222·2074·6162·696e··"#idm8482"·tabin0003b780:·743d·2223·6964·6d38·3438·3122·2074·6162··t="#idm8481"·tab
0003b9b0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b790:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b9c0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b7a0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b9d0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b7b0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b9e0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b7c0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b9f0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b7d0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003ba00:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans0003b7e0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
0003ba10:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003ba20:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003ba30:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003ba40:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003ba50:·2269·646d·3834·3832·223e·3c74·6162·6c65··"idm8482"><table 
0003ba60:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003ba70:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003ba80:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003ba90:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003baa0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003bab0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003bac0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003bad0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003b7f0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 0003b800:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b810:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b820:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b830:·6964·6d38·3438·3122·3e3c·7461·626c·6520··idm8481"><table·
 0003b840:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003b850:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003b860:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003b870:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003b880:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003b890:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b8a0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003b8b0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003b8c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b8d0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003b8e0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003b8f0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003b900:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003bae0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b910:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003baf0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003bb00:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003bb10:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003bb20:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003b920:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b930:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003b940:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003b950:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003b960:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
 0003b970:·7175·6965·7420·2d71·206b·6572·6e65·6c3b··quiet·-q·kernel;
 0003b980:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 0003b990:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 0003b9a0:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf
 0003b9b0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003b9c0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 0003b9d0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003b9e0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003b9f0:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003ba00:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 0003ba10:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
 0003ba20:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
Max diff block lines reached; 2384781/2422483 bytes (98.44%) of diff not shown.
238 KB
html2text {}
    
Offset 121, 19 lines modifiedOffset 121, 21 lines modified
121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3121 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79124 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
125 ············_\x8c_\x8i_\x8s············6.1.1125 ············_\x8c_\x8i_\x8s············6.1.1
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
127 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule127 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 133 package·install·aide
129 [[packages]] 
130 name·=·"aide" 
131 version·=·"*" 
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
137 #·Remediation·is·applicable·only·in·certain·platforms139 #·Remediation·is·applicable·only·in·certain·platforms
138 if·rpm·--quiet·-q·kernel;·then140 if·rpm·--quiet·-q·kernel;·then
Offset 179, 14 lines modifiedOffset 181, 26 lines modified
179 ··-·PCI-DSSv4-11.5.2181 ··-·PCI-DSSv4-11.5.2
180 ··-·enable_strategy182 ··-·enable_strategy
181 ··-·low_complexity183 ··-·low_complexity
182 ··-·low_disruption184 ··-·low_disruption
183 ··-·medium_severity185 ··-·medium_severity
184 ··-·no_reboot_needed186 ··-·no_reboot_needed
185 ··-·package_aide_installed187 ··-·package_aide_installed
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 package·--add=aide
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 195 [[packages]]
 196 name·=·"aide"
 197 version·=·"*"
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
191 dnf·install·aide203 dnf·install·aide
Offset 198, 28 lines modifiedOffset 212, 14 lines modified
198 include·install_aide212 include·install_aide
  
199 class·install_aide·{213 class·install_aide·{
200 ··package·{·'aide':214 ··package·{·'aide':
201 ····ensure·=>·'installed',215 ····ensure·=>·'installed',
202 ··}216 ··}
203 }217 }
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
209 package·install·aide 
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
215 package·--add=aide 
216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*218 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
217 Run·the·following·command·to·generate·a·new·database:219 Run·the·following·command·to·generate·a·new·database:
218 $·sudo·/usr/sbin/aide·--init220 $·sudo·/usr/sbin/aide·--init
219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:221 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
220 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz222 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
221 To·initiate·a·manual·check,·run·the·following·command:223 To·initiate·a·manual·check,·run·the·following·command:
222 $·sudo·/usr/sbin/aide·--check224 $·sudo·/usr/sbin/aide·--check
Offset 758, 14 lines modifiedOffset 758, 39 lines modified
758 »       echo·"to·see·what·package·to·(re)install"·>&2758 »       echo·"to·see·what·package·to·(re)install"·>&2
  
759 »       false··#·end·with·an·error·code759 »       false··#·end·with·an·error·code
760 elif·test·"$rc"·!=·0;·then760 elif·test·"$rc"·!=·0;·then
761 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2761 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
762 »       false··#·end·with·an·error·code762 »       false··#·end·with·an·error·code
763 fi763 fi
 764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 765 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 766 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 767 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 768 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 769 ---
 770 apiVersion:·machineconfiguration.openshift.io/v1
 771 kind:·MachineConfig
 772 spec:
 773 ··config:
 774 ····ignition:
 775 ······version:·3.1.0
 776 ····systemd:
 777 ······units:
 778 ········-·name:·configure-crypto-policy.service
 779 ··········enabled:·true
 780 ··········contents:·|
 781 ············[Unit]
 782 ············Before=kubelet.service
 783 ············[Service]
 784 ············Type=oneshot
 785 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 786 ············RemainAfterExit=yes
 787 ············[Install]
 788 ············WantedBy=multi-user.target
764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8789 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
765 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low790 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
766 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low791 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
767 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false792 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
768 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict793 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
769 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable794 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
770 ··set_fact:795 ··set_fact:
Offset 816, 39 lines modifiedOffset 841, 14 lines modified
816 ··-·PCI-DSSv4-2.2.7841 ··-·PCI-DSSv4-2.2.7
817 ··-·configure_crypto_policy842 ··-·configure_crypto_policy
818 ··-·high_severity843 ··-·high_severity
819 ··-·low_complexity844 ··-·low_complexity
820 ··-·low_disruption845 ··-·low_disruption
821 ··-·no_reboot_needed846 ··-·no_reboot_needed
Max diff block lines reached; 238562/243462 bytes (97.99%) of diff not shown.
4.54 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cis_workstation_l2.html
    
Offset 15230, 283 lines modifiedOffset 15230, 283 lines modified
0003b7d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b7d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b7e0:·3834·3830·2220·7461·6269·6e64·6578·3d22··8480"·tabindex="0003b7e0:·3834·3830·2220·7461·6269·6e64·6578·3d22··8480"·tabindex="
0003b7f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b7f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b840:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·0003b840:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
0003b850:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0003b860:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b870:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b880:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b890:·2220·6964·3d22·6964·6d38·3438·3022·3e3c··"·id="idm8480">< 
0003b8a0:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
0003b8b0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
0003b8c0:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=· 
0003b8d0:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
0003b8e0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b8f0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b900:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b910:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b920:·7267·6574·3d22·2369·646d·3834·3831·2220··rget="#idm8481"· 
0003b930:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b940:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b950:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b960:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b970:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b980:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b990:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003b9a0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b850:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b9b0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b860:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b9c0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b870:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b9d0:·643d·2269·646d·3834·3831·223e·3c74·6162··d="idm8481"><tab0003b880:·643d·2269·646d·3834·3830·223e·3c74·6162··d="idm8480"><tab
0003b9e0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b890:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b9f0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b8a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003ba00:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b8b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003ba10:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b8c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003ba20:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b8d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003ba30:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b8e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003ba40:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003b8f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003ba50:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003b900:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003ba60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b910:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003ba70:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003b920:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003ba80:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b930:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003ba90:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b940:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003baa0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b950:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003bab0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003b960:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003bac0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b970:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b980:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins
 0003b990:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code
0003bad0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0003bae0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0003baf0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0003bb00:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm 
0003bb10:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern 
0003bb20:·656c·3b20·7468·656e·0a0a·6966·2021·2072··el;·then..if·!·r 
0003bb30:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003bb40:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003bb50:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·" 
0003bb60:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003bb70:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003bb80:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003bb90:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003bba0:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003bbb0:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003bbc0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003b9a0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003bbd0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003b9b0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003bbe0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003b9c0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003bbf0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003b9d0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003bc00:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm840003b9e0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003bc10:·3832·2220·7461·6269·6e64·6578·3d22·3022··82"·tabindex="0"0003b9f0:·3834·3831·2220·7461·6269·6e64·6578·3d22··8481"·tabindex="
0003bc20:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003ba00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003bc30:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003ba10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003bc40:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003ba20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003bc50:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003ba30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003bc60:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003ba40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003ba50:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 0003ba60:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003ba70:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003ba80:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003ba90:·7073·6522·2069·643d·2269·646d·3834·3831··pse"·id="idm8481
 0003baa0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003bab0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003bc70:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003bc80:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003bc90:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003bca0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bcb0:·6170·7365·2220·6964·3d22·6964·6d38·3438··apse"·id="idm848 
0003bcc0:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class= 
0003bcd0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bce0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bcf0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003bac0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003bd00:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003bd10:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003bd20:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003bd30:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bd40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bd50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bd60:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003bad0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003bae0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003baf0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003bb00:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003bb10:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003bb20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003bb30:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003bb40:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003bb50:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003bb60:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003bb70:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003bb80:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003bb90:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 0003bba0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 0003bbb0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 0003bbc0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 0003bbd0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 0003bbe0:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then..
 0003bbf0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003bc00:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003bc10:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal
 0003bc20:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003bc30:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003bc40:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003bc50:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003bc60:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003bc70:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 0003bc80:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003bc90:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
Max diff block lines reached; 4339193/4376895 bytes (99.14%) of diff not shown.
371 KB
html2text {}
    
Offset 127, 19 lines modifiedOffset 127, 21 lines modified
127 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3127 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79130 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
131 ············_\x8c_\x8i_\x8s············6.1.1131 ············_\x8c_\x8i_\x8s············6.1.1
132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2132 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
133 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule133 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 139 package·install·aide
135 [[packages]] 
136 name·=·"aide" 
137 version·=·"*" 
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
143 #·Remediation·is·applicable·only·in·certain·platforms145 #·Remediation·is·applicable·only·in·certain·platforms
144 if·rpm·--quiet·-q·kernel;·then146 if·rpm·--quiet·-q·kernel;·then
Offset 185, 14 lines modifiedOffset 187, 26 lines modified
185 ··-·PCI-DSSv4-11.5.2187 ··-·PCI-DSSv4-11.5.2
186 ··-·enable_strategy188 ··-·enable_strategy
187 ··-·low_complexity189 ··-·low_complexity
188 ··-·low_disruption190 ··-·low_disruption
189 ··-·medium_severity191 ··-·medium_severity
190 ··-·no_reboot_needed192 ··-·no_reboot_needed
191 ··-·package_aide_installed193 ··-·package_aide_installed
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 199 package·--add=aide
 200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 201 [[packages]]
 202 name·=·"aide"
 203 version·=·"*"
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
197 dnf·install·aide209 dnf·install·aide
Offset 204, 28 lines modifiedOffset 218, 14 lines modified
204 include·install_aide218 include·install_aide
  
205 class·install_aide·{219 class·install_aide·{
206 ··package·{·'aide':220 ··package·{·'aide':
207 ····ensure·=>·'installed',221 ····ensure·=>·'installed',
208 ··}222 ··}
209 }223 }
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
215 package·install·aide 
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
221 package·--add=aide 
222 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*224 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
223 Run·the·following·command·to·generate·a·new·database:225 Run·the·following·command·to·generate·a·new·database:
224 $·sudo·/usr/sbin/aide·--init226 $·sudo·/usr/sbin/aide·--init
225 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:227 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
226 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz228 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
227 To·initiate·a·manual·check,·run·the·following·command:229 To·initiate·a·manual·check,·run·the·following·command:
228 $·sudo·/usr/sbin/aide·--check230 $·sudo·/usr/sbin/aide·--check
Offset 764, 14 lines modifiedOffset 764, 39 lines modified
764 »       echo·"to·see·what·package·to·(re)install"·>&2764 »       echo·"to·see·what·package·to·(re)install"·>&2
  
765 »       false··#·end·with·an·error·code765 »       false··#·end·with·an·error·code
766 elif·test·"$rc"·!=·0;·then766 elif·test·"$rc"·!=·0;·then
767 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2767 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
768 »       false··#·end·with·an·error·code768 »       false··#·end·with·an·error·code
769 fi769 fi
 770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 771 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 772 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 773 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 774 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 775 ---
 776 apiVersion:·machineconfiguration.openshift.io/v1
 777 kind:·MachineConfig
 778 spec:
 779 ··config:
 780 ····ignition:
 781 ······version:·3.1.0
 782 ····systemd:
 783 ······units:
 784 ········-·name:·configure-crypto-policy.service
 785 ··········enabled:·true
 786 ··········contents:·|
 787 ············[Unit]
 788 ············Before=kubelet.service
 789 ············[Service]
 790 ············Type=oneshot
 791 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 792 ············RemainAfterExit=yes
 793 ············[Install]
 794 ············WantedBy=multi-user.target
770 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8795 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
771 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low796 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
772 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low797 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
773 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false798 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
774 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict799 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
775 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable800 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
776 ··set_fact:801 ··set_fact:
Offset 822, 39 lines modifiedOffset 847, 14 lines modified
822 ··-·PCI-DSSv4-2.2.7847 ··-·PCI-DSSv4-2.2.7
823 ··-·configure_crypto_policy848 ··-·configure_crypto_policy
824 ··-·high_severity849 ··-·high_severity
825 ··-·low_complexity850 ··-·low_complexity
826 ··-·low_disruption851 ··-·low_disruption
827 ··-·no_reboot_needed852 ··-·no_reboot_needed
Max diff block lines reached; 375334/380234 bytes (98.71%) of diff not shown.
3.16 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-cui.html
    
Offset 15508, 62 lines modifiedOffset 15508, 62 lines modified
0003c930:·6574·3d22·2369·646d·3930·3333·2220·7461··et="#idm9033"·ta0003c930:·6574·3d22·2369·646d·3930·3333·2220·7461··et="#idm9033"·ta
0003c940:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003c940:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003c950:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003c950:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003c960:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003c960:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003c970:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003c970:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003c980:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003c980:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003c990:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003c990:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003c9a0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003c9b0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003c9c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003c9d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003c9e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003c9f0:·6d39·3033·3322·3e3c·7072·653e·3c63·6f64··m9033"><pre><cod 
0003ca00:·653e·0a5b·6375·7374·6f6d·697a·6174·696f··e>.[customizatio 
0003ca10:·6e73·5d0a·6669·7073·203d·2074·7275·650a··ns].fips·=·true. 
0003ca20:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003ca30:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003ca40:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003ca50:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003ca60:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003ca70:·3d22·2369·646d·3930·3334·2220·7461·6269··="#idm9034"·tabi 
0003ca80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003ca90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003caa0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003cab0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003cac0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003cad0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003cae0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</0003c9a0:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
0003caf0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003c9b0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003cb00:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003c9c0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003cb10:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003c9d0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003cb20:·646d·3930·3334·223e·3c70·7265·3e3c·636f··dm9034"><pre><co0003c9e0:·2269·646d·3930·3333·223e·3c70·7265·3e3c··"idm9033"><pre><
0003cb30:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation0003c9f0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
0003cb40:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o0003ca00:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
0003cb50:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p0003ca10:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
0003cb60:·6c61·7466·6f72·6d73·0a69·6620·2820·2120··latforms.if·(·!·0003ca20:·2070·6c61·7466·6f72·6d73·0a69·6620·2820···platforms.if·(·
0003cb70:·2820·5b20·2224·7b63·6f6e·7461·696e·6572··(·[·"${container0003ca30:·2120·2820·5b20·2224·7b63·6f6e·7461·696e··!·(·[·"${contain
0003cb80:·3a2d·7d22·203d·3d20·2262·7772·6170·2d6f··:-}"·==·"bwrap-o0003ca40:·6572·3a2d·7d22·203d·3d20·2262·7772·6170··er:-}"·==·"bwrap
0003cb90:·7362·7569·6c64·2220·5d20·2920·2661·6d70··sbuild"·]·)·&amp0003ca50:·2d6f·7362·7569·6c64·2220·5d20·2920·2661··-osbuild"·]·)·&a
0003cba0:·3b26·616d·703b·2072·706d·202d·2d71·7569··;&amp;·rpm·--qui0003ca60:·6d70·3b26·616d·703b·2072·706d·202d·2d71··mp;&amp;·rpm·--q
0003cbb0:·6574·202d·7120·6b65·726e·656c·2029·3b20··et·-q·kernel·);·0003ca70:·7569·6574·202d·7120·6b65·726e·656c·2029··uiet·-q·kernel·)
0003cbc0:·7468·656e·0a0a·6966·205b·5b20·2224·4f53··then..if·[[·"$OS0003ca80:·3b20·7468·656e·0a0a·6966·205b·5b20·2224··;·then..if·[[·"$
0003cbd0:·4341·505f·424f·4f54·435f·4255·494c·4422··CAP_BOOTC_BUILD"0003ca90:·4f53·4341·505f·424f·4f54·435f·4255·494c··OSCAP_BOOTC_BUIL
0003cbe0:·203d·3d20·2259·4553·2220·5d5d·3b20·7468···==·"YES"·]];·th0003caa0:·4422·203d·3d20·2259·4553·2220·5d5d·3b20··D"·==·"YES"·]];·
0003cbf0:·656e·0a09·6361·7420·2667·743b·202f·7573··en..cat·&gt;·/us0003cab0:·7468·656e·0a09·6361·7420·2667·743b·202f··then..cat·&gt;·/
0003cc00:·722f·6c69·622f·626f·6f74·632f·6b61·7267··r/lib/bootc/karg0003cac0:·7573·722f·6c69·622f·626f·6f74·632f·6b61··usr/lib/bootc/ka
0003cc10:·732e·642f·3031·2d66·6970·732e·746f·6d6c··s.d/01-fips.toml0003cad0:·7267·732e·642f·3031·2d66·6970·732e·746f··rgs.d/01-fips.to
0003cc20:·2026·6c74·3b26·6c74·3b20·454f·460a·6b61···&lt;&lt;·EOF.ka0003cae0:·6d6c·2026·6c74·3b26·6c74·3b20·454f·460a··ml·&lt;&lt;·EOF.
0003cc30:·7267·7320·3d20·5b22·6669·7073·3d31·225d··rgs·=·["fips=1"]0003caf0:·6b61·7267·7320·3d20·5b22·6669·7073·3d31··kargs·=·["fips=1
0003cc40:·0a45·4f46·0a66·690a·0a65·6c73·650a·2020··.EOF.fi..else.··0003cb00:·225d·0a45·4f46·0a66·690a·0a65·6c73·650a··"].EOF.fi..else.
0003cc50:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech0003cb10:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
0003cc60:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i0003cb20:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
0003cc70:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable0003cb30:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
0003cc80:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do0003cb40:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
0003cc90:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></0003cb50:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
 0003cb60:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003cb70:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003cb80:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003cb90:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003cba0:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9
 0003cbb0:·3033·3422·2074·6162·696e·6465·783d·2230··034"·tabindex="0
 0003cbc0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003cbd0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003cbe0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003cbf0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003cc00:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003cc10:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003cc20:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003cc30:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003cc40:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003cc50:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003cc60:·2069·643d·2269·646d·3930·3334·223e·3c70···id="idm9034"><p
 0003cc70:·7265·3e3c·636f·6465·3e0a·5b63·7573·746f··re><code>.[custo
 0003cc80:·6d69·7a61·7469·6f6e·735d·0a66·6970·7320··mizations].fips·
 0003cc90:·3d20·7472·7565·0a3c·2f63·6f64·653e·3c2f··=·true.</code></
0003cca0:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>0003cca0:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>
0003ccb0:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod0003ccb0:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod
0003ccc0:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><0003ccc0:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><
0003ccd0:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-0003ccd0:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-
0003cce0:·6964·3d22·6368·696c·6472·656e·2d78·6363··id="children-xcc0003cce0:·6964·3d22·6368·696c·6472·656e·2d78·6363··id="children-xcc
0003ccf0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec0003ccf0:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
0003cd00:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_0003cd00:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15836, 252 lines modifiedOffset 15836, 252 lines modified
0003ddb0:·7267·6574·3d22·2369·646d·3931·3633·2220··rget="#idm9163"·0003ddb0:·7267·6574·3d22·2369·646d·3931·3633·2220··rget="#idm9163"·
0003ddc0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003ddc0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003ddd0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003ddd0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003dde0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003dde0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003ddf0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003ddf0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003de00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003de00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003de10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003de10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003de20:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0003de30:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
0003de40:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003de50:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003de60:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003de70:·6964·6d39·3136·3322·3e3c·7072·653e·3c63··idm9163"><pre><c 
0003de80:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
0003de90:·5d0a·6e61·6d65·203d·2022·6372·7970·746f··].name·=·"crypto 
0003dea0:·2d70·6f6c·6963·6965·7322·0a76·6572·7369··-policies".versi 
0003deb0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003dec0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003ded0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003dee0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003def0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003df00:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9 
0003df10:·3136·3422·2074·6162·696e·6465·783d·2230··164"·tabindex="0 
0003df20:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003df30:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003df40:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003df50:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003df60:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003df70:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003df80:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003df90:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003dfa0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003dfb0:·7365·2220·6964·3d22·6964·6d39·3136·3422··se"·id="idm9164" 
0003dfc0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003dfd0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003dfe0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003dff0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003e000:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003e010:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003e020:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003e030:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003e040:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003e050:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003e060:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
Max diff block lines reached; 2909302/2950342 bytes (98.61%) of diff not shown.
350 KB
html2text {}
    
Offset 133, 31 lines modifiedOffset 133, 31 lines modified
133 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877133 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
134 ············_\x8i_\x8s_\x8m······1446134 ············_\x8i_\x8s_\x8m······1446
135 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1135 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
136 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12136 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
137 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1137 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176138 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
139 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule139 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
141 [customizations] 
142 fips·=·true 
143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
144 #·Remediation·is·applicable·only·in·certain·platforms141 #·Remediation·is·applicable·only·in·certain·platforms
145 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then142 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
146 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then143 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
147 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF144 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
148 kargs·=·["fips=1"]145 kargs·=·["fips=1"]
149 EOF146 EOF
150 fi147 fi
  
151 else148 else
152 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
153 fi150 fi
 151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 152 [customizations]
 153 fips·=·true
154 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules154 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules
155 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:155 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
156 ····*·GnuTLS·library156 ····*·GnuTLS·library
157 ····*·OpenSSL·library157 ····*·OpenSSL·library
158 ····*·NSS·library158 ····*·NSS·library
159 ····*·OpenJDK159 ····*·OpenJDK
160 ····*·Libkrb5160 ····*·Libkrb5
Offset 170, 19 lines modifiedOffset 170, 21 lines modified
170 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.170 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
171 Severity: ··medium171 Severity: ··medium
172 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed172 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
173 ············_\x8d_\x8i_\x8s_\x8a····CCI-002890,·CCI-002450,·CCI-003123173 ············_\x8d_\x8i_\x8s_\x8a····CCI-002890,·CCI-002450,·CCI-003123
174 References:·_\x8o_\x8s_\x8p_\x8p····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1174 References:·_\x8o_\x8s_\x8p_\x8p····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
175 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174175 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
176 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-258234r1051250_rule176 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-258234r1051250_rule
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·install·crypto-policies
178 [[packages]] 
179 name·=·"crypto-policies" 
180 version·=·"*" 
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
186 if·!·rpm·-q·--quiet·"crypto-policies"·;·then188 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 201, 14 lines modifiedOffset 203, 26 lines modified
201 ··-·DISA-STIG-RHEL-09-215100203 ··-·DISA-STIG-RHEL-09-215100
202 ··-·enable_strategy204 ··-·enable_strategy
203 ··-·low_complexity205 ··-·low_complexity
204 ··-·low_disruption206 ··-·low_disruption
205 ··-·medium_severity207 ··-·medium_severity
206 ··-·no_reboot_needed208 ··-·no_reboot_needed
207 ··-·package_crypto-policies_installed209 ··-·package_crypto-policies_installed
 210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 215 package·--add=crypto-policies
 216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 217 [[packages]]
 218 name·=·"crypto-policies"
 219 version·=·"*"
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
213 dnf·install·crypto-policies225 dnf·install·crypto-policies
Offset 220, 28 lines modifiedOffset 234, 14 lines modified
220 include·install_crypto-policies234 include·install_crypto-policies
  
221 class·install_crypto-policies·{235 class·install_crypto-policies·{
222 ··package·{·'crypto-policies':236 ··package·{·'crypto-policies':
223 ····ensure·=>·'installed',237 ····ensure·=>·'installed',
224 ··}238 ··}
225 }239 }
226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
231 package·install·crypto-policies 
232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
233 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
234 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
235 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
236 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
237 package·--add=crypto-policies 
238 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*240 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
239 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS·policy,·run·the·following·command:241 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS·policy,·run·the·following·command:
240 $·sudo·update-crypto-policies·--set·FIPS242 $·sudo·update-crypto-policies·--set·FIPS
241 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.243 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
242 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.244 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
243 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.245 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
244 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.246 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 272, 14 lines modifiedOffset 272, 39 lines modified
272 »       echo·"to·see·what·package·to·(re)install"·>&2272 »       echo·"to·see·what·package·to·(re)install"·>&2
  
273 »       false··#·end·with·an·error·code273 »       false··#·end·with·an·error·code
274 elif·test·"$rc"·!=·0;·then274 elif·test·"$rc"·!=·0;·then
275 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2275 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
276 »       false··#·end·with·an·error·code276 »       false··#·end·with·an·error·code
277 fi277 fi
 278 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 279 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 280 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 349904/358479 bytes (97.61%) of diff not shown.
1.97 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-e8.html
    
Offset 17631, 189 lines modifiedOffset 17631, 189 lines modified
00044de0:·6574·3d22·2369·646d·3932·3532·2220·7461··et="#idm9252"·ta00044de0:·6574·3d22·2369·646d·3932·3532·2220·7461··et="#idm9252"·ta
00044df0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00044df0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00044e00:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00044e00:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00044e10:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00044e10:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00044e20:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00044e20:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00044e30:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00044e30:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00044e40:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00044e40:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00044e50:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
00044e60:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00044e70:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00044e80:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00044e90:·6964·3d22·6964·6d39·3235·3222·3e3c·7461··id="idm9252"><ta 
00044ea0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
00044eb0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
00044ec0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
00044ed0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
00044ee0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
00044ef0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
00044f00:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00044f10:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
00044f20:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00044f30:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
00044f40:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
00044f50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00044f60:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
00044f70:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td>< 
00044f80:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
00044f90:·3e3c·636f·6465·3e2d·206e·616d·653a·2058··><code>-·name:·X 
00044fa0:·4343·4446·2056·616c·7565·2076·6172·5f73··CCDF·Value·var_s 
00044fb0:·7973·7465·6d5f·6372·7970·746f·5f70·6f6c··ystem_crypto_pol 
00044fc0:·6963·7920·2320·7072·6f6d·6f74·6520·746f··icy·#·promote·to 
00044fd0:·2076·6172·6961·626c·650a·2020·7365·745f···variable.··set_ 
00044fe0:·6661·6374·3a0a·2020·2020·7661·725f·7379··fact:.····var_sy 
00044ff0:·7374·656d·5f63·7279·7074·6f5f·706f·6c69··stem_crypto_poli 
00045000:·6379·3a20·2121·7374·7220·3c61·6262·7220··cy:·!!str·<abbr· 
00045010:·7469·746c·653d·2266·726f·6d20·5072·6f66··title="from·Prof 
00045020:·696c·652f·7265·6669·6e65·2d76·616c·7565··ile/refine-value 
00045030:·3a20·7863·6364·665f·6f72·672e·7373·6770··:·xccdf_org.ssgp 
00045040:·726f·6a65·6374·2e63·6f6e·7465·6e74·5f76··roject.content_v 
00045050:·616c·7565·5f76·6172·5f73·7973·7465·6d5f··alue_var_system_ 
00045060:·6372·7970·746f·5f70·6f6c·6963·7922·3e44··crypto_policy">D 
00045070:·4546·4155·4c54·3a4e·4f2d·5348·4131·3c2f··EFAULT:NO-SHA1</ 
00045080:·6162·6272·3e0a·2020·7461·6773·3a0a·2020··abbr>.··tags:.·· 
00045090:·2020·2d20·616c·7761·7973·0a0a·2d20·6e61····-·always..-·na 
000450a0:·6d65·3a20·436f·6e66·6967·7572·6520·5379··me:·Configure·Sy 
000450b0:·7374·656d·2043·7279·7074·6f67·7261·7068··stem·Cryptograph 
000450c0:·7920·506f·6c69·6379·0a20·206c·696e·6569··y·Policy.··linei 
000450d0:·6e66·696c·653a·0a20·2020·2070·6174·683a··nfile:.····path: 
000450e0:·202f·6574·632f·6372·7970·746f·2d70·6f6c···/etc/crypto-pol 
000450f0:·6963·6965·732f·636f·6e66·6967·0a20·2020··icies/config.··· 
00045100:·2072·6567·6578·703a·205e·283f·2123·2928···regexp:·^(?!#)( 
00045110:·5c53·2b29·240a·2020·2020·6c69·6e65·3a20··\S+)$.····line:· 
00045120:·277b·7b20·7661·725f·7379·7374·656d·5f63··'{{·var_system_c 
00045130:·7279·7074·6f5f·706f·6c69·6379·207d·7d27··rypto_policy·}}' 
00045140:·0a20·2020·2063·7265·6174·653a·2074·7275··.····create:·tru 
00045150:·650a·2020·7461·6773·3a0a·2020·2d20·4449··e.··tags:.··-·DI 
00045160:·5341·2d53·5449·472d·5248·454c·2d30·392d··SA-STIG-RHEL-09- 
00045170:·3231·3531·3035·0a20·202d·2044·4953·412d··215105.··-·DISA- 
00045180:·5354·4947·2d52·4845·4c2d·3039·2d36·3731··STIG-RHEL-09-671 
00045190:·3031·300a·2020·2d20·4449·5341·2d53·5449··010.··-·DISA-STI 
000451a0:·472d·5248·454c·2d30·392d·3637·3230·3330··G-RHEL-09-672030 
000451b0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
000451c0:·2d41·432d·3137·2832·290a·2020·2d20·4e49··-AC-17(2).··-·NI 
000451d0:·5354·2d38·3030·2d35·332d·4143·2d31·3728··ST-800-53-AC-17( 
000451e0:·6129·0a20·202d·204e·4953·542d·3830·302d··a).··-·NIST-800- 
000451f0:·3533·2d43·4d2d·3628·6129·0a20·202d·204e··53-CM-6(a).··-·N 
00045200:·4953·542d·3830·302d·3533·2d4d·412d·3428··IST-800-53-MA-4( 
00045210:·3629·0a20·202d·204e·4953·542d·3830·302d··6).··-·NIST-800- 
00045220:·3533·2d53·432d·3132·2832·290a·2020·2d20··53-SC-12(2).··-· 
00045230:·4e49·5354·2d38·3030·2d35·332d·5343·2d31··NIST-800-53-SC-1 
00045240:·3228·3329·0a20·202d·204e·4953·542d·3830··2(3).··-·NIST-80 
00045250:·302d·3533·2d53·432d·3133·0a20·202d·2050··0-53-SC-13.··-·P 
00045260:·4349·2d44·5353·7634·2d32·2e32·0a20·202d··CI-DSSv4-2.2.··- 
00045270:·2050·4349·2d44·5353·7634·2d32·2e32·2e37···PCI-DSSv4-2.2.7 
00045280:·0a20·202d·2063·6f6e·6669·6775·7265·5f63··.··-·configure_c 
00045290:·7279·7074·6f5f·706f·6c69·6379·0a20·202d··rypto_policy.··- 
000452a0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.· 
000452b0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
000452c0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
000452d0:·7469·6f6e·0a20·202d·206e·6f5f·7265·626f··tion.··-·no_rebo 
000452e0:·6f74·5f6e·6565·6465·640a·2020·2d20·7265··ot_needed.··-·re 
000452f0:·7374·7269·6374·5f73·7472·6174·6567·790a··strict_strategy. 
00045300:·0a2d·206e·616d·653a·2056·6572·6966·7920··.-·name:·Verify· 
00045310:·7468·6174·2043·7279·7074·6f20·506f·6c69··that·Crypto·Poli 
00045320:·6379·2069·7320·5365·7420·2872·756e·7469··cy·is·Set·(runti 
00045330:·6d65·290a·2020·636f·6d6d·616e·643a·202f··me).··command:·/ 
00045340:·7573·722f·6269·6e2f·7570·6461·7465·2d63··usr/bin/update-c 
00045350:·7279·7074·6f2d·706f·6c69·6369·6573·202d··rypto-policies·- 
00045360:·2d73·6574·207b·7b20·7661·725f·7379·7374··-set·{{·var_syst 
00045370:·656d·5f63·7279·7074·6f5f·706f·6c69·6379··em_crypto_policy 
00045380:·207d·7d0a·2020·7461·6773·3a0a·2020·2d20···}}.··tags:.··-· 
00045390:·4449·5341·2d53·5449·472d·5248·454c·2d30··DISA-STIG-RHEL-0 
000453a0:·392d·3231·3531·3035·0a20·202d·2044·4953··9-215105.··-·DIS 
000453b0:·412d·5354·4947·2d52·4845·4c2d·3039·2d36··A-STIG-RHEL-09-6 
000453c0:·3731·3031·300a·2020·2d20·4449·5341·2d53··71010.··-·DISA-S 
000453d0:·5449·472d·5248·454c·2d30·392d·3637·3230··TIG-RHEL-09-6720 
000453e0:·3330·0a20·202d·204e·4953·542d·3830·302d··30.··-·NIST-800- 
000453f0:·3533·2d41·432d·3137·2832·290a·2020·2d20··53-AC-17(2).··-· 
00045400:·4e49·5354·2d38·3030·2d35·332d·4143·2d31··NIST-800-53-AC-1 
00045410:·3728·6129·0a20·202d·204e·4953·542d·3830··7(a).··-·NIST-80 
00045420:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
00045430:·204e·4953·542d·3830·302d·3533·2d4d·412d···NIST-800-53-MA- 
00045440:·3428·3629·0a20·202d·204e·4953·542d·3830··4(6).··-·NIST-80 
00045450:·302d·3533·2d53·432d·3132·2832·290a·2020··0-53-SC-12(2).·· 
00045460:·2d20·4e49·5354·2d38·3030·2d35·332d·5343··-·NIST-800-53-SC 
00045470:·2d31·3228·3329·0a20·202d·204e·4953·542d··-12(3).··-·NIST- 
00045480:·3830·302d·3533·2d53·432d·3133·0a20·202d··800-53-SC-13.··- 
00045490:·2050·4349·2d44·5353·7634·2d32·2e32·0a20···PCI-DSSv4-2.2.· 
000454a0:·202d·2050·4349·2d44·5353·7634·2d32·2e32···-·PCI-DSSv4-2.2 
000454b0:·2e37·0a20·202d·2063·6f6e·6669·6775·7265··.7.··-·configure 
000454c0:·5f63·7279·7074·6f5f·706f·6c69·6379·0a20··_crypto_policy.· 
000454d0:·202d·2068·6967·685f·7365·7665·7269·7479···-·high_severity 
000454e0:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
000454f0:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
00045500:·7570·7469·6f6e·0a20·202d·206e·6f5f·7265··uption.··-·no_re 
00045510:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-· 
00045520:·7265·7374·7269·6374·5f73·7472·6174·6567··restrict_strateg 
00045530:·790a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··y.</code></pre>< 
00045540:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00045550:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00045560:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00045570:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00045580:·6574·3d22·2369·646d·3932·3534·2220·7461··et="#idm9254"·ta 
00045590:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
000455a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
000455b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
000455c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
Max diff block lines reached; 1876361/1901091 bytes (98.70%) of diff not shown.
164 KB
html2text {}
    
Offset 718, 14 lines modifiedOffset 718, 39 lines modified
718 »       echo·"to·see·what·package·to·(re)install"·>&2718 »       echo·"to·see·what·package·to·(re)install"·>&2
  
719 »       false··#·end·with·an·error·code719 »       false··#·end·with·an·error·code
720 elif·test·"$rc"·!=·0;·then720 elif·test·"$rc"·!=·0;·then
721 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2721 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
722 »       false··#·end·with·an·error·code722 »       false··#·end·with·an·error·code
723 fi723 fi
 724 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 725 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 726 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 727 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 728 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 729 ---
 730 apiVersion:·machineconfiguration.openshift.io/v1
 731 kind:·MachineConfig
 732 spec:
 733 ··config:
 734 ····ignition:
 735 ······version:·3.1.0
 736 ····systemd:
 737 ······units:
 738 ········-·name:·configure-crypto-policy.service
 739 ··········enabled:·true
 740 ··········contents:·|
 741 ············[Unit]
 742 ············Before=kubelet.service
 743 ············[Service]
 744 ············Type=oneshot
 745 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 746 ············RemainAfterExit=yes
 747 ············[Install]
 748 ············WantedBy=multi-user.target
724 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
725 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low750 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
726 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low751 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
727 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false752 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
728 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict753 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
729 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable754 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
730 ··set_fact:755 ··set_fact:
Offset 776, 39 lines modifiedOffset 801, 14 lines modified
776 ··-·PCI-DSSv4-2.2.7801 ··-·PCI-DSSv4-2.2.7
777 ··-·configure_crypto_policy802 ··-·configure_crypto_policy
778 ··-·high_severity803 ··-·high_severity
779 ··-·low_complexity804 ··-·low_complexity
780 ··-·low_disruption805 ··-·low_disruption
781 ··-·no_reboot_needed806 ··-·no_reboot_needed
782 ··-·restrict_strategy807 ··-·restrict_strategy
783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
784 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
785 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
786 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
787 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
788 --- 
789 apiVersion:·machineconfiguration.openshift.io/v1 
790 kind:·MachineConfig 
791 spec: 
792 ··config: 
793 ····ignition: 
794 ······version:·3.1.0 
795 ····systemd: 
796 ······units: 
797 ········-·name:·configure-crypto-policy.service 
798 ··········enabled:·true 
799 ··········contents:·| 
800 ············[Unit] 
801 ············Before=kubelet.service 
802 ············[Service] 
803 ············Type=oneshot 
804 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
805 ············RemainAfterExit=yes 
806 ············[Install] 
807 ············WantedBy=multi-user.target 
808 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*808 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
809 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.809 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
810 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.810 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
811 Severity: ··medium811 Severity: ··medium
812 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy812 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
813 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453813 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
814 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)814 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 1146, 19 lines modifiedOffset 1146, 21 lines modified
1146 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.1146 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.
1147 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1147 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1148 The·rear·package·can·be·installed·with·the·following·command:1148 The·rear·package·can·be·installed·with·the·following·command:
1149 $·sudo·dnf·install·rear1149 $·sudo·dnf·install·rear
1150 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.1150 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.
1151 Severity: ·medium1151 Severity: ·medium
1152 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed1152 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed
1153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1158 package·install·rear
1154 [[packages]] 
1155 name·=·"rear" 
1156 version·=·"*" 
1157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1160 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1161 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1162 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1163 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1162 #·Remediation·is·applicable·only·in·certain·platforms1164 #·Remediation·is·applicable·only·in·certain·platforms
1163 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1165 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1187, 14 lines modifiedOffset 1189, 26 lines modified
1187 ··tags:1189 ··tags:
1188 ··-·enable_strategy1190 ··-·enable_strategy
1189 ··-·low_complexity1191 ··-·low_complexity
1190 ··-·low_disruption1192 ··-·low_disruption
1191 ··-·medium_severity1193 ··-·medium_severity
1192 ··-·no_reboot_needed1194 ··-·no_reboot_needed
1193 ··-·package_rear_installed1195 ··-·package_rear_installed
 1196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1201 package·--add=rear
 1202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1203 [[packages]]
 1204 name·=·"rear"
 1205 version·=·"*"
1194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 161719/168130 bytes (96.19%) of diff not shown.
1.94 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-hipaa.html
    
Offset 16957, 189 lines modifiedOffset 16957, 189 lines modified
000423c0:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9000423c0:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9
000423d0:·3235·3222·2074·6162·696e·6465·783d·2230··252"·tabindex="0000423d0:·3235·3222·2074·6162·696e·6465·783d·2230··252"·tabindex="0
000423e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·000423e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
000423f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f000423f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00042400:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00042400:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00042410:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00042410:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00042420:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00042420:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00042430:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
00042440:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00042450:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00042460:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00042470:·6c61·7073·6522·2069·643d·2269·646d·3932··lapse"·id="idm92 
00042480:·3532·223e·3c74·6162·6c65·2063·6c61·7373··52"><table·class 
00042490:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00042430:·6961·7469·6f6e·204b·7562·6572·6e65·7465··iation·Kubernete
 00042440:·7320·736e·6970·7065·7420·e287·b23c·2f61··s·snippet·...</a
 00042450:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00042460:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00042470:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00042480:·6d39·3235·3222·3e3c·7461·626c·6520·636c··m9252"><table·cl
 00042490:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 000424a0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
000424a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord000424b0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 000424c0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 000424d0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 000424e0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 000424f0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
000424b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
000424c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
000424d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
000424e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
000424f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
00042500:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
00042510:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00042520:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>00042500:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
00042530:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><00042510:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00042520:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00042530:·7464·3e74·7275·653c·2f74·643e·3c2f·7472··td>true</td></tr
00042540:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00042540:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
00042550:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric00042550:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr
00042560:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab00042560:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t
00042570:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·00042570:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
00042580:·6e61·6d65·3a20·5843·4344·4620·5661·6c75··name:·XCCDF·Valu 
00042590:·6520·7661·725f·7379·7374·656d·5f63·7279··e·var_system_cry 
000425a0:·7074·6f5f·706f·6c69·6379·2023·2070·726f··pto_policy·#·pro 
000425b0:·6d6f·7465·2074·6f20·7661·7269·6162·6c65··mote·to·variable 
000425c0:·0a20·2073·6574·5f66·6163·743a·0a20·2020··.··set_fact:.···00042580:·2d2d·2d0a·6170·6956·6572·7369·6f6e·3a20··---.apiVersion:·
 00042590:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura
 000425a0:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i
 000425b0:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi
 000425c0:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.·
 000425d0:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign
 000425e0:·6974·696f·6e3a·0a20·2020·2020·2076·6572··ition:.······ver
 000425f0:·7369·6f6e·3a20·332e·312e·300a·2020·2020··sion:·3.1.0.····
 00042600:·7379·7374·656d·643a·0a20·2020·2020·2075··systemd:.······u
 00042610:·6e69·7473·3a0a·2020·2020·2020·2020·2d20··nits:.········-·
 00042620:·6e61·6d65·3a20·636f·6e66·6967·7572·652d··name:·configure-
 00042630:·6372·7970·746f·2d70·6f6c·6963·792e·7365··crypto-policy.se
 00042640:·7276·6963·650a·2020·2020·2020·2020·2020··rvice.··········
 00042650:·656e·6162·6c65·643a·2074·7275·650a·2020··enabled:·true.··
 00042660:·2020·2020·2020·2020·636f·6e74·656e·7473··········contents
 00042670:·3a20·7c0a·2020·2020·2020·2020·2020·2020··:·|.············
 00042680:·5b55·6e69·745d·0a20·2020·2020·2020·2020··[Unit].·········
 00042690:·2020·2042·6566·6f72·653d·6b75·6265·6c65·····Before=kubele
 000426a0:·742e·7365·7276·6963·650a·2020·2020·2020··t.service.······
 000426b0:·2020·2020·2020·5b53·6572·7669·6365·5d0a········[Service].
 000426c0:·2020·2020·2020·2020·2020·2020·5479·7065··············Type
 000426d0:·3d6f·6e65·7368·6f74·0a20·2020·2020·2020··=oneshot.·······
 000426e0:·2020·2020·2045·7865·6353·7461·7274·3d75·······ExecStart=u
 000426f0:·7064·6174·652d·6372·7970·746f·2d70·6f6c··pdate-crypto-pol
 00042700:·6963·6965·7320·2d2d·7365·7420·7b7b·2e76··icies·--set·{{.v
000425d0:·2076·6172·5f73·7973·7465·6d5f·6372·7970···var_system_cryp00042710:·6172·5f73·7973·7465·6d5f·6372·7970·746f··ar_system_crypto
000425e0:·746f·5f70·6f6c·6963·793a·2021·2173·7472··to_policy:·!!str 
000425f0:·203c·6162·6272·2074·6974·6c65·3d22·6672···<abbr·title="fr 
00042600:·6f6d·2050·726f·6669·6c65·2f72·6566·696e··om·Profile/refin 
00042610:·652d·7661·6c75·653a·2078·6363·6466·5f6f··e-value:·xccdf_o 
00042620:·7267·2e73·7367·7072·6f6a·6563·742e·636f··rg.ssgproject.co 
00042630:·6e74·656e·745f·7661·6c75·655f·7661·725f··ntent_value_var_ 
00042640:·7379·7374·656d·5f63·7279·7074·6f5f·706f··system_crypto_po 
00042650:·6c69·6379·223e·4649·5053·3c2f·6162·6272··licy">FIPS</abbr 
00042660:·3e0a·2020·7461·6773·3a0a·2020·2020·2d20··>.··tags:.····-· 
00042670:·616c·7761·7973·0a0a·2d20·6e61·6d65·3a20··always..-·name:· 
00042680:·436f·6e66·6967·7572·6520·5379·7374·656d··Configure·System 
00042690:·2043·7279·7074·6f67·7261·7068·7920·506f···Cryptography·Po 
000426a0:·6c69·6379·0a20·206c·696e·6569·6e66·696c··licy.··lineinfil 
000426b0:·653a·0a20·2020·2070·6174·683a·202f·6574··e:.····path:·/et 
000426c0:·632f·6372·7970·746f·2d70·6f6c·6963·6965··c/crypto-policie 
000426d0:·732f·636f·6e66·6967·0a20·2020·2072·6567··s/config.····reg 
000426e0:·6578·703a·205e·283f·2123·2928·5c53·2b29··exp:·^(?!#)(\S+) 
000426f0:·240a·2020·2020·6c69·6e65·3a20·277b·7b20··$.····line:·'{{·00042720:·5f70·6f6c·6963·797d·7d0a·2020·2020·2020··_policy}}.······
 00042730:·2020·2020·2020·5265·6d61·696e·4166·7465········RemainAfte
 00042740:·7245·7869·743d·7965·730a·2020·2020·2020··rExit=yes.······
 00042750:·2020·2020·2020·5b49·6e73·7461·6c6c·5d0a········[Install].
 00042760:·2020·2020·2020·2020·2020·2020·5761·6e74··············Want
 00042770:·6564·4279·3d6d·756c·7469·2d75·7365·722e··edBy=multi-user.
 00042780:·7461·7267·6574·0a3c·2f63·6f64·653e·3c2f··target.</code></
 00042790:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 000427a0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 000427b0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 000427c0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 000427d0:·2d74·6172·6765·743d·2223·6964·6d39·3235··-target="#idm925
 000427e0:·3322·2074·6162·696e·6465·783d·2230·2220··3"·tabindex="0"·
 000427f0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 00042800:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 00042810:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 00042820:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 00042830:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00042840:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
 00042850:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 00042860:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00042870:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00042880:·7073·6522·2069·643d·2269·646d·3932·3533··pse"·id="idm9253
 00042890:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 000428a0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 000428b0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 000428c0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 000428d0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 000428e0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 000428f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00042900:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00042910:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00042920:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00042930:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00042940:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00042950:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00042960:·7468·3e3c·7464·3e72·6573·7472·6963·743c··th><td>restrict<
 00042970:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 00042980:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na
Max diff block lines reached; 1864823/1889553 bytes (98.69%) of diff not shown.
136 KB
html2text {}
    
Offset 550, 14 lines modifiedOffset 550, 39 lines modified
550 »       echo·"to·see·what·package·to·(re)install"·>&2550 »       echo·"to·see·what·package·to·(re)install"·>&2
  
551 »       false··#·end·with·an·error·code551 »       false··#·end·with·an·error·code
552 elif·test·"$rc"·!=·0;·then552 elif·test·"$rc"·!=·0;·then
553 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2553 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
554 »       false··#·end·with·an·error·code554 »       false··#·end·with·an·error·code
555 fi555 fi
 556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 561 ---
 562 apiVersion:·machineconfiguration.openshift.io/v1
 563 kind:·MachineConfig
 564 spec:
 565 ··config:
 566 ····ignition:
 567 ······version:·3.1.0
 568 ····systemd:
 569 ······units:
 570 ········-·name:·configure-crypto-policy.service
 571 ··········enabled:·true
 572 ··········contents:·|
 573 ············[Unit]
 574 ············Before=kubelet.service
 575 ············[Service]
 576 ············Type=oneshot
 577 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 578 ············RemainAfterExit=yes
 579 ············[Install]
 580 ············WantedBy=multi-user.target
556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8581 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low582 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low583 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false584 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict585 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
561 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable586 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
562 ··set_fact:587 ··set_fact:
Offset 608, 39 lines modifiedOffset 633, 14 lines modified
608 ··-·PCI-DSSv4-2.2.7633 ··-·PCI-DSSv4-2.2.7
609 ··-·configure_crypto_policy634 ··-·configure_crypto_policy
610 ··-·high_severity635 ··-·high_severity
611 ··-·low_complexity636 ··-·low_complexity
612 ··-·low_disruption637 ··-·low_disruption
613 ··-·no_reboot_needed638 ··-·no_reboot_needed
614 ··-·restrict_strategy639 ··-·restrict_strategy
615 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
616 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
617 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
618 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
619 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
620 --- 
621 apiVersion:·machineconfiguration.openshift.io/v1 
622 kind:·MachineConfig 
623 spec: 
624 ··config: 
625 ····ignition: 
626 ······version:·3.1.0 
627 ····systemd: 
628 ······units: 
629 ········-·name:·configure-crypto-policy.service 
630 ··········enabled:·true 
631 ··········contents:·| 
632 ············[Unit] 
633 ············Before=kubelet.service 
634 ············[Service] 
635 ············Type=oneshot 
636 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
637 ············RemainAfterExit=yes 
638 ············[Install] 
639 ············WantedBy=multi-user.target 
640 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*640 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
641 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.641 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
642 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.642 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
643 Severity: ··medium643 Severity: ··medium
644 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy644 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
645 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453645 ············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
646 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)646 ············_\x8h_\x8i_\x8p_\x8a_\x8a····164.308(a)(4)(i),·164.308(b)(1),·164.308(b)(3),·164.312(e)(1),·164.312(e)(2)(ii)
Offset 1615, 18 lines modifiedOffset 1615, 21 lines modified
1615 ············_\x8c_\x8u_\x8i·····3.4.51615 ············_\x8c_\x8u_\x8i·····3.4.5
1616 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-0022351616 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-002235
1617 ············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1617 ············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1618 References:·_\x8n_\x8i_\x8s_\x8t····CM-61618 References:·_\x8n_\x8i_\x8s_\x8t····CM-6
1619 ············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.11619 ············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.1
1620 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271620 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1621 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-257786r1044834_rule1621 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-257786r1044834_rule
1622 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81622 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1623 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1624 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1625 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1626 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1627 service·disable·debug-shell
1623 [customizations.services] 
1624 masked·=·["debug-shell"] 
1625 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81628 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1626 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1629 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1627 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1630 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1628 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1631 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1629 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1632 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1630 #·Remediation·is·applicable·only·in·certain·platforms1633 #·Remediation·is·applicable·only·in·certain·platforms
1631 if·rpm·--quiet·-q·kernel;·then1634 if·rpm·--quiet·-q·kernel;·then
Offset 1648, 14 lines modifiedOffset 1651, 33 lines modified
1648 #·so·let's·reset·the·state·so·OVAL·checks·pass.1651 #·so·let's·reset·the·state·so·OVAL·checks·pass.
1649 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.1652 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
1650 "$SYSTEMCTL_EXEC"·reset-failed·'debug-shell.service'·||·true1653 "$SYSTEMCTL_EXEC"·reset-failed·'debug-shell.service'·||·true
  
1651 else1654 else
1652 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1655 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1653 fi1656 fi
 1657 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1658 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1659 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 1660 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 1661 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
 1662 apiVersion:·machineconfiguration.openshift.io/v1
 1663 kind:·MachineConfig
 1664 spec:
 1665 ··config:
 1666 ····ignition:
 1667 ······version:·3.1.0
 1668 ····systemd:
 1669 ······units:
 1670 ······-·name:·debug-shell.service
 1671 ········enabled:·false
 1672 ········mask:·true
Max diff block lines reached; 134263/139735 bytes (96.08%) of diff not shown.
2.57 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ism_o.html
    
Offset 17469, 283 lines modifiedOffset 17469, 283 lines modified
000443c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#000443c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
000443d0:·6964·6d38·3438·3022·2074·6162·696e·6465··idm8480"·tabinde000443d0:·6964·6d38·3438·3022·2074·6162·696e·6465··idm8480"·tabinde
000443e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt000443e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
000443f0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande000443f0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
00044400:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=00044400:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
00044410:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev00044410:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
00044420:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R00044420:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
00044430:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui00044430:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
00044440:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
00044450:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
00044460:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00044470:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00044480:·7073·6522·2069·643d·2269·646d·3834·3830··pse"·id="idm8480 
00044490:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
000444a0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
000444b0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
000444c0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
000444d0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
000444e0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
000444f0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00044500:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00044510:·2d74·6172·6765·743d·2223·6964·6d38·3438··-target="#idm848 
00044520:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
00044530:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00044540:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00044550:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00044560:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
00044570:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
00044580:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
00044590:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00044440:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
000445a0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00044450:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
000445b0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00044460:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
000445c0:·2220·6964·3d22·6964·6d38·3438·3122·3e3c··"·id="idm8481"><00044470:·2220·6964·3d22·6964·6d38·3438·3022·3e3c··"·id="idm8480"><
000445d0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab00044480:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
000445e0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped00044490:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
000445f0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·000444a0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
00044600:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"000444b0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
00044610:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex000444c0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
00044620:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low000444d0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00044630:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00044640:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
00044650:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00044660:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
00044670:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
00044680:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00044690:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
000446a0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
000446b0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
000446c0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
000446d0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
000446e0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
000446f0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
00044700:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
00044710:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if· 
00044720:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
00044730:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
00044740:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
00044750:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
00044760:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
00044770:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
00044780:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
00044790:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
000447a0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
000447b0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
000447c0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
000447d0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
000447e0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
000447f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
00044800:·6d38·3438·3222·2074·6162·696e·6465·783d··m8482"·tabindex= 
00044810:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
00044820:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
00044830:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
00044840:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
00044850:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
00044860:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
00044870:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
00044880:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
00044890:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
000448a0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
000448b0:·3834·3832·223e·3c74·6162·6c65·2063·6c61··8482"><table·cla 
000448c0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
000448d0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
000448e0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
000448f0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
00044900:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
00044910:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00044920:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
00044930:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
00044940:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t000444e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
00044950:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
00044960:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
00044970:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
00044980:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
00044990:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
000449a0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
000449b0:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
000449c0:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
000449d0:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
000449e0:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
000449f0:·6f0a·2020·7461·6773·3a0a·2020·2d20·434a··o.··tags:.··-·CJ 
00044a00:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
00044a10:·4449·5341·2d53·5449·472d·5248·454c·2d30··DISA-STIG-RHEL-0 
00044a20:·392d·3635·3130·3130·0a20·202d·204e·4953··9-651010.··-·NIS 
00044a30:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
00044a40:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
00044a50:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
00044a60:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
00044a70:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
00044a80:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
00044a90:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
00044aa0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
00044ab0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
00044ac0:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
00044ad0:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
00044ae0:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name 
00044af0:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is 
00044b00:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac 
00044b10:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:· 
00044b20:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:· 
00044b30:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:· 
00044b40:·2722·6b65·726e·656c·2220·696e·2061·6e73··'"kernel"·in·ans 
00044b50:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
00044b60:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··- 
00044b70:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
00044b80:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE 
00044b90:·4c2d·3039·2d36·3531·3031·300a·2020·2d20··L-09-651010.··-· 
00044ba0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
Max diff block lines reached; 2433283/2470985 bytes (98.47%) of diff not shown.
216 KB
html2text {}
    
Offset 701, 19 lines modifiedOffset 701, 21 lines modified
701 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3701 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
702 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5702 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
703 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199703 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
704 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79704 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
705 ············_\x8c_\x8i_\x8s············6.1.1705 ············_\x8c_\x8i_\x8s············6.1.1
706 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2706 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
707 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule707 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
708 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8708 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 709 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 710 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 711 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 712 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 713 package·install·aide
709 [[packages]] 
710 name·=·"aide" 
711 version·=·"*" 
712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8714 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low715 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low716 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false717 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable718 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
717 #·Remediation·is·applicable·only·in·certain·platforms719 #·Remediation·is·applicable·only·in·certain·platforms
718 if·rpm·--quiet·-q·kernel;·then720 if·rpm·--quiet·-q·kernel;·then
Offset 759, 14 lines modifiedOffset 761, 26 lines modified
759 ··-·PCI-DSSv4-11.5.2761 ··-·PCI-DSSv4-11.5.2
760 ··-·enable_strategy762 ··-·enable_strategy
761 ··-·low_complexity763 ··-·low_complexity
762 ··-·low_disruption764 ··-·low_disruption
763 ··-·medium_severity765 ··-·medium_severity
764 ··-·no_reboot_needed766 ··-·no_reboot_needed
765 ··-·package_aide_installed767 ··-·package_aide_installed
 768 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 769 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 770 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 771 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 772 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 773 package·--add=aide
 774 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 775 [[packages]]
 776 name·=·"aide"
 777 version·=·"*"
766 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8778 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
767 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low779 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
768 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low780 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
769 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false781 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
770 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable782 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
771 dnf·install·aide783 dnf·install·aide
Offset 778, 28 lines modifiedOffset 792, 14 lines modified
778 include·install_aide792 include·install_aide
  
779 class·install_aide·{793 class·install_aide·{
780 ··package·{·'aide':794 ··package·{·'aide':
781 ····ensure·=>·'installed',795 ····ensure·=>·'installed',
782 ··}796 ··}
783 }797 }
784 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
785 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
786 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
787 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
788 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
789 package·install·aide 
790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
791 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
792 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
793 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
794 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
795 package·--add=aide 
796 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules798 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
797 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.799 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
798 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·9.800 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·9.
  
799 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.801 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
800 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*802 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 830, 31 lines modifiedOffset 830, 31 lines modified
830 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877830 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
831 ············_\x8i_\x8s_\x8m······1446831 ············_\x8i_\x8s_\x8m······1446
832 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1832 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
833 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12833 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
834 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1834 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
835 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176835 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
836 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule836 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule
837 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
838 [customizations] 
839 fips·=·true 
840 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8837 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
841 #·Remediation·is·applicable·only·in·certain·platforms838 #·Remediation·is·applicable·only·in·certain·platforms
842 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then839 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
843 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then840 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
844 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF841 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
845 kargs·=·["fips=1"]842 kargs·=·["fips=1"]
846 EOF843 EOF
847 fi844 fi
  
848 else845 else
849 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'846 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
850 fi847 fi
 848 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 849 [customizations]
 850 fips·=·true
851 Group  ·System·Cryptographic·Policies·  Group·contains·2·rules851 Group  ·System·Cryptographic·Policies·  Group·contains·2·rules
852 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:852 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
853 ····*·GnuTLS·library853 ····*·GnuTLS·library
854 ····*·OpenSSL·library854 ····*·OpenSSL·library
855 ····*·NSS·library855 ····*·NSS·library
856 ····*·OpenJDK856 ····*·OpenJDK
857 ····*·Libkrb5857 ····*·Libkrb5
Offset 895, 14 lines modifiedOffset 895, 39 lines modified
895 »       echo·"to·see·what·package·to·(re)install"·>&2895 »       echo·"to·see·what·package·to·(re)install"·>&2
  
896 »       false··#·end·with·an·error·code896 »       false··#·end·with·an·error·code
897 elif·test·"$rc"·!=·0;·then897 elif·test·"$rc"·!=·0;·then
898 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2898 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
899 »       false··#·end·with·an·error·code899 »       false··#·end·with·an·error·code
900 fi900 fi
 901 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 902 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 903 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 214049/221066 bytes (96.83%) of diff not shown.
3.15 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-ospp.html
    
Offset 15476, 62 lines modifiedOffset 15476, 62 lines modified
0003c730:·6765·743d·2223·6964·6d39·3033·3322·2074··get="#idm9033"·t0003c730:·6765·743d·2223·6964·6d39·3033·3322·2074··get="#idm9033"·t
0003c740:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003c740:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003c750:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003c750:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003c760:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003c760:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003c770:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003c770:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003c780:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003c780:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003c790:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003c790:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003c7a0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003c7b0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003c7c0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003c7d0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003c7e0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003c7f0:·646d·3930·3333·223e·3c70·7265·3e3c·636f··dm9033"><pre><co 
0003c800:·6465·3e0a·5b63·7573·746f·6d69·7a61·7469··de>.[customizati 
0003c810:·6f6e·735d·0a66·6970·7320·3d20·7472·7565··ons].fips·=·true 
0003c820:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003c830:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003c840:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003c850:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003c860:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003c870:·743d·2223·6964·6d39·3033·3422·2074·6162··t="#idm9034"·tab 
0003c880:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003c890:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003c8a0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003c8b0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003c8c0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003c8d0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003c8e0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<0003c7a0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
0003c8f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003c7b0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003c900:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003c7c0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003c910:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003c7d0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003c920:·6964·6d39·3033·3422·3e3c·7072·653e·3c63··idm9034"><pre><c0003c7e0:·3d22·6964·6d39·3033·3322·3e3c·7072·653e··="idm9033"><pre>
0003c930:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio0003c7f0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
0003c940:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·0003c800:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
0003c950:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·0003c810:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
0003c960:·706c·6174·666f·726d·730a·6966·2028·2021··platforms.if·(·!0003c820:·6e20·706c·6174·666f·726d·730a·6966·2028··n·platforms.if·(
0003c970:·2028·205b·2022·247b·636f·6e74·6169·6e65···(·[·"${containe0003c830:·2021·2028·205b·2022·247b·636f·6e74·6169···!·(·[·"${contai
0003c980:·723a·2d7d·2220·3d3d·2022·6277·7261·702d··r:-}"·==·"bwrap-0003c840:·6e65·723a·2d7d·2220·3d3d·2022·6277·7261··ner:-}"·==·"bwra
0003c990:·6f73·6275·696c·6422·205d·2029·2026·616d··osbuild"·]·)·&am0003c850:·702d·6f73·6275·696c·6422·205d·2029·2026··p-osbuild"·]·)·&
0003c9a0:·703b·2661·6d70·3b20·7270·6d20·2d2d·7175··p;&amp;·rpm·--qu0003c860:·616d·703b·2661·6d70·3b20·7270·6d20·2d2d··amp;&amp;·rpm·--
0003c9b0:·6965·7420·2d71·206b·6572·6e65·6c20·293b··iet·-q·kernel·);0003c870:·7175·6965·7420·2d71·206b·6572·6e65·6c20··quiet·-q·kernel·
0003c9c0:·2074·6865·6e0a·0a69·6620·5b5b·2022·244f···then..if·[[·"$O0003c880:·293b·2074·6865·6e0a·0a69·6620·5b5b·2022··);·then..if·[[·"
0003c9d0:·5343·4150·5f42·4f4f·5443·5f42·5549·4c44··SCAP_BOOTC_BUILD0003c890:·244f·5343·4150·5f42·4f4f·5443·5f42·5549··$OSCAP_BOOTC_BUI
0003c9e0:·2220·3d3d·2022·5945·5322·205d·5d3b·2074··"·==·"YES"·]];·t0003c8a0:·4c44·2220·3d3d·2022·5945·5322·205d·5d3b··LD"·==·"YES"·]];
0003c9f0:·6865·6e0a·0963·6174·2026·6774·3b20·2f75··hen..cat·&gt;·/u0003c8b0:·2074·6865·6e0a·0963·6174·2026·6774·3b20···then..cat·&gt;·
0003ca00:·7372·2f6c·6962·2f62·6f6f·7463·2f6b·6172··sr/lib/bootc/kar0003c8c0:·2f75·7372·2f6c·6962·2f62·6f6f·7463·2f6b··/usr/lib/bootc/k
0003ca10:·6773·2e64·2f30·312d·6669·7073·2e74·6f6d··gs.d/01-fips.tom0003c8d0:·6172·6773·2e64·2f30·312d·6669·7073·2e74··args.d/01-fips.t
0003ca20:·6c20·266c·743b·266c·743b·2045·4f46·0a6b··l·&lt;&lt;·EOF.k0003c8e0:·6f6d·6c20·266c·743b·266c·743b·2045·4f46··oml·&lt;&lt;·EOF
0003ca30:·6172·6773·203d·205b·2266·6970·733d·3122··args·=·["fips=1"0003c8f0:·0a6b·6172·6773·203d·205b·2266·6970·733d··.kargs·=·["fips=
0003ca40:·5d0a·454f·460a·6669·0a0a·656c·7365·0a20··].EOF.fi..else.·0003c900:·3122·5d0a·454f·460a·6669·0a0a·656c·7365··1"].EOF.fi..else
0003ca50:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec0003c910:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
0003ca60:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·0003c920:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
0003ca70:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl0003c930:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
0003ca80:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d0003c940:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
0003ca90:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><0003c950:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
 0003c960:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003c970:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003c980:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003c990:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003c9a0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003c9b0:·3930·3334·2220·7461·6269·6e64·6578·3d22··9034"·tabindex="
 0003c9c0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003c9d0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 0003c9e0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 0003c9f0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 0003ca00:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003ca10:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·
 0003ca20:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe
 0003ca30:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003ca40:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003ca50:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003ca60:·2220·6964·3d22·6964·6d39·3033·3422·3e3c··"·id="idm9034"><
 0003ca70:·7072·653e·3c63·6f64·653e·0a5b·6375·7374··pre><code>.[cust
 0003ca80:·6f6d·697a·6174·696f·6e73·5d0a·6669·7073··omizations].fips
 0003ca90:·203d·2074·7275·650a·3c2f·636f·6465·3e3c···=·true.</code><
0003caa0:·2f70·7265·3e3c·2f64·6976·3e3c·2f64·6976··/pre></div></div0003caa0:·2f70·7265·3e3c·2f64·6976·3e3c·2f64·6976··/pre></div></div
0003cab0:·3e3c·2f74·643e·3c2f·7472·3e3c·2f74·626f··></td></tr></tbo0003cab0:·3e3c·2f74·643e·3c2f·7472·3e3c·2f74·626f··></td></tr></tbo
0003cac0:·6479·3e3c·2f74·6162·6c65·3e3c·2f74·643e··dy></table></td>0003cac0:·6479·3e3c·2f74·6162·6c65·3e3c·2f74·643e··dy></table></td>
0003cad0:·3c2f·7472·3e3c·7472·2064·6174·612d·7474··</tr><tr·data-tt0003cad0:·3c2f·7472·3e3c·7472·2064·6174·612d·7474··</tr><tr·data-tt
0003cae0:·2d69·643d·2263·6869·6c64·7265·6e2d·7863··-id="children-xc0003cae0:·2d69·643d·2263·6869·6c64·7265·6e2d·7863··-id="children-xc
0003caf0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje0003caf0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
0003cb00:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group0003cb00:·6374·2e63·6f6e·7465·6e74·5f67·726f·7570··ct.content_group
Offset 15804, 252 lines modifiedOffset 15804, 252 lines modified
0003dbb0:·6172·6765·743d·2223·6964·6d39·3136·3322··arget="#idm9163"0003dbb0:·6172·6765·743d·2223·6964·6d39·3136·3322··arget="#idm9163"
0003dbc0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003dbc0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003dbd0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003dbd0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003dbe0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003dbe0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003dbf0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003dbf0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003dc00:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003dc00:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003dc10:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003dc10:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003dc20:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a
 0003dc30:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003dc40:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003dc50:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003dc60:·6d39·3136·3322·3e3c·7461·626c·6520·636c··m9163"><table·cl
 0003dc70:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003dc80:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003dc90:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003dca0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003dcb0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003dcc0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003dcd0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003dc20:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003dc30:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003dc40:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003dc50:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003dc60:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003dc70:·2269·646d·3931·3633·223e·3c70·7265·3e3c··"idm9163"><pre>< 
0003dc80:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003dc90:·5d5d·0a6e·616d·6520·3d20·2263·7279·7074··]].name·=·"crypt 
0003dca0:·6f2d·706f·6c69·6369·6573·220a·7665·7273··o-policies".vers 
0003dcb0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003dcc0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003dcd0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003dce0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003dcf0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003dd00:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003dd10:·3931·3634·2220·7461·6269·6e64·6578·3d22··9164"·tabindex=" 
0003dd20:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003dd30:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003dd40:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003dd50:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003dd60:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003dd70:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003dd80:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003dd90:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003dda0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
Max diff block lines reached; 2907922/2948962 bytes (98.61%) of diff not shown.
350 KB
html2text {}
    
Offset 124, 31 lines modifiedOffset 124, 31 lines modified
124 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877124 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
125 ············_\x8i_\x8s_\x8m······1446125 ············_\x8i_\x8s_\x8m······1446
126 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1126 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
127 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12127 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
128 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1128 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176129 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
130 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule130 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
132 [customizations] 
133 fips·=·true 
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
135 #·Remediation·is·applicable·only·in·certain·platforms132 #·Remediation·is·applicable·only·in·certain·platforms
136 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then133 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
137 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then134 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
138 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF135 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
139 kargs·=·["fips=1"]136 kargs·=·["fips=1"]
140 EOF137 EOF
141 fi138 fi
  
142 else139 else
143 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'140 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
144 fi141 fi
 142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 143 [customizations]
 144 fips·=·true
145 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules145 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules
146 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:146 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
147 ····*·GnuTLS·library147 ····*·GnuTLS·library
148 ····*·OpenSSL·library148 ····*·OpenSSL·library
149 ····*·NSS·library149 ····*·NSS·library
150 ····*·OpenJDK150 ····*·OpenJDK
151 ····*·Libkrb5151 ····*·Libkrb5
Offset 161, 19 lines modifiedOffset 161, 21 lines modified
161 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.161 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
162 Severity: ··medium162 Severity: ··medium
163 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed163 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
164 ············_\x8d_\x8i_\x8s_\x8a····CCI-002890,·CCI-002450,·CCI-003123164 ············_\x8d_\x8i_\x8s_\x8a····CCI-002890,·CCI-002450,·CCI-003123
165 References:·_\x8o_\x8s_\x8p_\x8p····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1165 References:·_\x8o_\x8s_\x8p_\x8p····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
166 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174166 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
167 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-258234r1051250_rule167 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-258234r1051250_rule
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 173 package·install·crypto-policies
169 [[packages]] 
170 name·=·"crypto-policies" 
171 version·=·"*" 
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
177 if·!·rpm·-q·--quiet·"crypto-policies"·;·then179 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 192, 14 lines modifiedOffset 194, 26 lines modified
192 ··-·DISA-STIG-RHEL-09-215100194 ··-·DISA-STIG-RHEL-09-215100
193 ··-·enable_strategy195 ··-·enable_strategy
194 ··-·low_complexity196 ··-·low_complexity
195 ··-·low_disruption197 ··-·low_disruption
196 ··-·medium_severity198 ··-·medium_severity
197 ··-·no_reboot_needed199 ··-·no_reboot_needed
198 ··-·package_crypto-policies_installed200 ··-·package_crypto-policies_installed
 201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 206 package·--add=crypto-policies
 207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 208 [[packages]]
 209 name·=·"crypto-policies"
 210 version·=·"*"
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
204 dnf·install·crypto-policies216 dnf·install·crypto-policies
Offset 211, 28 lines modifiedOffset 225, 14 lines modified
211 include·install_crypto-policies225 include·install_crypto-policies
  
212 class·install_crypto-policies·{226 class·install_crypto-policies·{
213 ··package·{·'crypto-policies':227 ··package·{·'crypto-policies':
214 ····ensure·=>·'installed',228 ····ensure·=>·'installed',
215 ··}229 ··}
216 }230 }
217 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
218 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
219 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
220 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
221 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
222 package·install·crypto-policies 
223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
224 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
225 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
226 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
227 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
228 package·--add=crypto-policies 
229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*231 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
230 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:232 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
231 $·sudo·update-crypto-policies·--set·FIPS:OSPP233 $·sudo·update-crypto-policies·--set·FIPS:OSPP
232 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.234 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
233 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.235 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
234 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.236 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
235 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.237 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 263, 14 lines modifiedOffset 263, 39 lines modified
263 »       echo·"to·see·what·package·to·(re)install"·>&2263 »       echo·"to·see·what·package·to·(re)install"·>&2
  
264 »       false··#·end·with·an·error·code264 »       false··#·end·with·an·error·code
265 elif·test·"$rc"·!=·0;·then265 elif·test·"$rc"·!=·0;·then
266 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2266 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
267 »       false··#·end·with·an·error·code267 »       false··#·end·with·an·error·code
268 fi268 fi
 269 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 270 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 271 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 349904/358489 bytes (97.61%) of diff not shown.
2.83 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-pci-dss.html
    
Offset 16722, 282 lines modifiedOffset 16722, 282 lines modified
00041510:·6574·3d22·2369·646d·3834·3830·2220·7461··et="#idm8480"·ta00041510:·6574·3d22·2369·646d·3834·3830·2220·7461··et="#idm8480"·ta
00041520:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00041520:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00041530:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00041530:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00041540:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00041540:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00041550:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00041550:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00041560:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00041560:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00041570:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00041570:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00041580:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
00041590:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
000415a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
000415b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
000415c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
000415d0:·6d38·3438·3022·3e3c·7072·653e·3c63·6f64··m8480"><pre><cod 
000415e0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
000415f0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
00041600:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
00041610:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
00041620:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
00041630:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
00041640:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
00041650:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
00041660:·646d·3834·3831·2220·7461·6269·6e64·6578··dm8481"·tabindex 
00041670:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00041680:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00041690:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
000416a0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
000416b0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
000416c0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
000416d0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b00041580:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
000416e0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00041590:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
000416f0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col000415a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00041700:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84000415b0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
00041710:·3831·223e·3c74·6162·6c65·2063·6c61·7373··81"><table·class000415c0:·3830·223e·3c74·6162·6c65·2063·6c61·7373··80"><table·class
00041720:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st000415d0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
00041730:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord000415e0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
00041740:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde000415f0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
00041750:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00041600:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
00041760:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00041610:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00041770:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00041620:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00041780:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio00041630:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00041790:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</00041640:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
000417a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00041650:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
000417b0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>00041660:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
000417c0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><00041670:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
000417d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00041680:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
000417e0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<00041690:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
000417f0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table000416a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
00041800:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re000416b0:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 000416c0:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
00041810:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
00041820:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
00041830:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
00041840:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
00041850:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
00041860:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
00041870:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
00041880:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
00041890:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
000418a0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
000418b0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
000418c0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
000418d0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
000418e0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
000418f0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d000416d0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
00041900:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn000416e0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
00041910:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da000416f0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
00041920:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla00041700:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
00041930:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00041710:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
00041940:·3d22·2369·646d·3834·3832·2220·7461·6269··="#idm8482"·tabi00041720:·6574·3d22·2369·646d·3834·3831·2220·7461··et="#idm8481"·ta
00041950:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00041730:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00041960:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00041740:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00041970:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00041750:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00041980:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00041760:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00041990:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00041770:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
000419a0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An00041780:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
000419b0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
000419c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
000419d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
000419e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
000419f0:·3d22·6964·6d38·3438·3222·3e3c·7461·626c··="idm8482"><tabl 
00041a00:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00041a10:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00041a20:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00041a30:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00041a40:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00041a50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00041a60:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00041a70:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00041790:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 000417a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 000417b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 000417c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000417d0:·2269·646d·3834·3831·223e·3c74·6162·6c65··"idm8481"><table
 000417e0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 000417f0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00041800:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00041810:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00041820:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00041830:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00041840:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00041850:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00041860:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00041870:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00041880:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 00041890:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 000418a0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00041a80:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><000418b0:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
00041a90:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00041aa0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00041ab0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00041ac0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00041ad0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00041ae0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00041af0:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
00041b00:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
00041b10:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
00041b20:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
00041b30:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
00041b40:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
00041b50:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R 
00041b60:·4845·4c2d·3039·2d36·3531·3031·300a·2020··HEL-09-651010.·· 
00041b70:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
00041b80:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
00041b90:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
00041ba0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
00041bb0:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
00041bc0:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
00041bd0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d 
Max diff block lines reached; 2696610/2734174 bytes (98.63%) of diff not shown.
231 KB
html2text {}
    
Offset 517, 19 lines modifiedOffset 517, 21 lines modified
517 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3517 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
518 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5518 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
519 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199519 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
520 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79520 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
521 ············_\x8c_\x8i_\x8s············6.1.1521 ············_\x8c_\x8i_\x8s············6.1.1
522 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2522 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
523 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule523 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 525 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 526 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 527 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 528 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 529 package·install·aide
525 [[packages]] 
526 name·=·"aide" 
527 version·=·"*" 
528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8530 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
529 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low531 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
530 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low532 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
531 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false533 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
532 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable534 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
533 #·Remediation·is·applicable·only·in·certain·platforms535 #·Remediation·is·applicable·only·in·certain·platforms
534 if·rpm·--quiet·-q·kernel;·then536 if·rpm·--quiet·-q·kernel;·then
Offset 575, 14 lines modifiedOffset 577, 26 lines modified
575 ··-·PCI-DSSv4-11.5.2577 ··-·PCI-DSSv4-11.5.2
576 ··-·enable_strategy578 ··-·enable_strategy
577 ··-·low_complexity579 ··-·low_complexity
578 ··-·low_disruption580 ··-·low_disruption
579 ··-·medium_severity581 ··-·medium_severity
580 ··-·no_reboot_needed582 ··-·no_reboot_needed
581 ··-·package_aide_installed583 ··-·package_aide_installed
 584 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 585 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 586 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 587 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 588 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 589 package·--add=aide
 590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 591 [[packages]]
 592 name·=·"aide"
 593 version·=·"*"
582 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
583 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
584 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
585 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
586 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
587 dnf·install·aide599 dnf·install·aide
Offset 594, 28 lines modifiedOffset 608, 14 lines modified
594 include·install_aide608 include·install_aide
  
595 class·install_aide·{609 class·install_aide·{
596 ··package·{·'aide':610 ··package·{·'aide':
597 ····ensure·=>·'installed',611 ····ensure·=>·'installed',
598 ··}612 ··}
599 }613 }
600 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
601 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
602 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
603 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
604 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
605 package·install·aide 
606 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
607 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
608 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
609 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
610 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
611 package·--add=aide 
612 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*614 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
613 Run·the·following·command·to·generate·a·new·database:615 Run·the·following·command·to·generate·a·new·database:
614 $·sudo·/usr/sbin/aide·--init616 $·sudo·/usr/sbin/aide·--init
615 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:617 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
616 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz618 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
617 To·initiate·a·manual·check,·run·the·following·command:619 To·initiate·a·manual·check,·run·the·following·command:
618 $·sudo·/usr/sbin/aide·--check620 $·sudo·/usr/sbin/aide·--check
Offset 969, 14 lines modifiedOffset 969, 39 lines modified
969 »       echo·"to·see·what·package·to·(re)install"·>&2969 »       echo·"to·see·what·package·to·(re)install"·>&2
  
970 »       false··#·end·with·an·error·code970 »       false··#·end·with·an·error·code
971 elif·test·"$rc"·!=·0;·then971 elif·test·"$rc"·!=·0;·then
972 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2972 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
973 »       false··#·end·with·an·error·code973 »       false··#·end·with·an·error·code
974 fi974 fi
 975 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 976 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 977 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 978 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 979 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 980 ---
 981 apiVersion:·machineconfiguration.openshift.io/v1
 982 kind:·MachineConfig
 983 spec:
 984 ··config:
 985 ····ignition:
 986 ······version:·3.1.0
 987 ····systemd:
 988 ······units:
 989 ········-·name:·configure-crypto-policy.service
 990 ··········enabled:·true
 991 ··········contents:·|
 992 ············[Unit]
 993 ············Before=kubelet.service
 994 ············[Service]
 995 ············Type=oneshot
 996 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 997 ············RemainAfterExit=yes
 998 ············[Install]
 999 ············WantedBy=multi-user.target
975 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81000 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
976 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1001 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
977 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1002 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
978 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1003 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
979 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict1004 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
980 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable1005 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
981 ··set_fact:1006 ··set_fact:
Offset 1027, 39 lines modifiedOffset 1052, 14 lines modified
1027 ··-·PCI-DSSv4-2.2.71052 ··-·PCI-DSSv4-2.2.7
1028 ··-·configure_crypto_policy1053 ··-·configure_crypto_policy
1029 ··-·high_severity1054 ··-·high_severity
1030 ··-·low_complexity1055 ··-·low_complexity
1031 ··-·low_disruption1056 ··-·low_disruption
1032 ··-·no_reboot_needed1057 ··-·no_reboot_needed
Max diff block lines reached; 231403/236305 bytes (97.93%) of diff not shown.
4.79 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-stig.html
    
Offset 15233, 282 lines modifiedOffset 15233, 282 lines modified
0003b800:·6765·743d·2223·6964·6d38·3438·3022·2074··get="#idm8480"·t0003b800:·6765·743d·2223·6964·6d38·3438·3022·2074··get="#idm8480"·t
0003b810:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b810:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b820:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b820:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b830:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b830:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b840:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b840:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b850:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b850:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b860:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b860:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b870:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003b880:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003b890:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b8a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b8b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b8c0:·646d·3834·3830·223e·3c70·7265·3e3c·636f··dm8480"><pre><co 
0003b8d0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003b8e0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003b8f0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003b900:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b910:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b920:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b930:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b940:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b950:·6964·6d38·3438·3122·2074·6162·696e·6465··idm8481"·tabinde 
0003b960:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b970:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b980:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b990:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b9a0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b9b0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b9c0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><0003b870:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003b9d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b880:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b9e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b890:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b9f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003b8a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003ba00:·3438·3122·3e3c·7461·626c·6520·636c·6173··481"><table·clas0003b8b0:·3438·3022·3e3c·7461·626c·6520·636c·6173··480"><table·clas
0003ba10:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b8c0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003ba20:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b8d0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003ba30:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b8e0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003ba40:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b8f0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003ba50:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b900:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003ba60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b910:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003ba70:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003b920:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003ba80:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003b930:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003ba90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b940:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003baa0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b950:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003bab0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003b960:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003bac0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003b970:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003bad0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003b980:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003bae0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003b990:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003baf0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R0003b9a0:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003b9b0:·636b·6167·6520·696e·7374·616c·6c20·6169··ckage·install·ai
0003bb00:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003bb10:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003bb20:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003bb30:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003bb40:·7420·2d71·206b·6572·6e65·6c3b·2074·6865··t·-q·kernel;·the 
0003bb50:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003bb60:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003bb70:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins 
0003bb80:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003bb90:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003bba0:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003bbb0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003bbc0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003bbd0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003bbe0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003b9c0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>
0003bbf0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003b9d0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003bc00:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003b9e0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003bc10:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003b9f0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003bc20:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003ba00:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003bc30:·743d·2223·6964·6d38·3438·3222·2074·6162··t="#idm8482"·tab0003ba10:·6765·743d·2223·6964·6d38·3438·3122·2074··get="#idm8481"·t
0003bc40:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003ba20:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003bc50:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003ba30:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003bc60:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003ba40:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003bc70:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003ba50:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003bc80:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003ba60:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003bc90:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003ba70:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003bca0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003bcb0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003bcc0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003bcd0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003bce0:·643d·2269·646d·3834·3832·223e·3c74·6162··d="idm8482"><tab 
0003bcf0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003bd00:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003bd10:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003bd20:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003bd30:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003bd40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bd50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003bd60:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003ba80:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003ba90:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003baa0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003bab0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003bac0:·3d22·6964·6d38·3438·3122·3e3c·7461·626c··="idm8481"><tabl
 0003bad0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003bae0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003baf0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003bb00:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003bb10:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003bb20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003bb30:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003bb40:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003bb50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003bb60:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003bb70:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003bb80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003bb90:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003bd70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bba0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003bd80:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003bd90:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003bda0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003bdb0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003bdc0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003bdd0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bde0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003bdf0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f 
0003be00:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f 
0003be10:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage 
0003be20:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:. 
0003be30:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003be40:·330a·2020·2d20·4449·5341·2d53·5449·472d··3.··-·DISA-STIG- 
0003be50:·5248·454c·2d30·392d·3635·3130·3130·0a20··RHEL-09-651010.· 
0003be60:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0003be70:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D 
0003be80:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-· 
0003be90:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2 
0003bea0:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0003beb0:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0003bec0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
Max diff block lines reached; 4506270/4543834 bytes (99.17%) of diff not shown.
469 KB
html2text {}
Max HTML report size reached
4.76 MB
./usr/share/doc/ssg-nondebian/ssg-cs9-guide-stig_gui.html
    
Offset 15251, 283 lines modifiedOffset 15251, 283 lines modified
0003b920:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b920:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b930:·646d·3834·3830·2220·7461·6269·6e64·6578··dm8480"·tabindex0003b930:·646d·3834·3830·2220·7461·6269·6e64·6578··dm8480"·tabindex
0003b940:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b940:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b950:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b950:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b960:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b960:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b970:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b970:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b980:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b980:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b990:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b990:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
0003b9a0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b9b0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b9c0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b9d0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b9e0:·7365·2220·6964·3d22·6964·6d38·3438·3022··se"·id="idm8480" 
0003b9f0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
0003ba00:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003ba10:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003ba20:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003ba30:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003ba40:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003ba50:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003ba60:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003ba70:·7461·7267·6574·3d22·2369·646d·3834·3831··target="#idm8481 
0003ba80:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003ba90:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003baa0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003bab0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003bac0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003bad0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003bae0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003baf0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b9a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003bb00:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b9b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003bb10:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b9c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003bb20:·2069·643d·2269·646d·3834·3831·223e·3c74···id="idm8481"><t0003b9d0:·2069·643d·2269·646d·3834·3830·223e·3c74···id="idm8480"><t
0003bb30:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b9e0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003bb40:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b9f0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003bb50:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003ba00:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003bb60:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003ba10:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003bb70:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003ba20:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003bb80:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003ba30:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003bb90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bba0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003bbb0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003bbc0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003bbd0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003bbe0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003bbf0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003bc00:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003bc10:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003bc20:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003bc30:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003bc40:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003bc50:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r 
0003bc60:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003bc70:·726e·656c·3b20·7468·656e·0a0a·6966·2021··rnel;·then..if·! 
0003bc80:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003bc90:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003bca0:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y 
0003bcb0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003bcc0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003bcd0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003bce0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003bcf0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003bd00:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003bd10:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003bd20:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003bd30:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003bd40:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003bd50:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003bd60:·3834·3832·2220·7461·6269·6e64·6578·3d22··8482"·tabindex=" 
0003bd70:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003bd80:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003bd90:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003bda0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003bdb0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003bdc0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003bdd0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003bde0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003bdf0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003be00:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003be10:·3438·3222·3e3c·7461·626c·6520·636c·6173··482"><table·clas 
0003be20:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003be30:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003be40:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003be50:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003be60:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003be70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003be80:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003be90:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003bea0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003ba40:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003beb0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003ba50:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003ba60:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003ba70:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003ba80:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003ba90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003baa0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003bab0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003bac0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003bad0:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i
 0003bae0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co
 0003baf0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003bb00:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003bb10:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003bb20:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003bb30:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003bb40:·646d·3834·3831·2220·7461·6269·6e64·6578··dm8481"·tabindex
 0003bb50:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003bb60:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003bb70:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003bb80:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003bb90:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003bba0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 0003bbb0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003bbc0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003bbd0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003bbe0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
 0003bbf0:·3831·223e·3c74·6162·6c65·2063·6c61·7373··81"><table·class
 0003bc00:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003bc10:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003bc20:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003bc30:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003bc40:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003bc50:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003bc60:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003bc70:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003bc80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003bc90:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003bca0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
Max diff block lines reached; 4477674/4515376 bytes (99.17%) of diff not shown.
465 KB
html2text {}
Max HTML report size reached
3.54 MB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-cusp_fedora.html
    
Offset 15616, 179 lines modifiedOffset 15616, 179 lines modified
0003cff0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003cff0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003d000:·3d22·2369·646d·3235·3636·2220·7461·6269··="#idm2566"·tabi0003d000:·3d22·2369·646d·3235·3636·2220·7461·6269··="#idm2566"·tabi
0003d010:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003d010:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003d020:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003d020:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003d030:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003d030:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003d040:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003d040:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003d050:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003d050:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003d060:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003d060:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
0003d070:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003d080:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003d090:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003d0a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003d0b0:·3d22·6964·6d32·3536·3622·3e3c·7461·626c··="idm2566"><tabl 
0003d0c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003d0d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003d0e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003d0f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003d100:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003d070:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
 0003d080:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003d090:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003d0a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003d0b0:·2069·643d·2269·646d·3235·3636·223e·3c74···id="idm2566"><t
 0003d0c0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003d0d0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003d0e0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003d0f0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003d100:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003d110:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003d120:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003d130:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003d110:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003d140:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003d150:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003d160:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
0003d120:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003d130:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003d140:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003d150:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003d160:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003d170:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003d170:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003d180:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003d180:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003d190:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t0003d190:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><
0003d1a0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003d1a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
0003d1b0:·636f·6465·3e2d·206e·616d·653a·2058·4343··code>-·name:·XCC 
0003d1c0:·4446·2056·616c·7565·2076·6172·5f73·7973··DF·Value·var_sys 
0003d1d0:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic 
0003d1e0:·7920·2320·7072·6f6d·6f74·6520·746f·2076··y·#·promote·to·v 
0003d1f0:·6172·6961·626c·650a·2020·7365·745f·6661··ariable.··set_fa 
0003d200:·6374·3a0a·2020·2020·7661·725f·7379·7374··ct:.····var_syst0003d1b0:·3e3c·636f·6465·3e2d·2d2d·0a61·7069·5665··><code>---.apiVe
 0003d1c0:·7273·696f·6e3a·206d·6163·6869·6e65·636f··rsion:·machineco
 0003d1d0:·6e66·6967·7572·6174·696f·6e2e·6f70·656e··nfiguration.open
 0003d1e0:·7368·6966·742e·696f·2f76·310a·6b69·6e64··shift.io/v1.kind
 0003d1f0:·3a20·4d61·6368·696e·6543·6f6e·6669·670a··:·MachineConfig.
 0003d200:·7370·6563·3a0a·2020·636f·6e66·6967·3a0a··spec:.··config:.
 0003d210:·2020·2020·6967·6e69·7469·6f6e·3a0a·2020······ignition:.··
 0003d220:·2020·2020·7665·7273·696f·6e3a·2033·2e31······version:·3.1
 0003d230:·2e30·0a20·2020·2073·7973·7465·6d64·3a0a··.0.····systemd:.
 0003d240:·2020·2020·2020·756e·6974·733a·0a20·2020········units:.···
 0003d250:·2020·2020·202d·206e·616d·653a·2063·6f6e·······-·name:·con
 0003d260:·6669·6775·7265·2d63·7279·7074·6f2d·706f··figure-crypto-po
 0003d270:·6c69·6379·2e73·6572·7669·6365·0a20·2020··licy.service.···
 0003d280:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:·
 0003d290:·7472·7565·0a20·2020·2020·2020·2020·2063··true.··········c
 0003d2a0:·6f6e·7465·6e74·733a·207c·0a20·2020·2020··ontents:·|.·····
 0003d2b0:·2020·2020·2020·205b·556e·6974·5d0a·2020·········[Unit].··
 0003d2c0:·2020·2020·2020·2020·2020·4265·666f·7265············Before
 0003d2d0:·3d6b·7562·656c·6574·2e73·6572·7669·6365··=kubelet.service
 0003d2e0:·0a20·2020·2020·2020·2020·2020·205b·5365··.············[Se
 0003d2f0:·7276·6963·655d·0a20·2020·2020·2020·2020··rvice].·········
 0003d300:·2020·2054·7970·653d·6f6e·6573·686f·740a·····Type=oneshot.
 0003d310:·2020·2020·2020·2020·2020·2020·4578·6563··············Exec
 0003d320:·5374·6172·743d·7570·6461·7465·2d63·7279··Start=update-cry
 0003d330:·7074·6f2d·706f·6c69·6369·6573·202d·2d73··pto-policies·--s
 0003d340:·6574·207b·7b2e·7661·725f·7379·7374·656d··et·{{.var_system
0003d210:·656d·5f63·7279·7074·6f5f·706f·6c69·6379··em_crypto_policy0003d350:·5f63·7279·7074·6f5f·706f·6c69·6379·7d7d··_crypto_policy}}
 0003d360:·0a20·2020·2020·2020·2020·2020·2052·656d··.············Rem
 0003d370:·6169·6e41·6674·6572·4578·6974·3d79·6573··ainAfterExit=yes
 0003d380:·0a20·2020·2020·2020·2020·2020·205b·496e··.············[In
 0003d390:·7374·616c·6c5d·0a20·2020·2020·2020·2020··stall].·········
 0003d3a0:·2020·2057·616e·7465·6442·793d·6d75·6c74·····WantedBy=mult
 0003d3b0:·692d·7573·6572·2e74·6172·6765·740a·3c2f··i-user.target.</
 0003d3c0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003d3d0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003d3e0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003d3f0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003d400:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003d410:·2369·646d·3235·3637·2220·7461·6269·6e64··#idm2567"·tabind
 0003d420:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003d430:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003d440:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003d450:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003d460:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003d470:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
 0003d480:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
 0003d490:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003d4a0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003d4b0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003d4c0:·6964·6d32·3536·3722·3e3c·7461·626c·6520··idm2567"><table·
 0003d4d0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003d4e0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003d4f0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003d500:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003d510:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003d520:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003d530:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003d540:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003d550:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003d560:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003d570:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003d580:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003d590:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re
 0003d5a0:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>
 0003d5b0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003d5c0:·6465·3e2d·206e·616d·653a·2058·4343·4446··de>-·name:·XCCDF
 0003d5d0:·2056·616c·7565·2076·6172·5f73·7973·7465···Value·var_syste
0003d220:·3a20·2121·7374·7220·3c61·6262·7220·7469··:·!!str·<abbr·ti 
0003d230:·746c·653d·2266·726f·6d20·5072·6f66·696c··tle="from·Profil 
0003d240:·652f·7265·6669·6e65·2d76·616c·7565·3a20··e/refine-value:· 
0003d250:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro 
0003d260:·6a65·6374·2e63·6f6e·7465·6e74·5f76·616c··ject.content_val 
0003d270:·7565·5f76·6172·5f73·7973·7465·6d5f·6372··ue_var_system_cr 
0003d280:·7970·746f·5f70·6f6c·6963·7922·3e44·4546··ypto_policy">DEF 
0003d290:·4155·4c54·3c2f·6162·6272·3e0a·2020·7461··AULT</abbr>.··ta 
0003d2a0:·6773·3a0a·2020·2020·2d20·616c·7761·7973··gs:.····-·always 
0003d2b0:·0a0a·2d20·6e61·6d65·3a20·436f·6e66·6967··..-·name:·Config 
0003d2c0:·7572·6520·5379·7374·656d·2043·7279·7074··ure·System·Crypt 
0003d2d0:·6f67·7261·7068·7920·506f·6c69·6379·0a20··ography·Policy.· 
0003d2e0:·206c·696e·6569·6e66·696c·653a·0a20·2020···lineinfile:.··· 
Max diff block lines reached; 3384744/3408094 bytes (99.31%) of diff not shown.
296 KB
html2text {}
    
Offset 228, 14 lines modifiedOffset 228, 39 lines modified
228 »       echo·"to·see·what·package·to·(re)install"·>&2228 »       echo·"to·see·what·package·to·(re)install"·>&2
  
229 »       false··#·end·with·an·error·code229 »       false··#·end·with·an·error·code
230 elif·test·"$rc"·!=·0;·then230 elif·test·"$rc"·!=·0;·then
231 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2231 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
232 »       false··#·end·with·an·error·code232 »       false··#·end·with·an·error·code
233 fi233 fi
 234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 239 ---
 240 apiVersion:·machineconfiguration.openshift.io/v1
 241 kind:·MachineConfig
 242 spec:
 243 ··config:
 244 ····ignition:
 245 ······version:·3.1.0
 246 ····systemd:
 247 ······units:
 248 ········-·name:·configure-crypto-policy.service
 249 ··········enabled:·true
 250 ··········contents:·|
 251 ············[Unit]
 252 ············Before=kubelet.service
 253 ············[Service]
 254 ············Type=oneshot
 255 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 256 ············RemainAfterExit=yes
 257 ············[Install]
 258 ············WantedBy=multi-user.target
234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8259 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low260 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low261 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false262 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict263 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
239 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable264 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
240 ··set_fact:265 ··set_fact:
Offset 280, 39 lines modifiedOffset 305, 14 lines modified
280 ··-·PCI-DSSv4-2.2.7305 ··-·PCI-DSSv4-2.2.7
281 ··-·configure_crypto_policy306 ··-·configure_crypto_policy
282 ··-·high_severity307 ··-·high_severity
283 ··-·low_complexity308 ··-·low_complexity
284 ··-·low_disruption309 ··-·low_disruption
285 ··-·no_reboot_needed310 ··-·no_reboot_needed
286 ··-·restrict_strategy311 ··-·restrict_strategy
287 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
288 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
289 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
290 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
291 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
292 --- 
293 apiVersion:·machineconfiguration.openshift.io/v1 
294 kind:·MachineConfig 
295 spec: 
296 ··config: 
297 ····ignition: 
298 ······version:·3.1.0 
299 ····systemd: 
300 ······units: 
301 ········-·name:·configure-crypto-policy.service 
302 ··········enabled:·true 
303 ··········contents:·| 
304 ············[Unit] 
305 ············Before=kubelet.service 
306 ············[Service] 
307 ············Type=oneshot 
308 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
309 ············RemainAfterExit=yes 
310 ············[Install] 
311 ············WantedBy=multi-user.target 
312 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·G\x8Gn\x8nu\x8uT\x8TL\x8LS\x8S·l\x8li\x8ib\x8br\x8ra\x8ar\x8ry\x8y·t\x8to\x8o·u\x8us\x8se\x8e·D\x8Do\x8oD\x8D-\x8-a\x8ap\x8pp\x8pr\x8ro\x8ov\x8ve\x8ed\x8d·T\x8TL\x8LS\x8S·E\x8En\x8nc\x8cr\x8ry\x8yp\x8pt\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*312 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·G\x8Gn\x8nu\x8uT\x8TL\x8LS\x8S·l\x8li\x8ib\x8br\x8ra\x8ar\x8ry\x8y·t\x8to\x8o·u\x8us\x8se\x8e·D\x8Do\x8oD\x8D-\x8-a\x8ap\x8pp\x8pr\x8ro\x8ov\x8ve\x8ed\x8d·T\x8TL\x8LS\x8S·E\x8En\x8nc\x8cr\x8ry\x8yp\x8pt\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
313 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·GnuTLS·is·supported·by·system·crypto·policy,·but·the·GnuTLS·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·/etc/crypto-policies/back-ends/gnutls.config·contains·the·following·line·and·is·not·commented·out:·+VERS-ALL:-VERS-DTLS0.9:-VERS-SSL3.0:-VERS-TLS1.0:-VERS-TLS1.1:-VERS-DTLS1.0313 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·GnuTLS·is·supported·by·system·crypto·policy,·but·the·GnuTLS·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·/etc/crypto-policies/back-ends/gnutls.config·contains·the·following·line·and·is·not·commented·out:·+VERS-ALL:-VERS-DTLS0.9:-VERS-SSL3.0:-VERS-TLS1.0:-VERS-TLS1.1:-VERS-DTLS1.0
314 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·GnuTLS·library·violate·expectations,·and·makes·system·configuration·more·fragmented.314 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·the·GnuTLS·library·violate·expectations,·and·makes·system·configuration·more·fragmented.
315 Severity: ··medium315 Severity: ··medium
316 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_gnutls_tls_crypto_policy316 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_gnutls_tls_crypto_policy
317 ············_\x8d_\x8i_\x8s_\x8a···CCI-001453317 ············_\x8d_\x8i_\x8s_\x8a···CCI-001453
318 References:·_\x8n_\x8i_\x8s_\x8t···AC-17(2)318 References:·_\x8n_\x8i_\x8s_\x8t···AC-17(2)
Offset 857, 19 lines modifiedOffset 857, 21 lines modified
857 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235857 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
858 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386858 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
859 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)859 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
860 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1860 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
861 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125861 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
862 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33862 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
863 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2863 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
864 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8864 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 865 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 866 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 867 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 868 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 869 package·install·sudo
865 [[packages]] 
866 name·=·"sudo" 
867 version·=·"*" 
868 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8870 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
869 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low871 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
870 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low872 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
871 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false873 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
872 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable874 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
873 #·Remediation·is·applicable·only·in·certain·platforms875 #·Remediation·is·applicable·only·in·certain·platforms
874 if·rpm·--quiet·-q·kernel;·then876 if·rpm·--quiet·-q·kernel;·then
Offset 911, 14 lines modifiedOffset 913, 26 lines modified
911 ··-·PCI-DSSv4-2.2.6913 ··-·PCI-DSSv4-2.2.6
912 ··-·enable_strategy914 ··-·enable_strategy
913 ··-·low_complexity915 ··-·low_complexity
914 ··-·low_disruption916 ··-·low_disruption
915 ··-·medium_severity917 ··-·medium_severity
916 ··-·no_reboot_needed918 ··-·no_reboot_needed
917 ··-·package_sudo_installed919 ··-·package_sudo_installed
 920 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 921 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 922 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 923 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 924 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 925 package·--add=sudo
 926 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 927 [[packages]]
 928 name·=·"sudo"
 929 version·=·"*"
918 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8930 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
919 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low931 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
920 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low932 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 298025/303185 bytes (98.30%) of diff not shown.
1.87 MB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-ospp.html
    
Offset 16023, 62 lines modifiedOffset 16023, 62 lines modified
0003e960:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003e960:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003e970:·646d·3234·3032·2220·7461·6269·6e64·6578··dm2402"·tabindex0003e970:·646d·3234·3032·2220·7461·6269·6e64·6578··dm2402"·tabindex
0003e980:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003e980:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003e990:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003e990:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003e9a0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003e9a0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003e9b0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003e9b0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003e9c0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003e9c0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003e9d0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil 
0003e9e0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003e9f0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003ea00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003ea10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003ea20:·7365·2220·6964·3d22·6964·6d32·3430·3222··se"·id="idm2402" 
0003ea30:·3e3c·7072·653e·3c63·6f64·653e·0a5b·6375··><pre><code>.[cu 
0003ea40:·7374·6f6d·697a·6174·696f·6e73·5d0a·6669··stomizations].fi 
0003ea50:·7073·203d·2074·7275·650a·3c2f·636f·6465··ps·=·true.</code 
0003ea60:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003ea70:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003ea80:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003ea90:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003eaa0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003eab0:·3234·3033·2220·7461·6269·6e64·6578·3d22··2403"·tabindex=" 
0003eac0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003ead0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003eae0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003eaf0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003eb00:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003eb10:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc0003e9d0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003eb20:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0003e9e0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
0003eb30:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003e9f0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003eb40:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003ea00:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003eb50:·7073·6522·2069·643d·2269·646d·3234·3033··pse"·id="idm24030003ea10:·6c61·7073·6522·2069·643d·2269·646d·3234··lapse"·id="idm24
0003eb60:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R0003ea20:·3032·223e·3c70·7265·3e3c·636f·6465·3e23··02"><pre><code>#
 0003ea30:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003ea40:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003ea50:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003ea60:·6f72·6d73·0a69·6620·2820·2120·2820·5b20··orms.if·(·!·(·[·
 0003ea70:·2224·7b63·6f6e·7461·696e·6572·3a2d·7d22··"${container:-}"
 0003ea80:·203d·3d20·2262·7772·6170·2d6f·7362·7569···==·"bwrap-osbui
 0003ea90:·6c64·2220·5d20·2920·2661·6d70·3b26·616d··ld"·]·)·&amp;&am
 0003eaa0:·703b·2072·706d·202d·2d71·7569·6574·202d··p;·rpm·--quiet·-
 0003eab0:·7120·6b65·726e·656c·2029·3b20·7468·656e··q·kernel·);·then
 0003eac0:·0a0a·6966·205b·5b20·2224·4f53·4341·505f··..if·[[·"$OSCAP_
 0003ead0:·424f·4f54·435f·4255·494c·4422·203d·3d20··BOOTC_BUILD"·==·
 0003eae0:·2259·4553·2220·5d5d·3b20·7468·656e·0a09··"YES"·]];·then..
 0003eaf0:·6361·7420·2667·743b·202f·7573·722f·6c69··cat·&gt;·/usr/li
 0003eb00:·622f·626f·6f74·632f·6b61·7267·732e·642f··b/bootc/kargs.d/
 0003eb10:·3031·2d66·6970·732e·746f·6d6c·2026·6c74··01-fips.toml·&lt
 0003eb20:·3b26·6c74·3b20·454f·460a·6b61·7267·7320··;&lt;·EOF.kargs·
 0003eb30:·3d20·5b22·6669·7073·3d31·225d·0a45·4f46··=·["fips=1"].EOF
 0003eb40:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 0003eb50:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
0003eb70:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap0003eb60:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
0003eb80:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003eb90:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003eba0:·6d73·0a69·6620·2820·2120·2820·5b20·2224··ms.if·(·!·(·[·"$ 
0003ebb0:·7b63·6f6e·7461·696e·6572·3a2d·7d22·203d··{container:-}"·= 
0003ebc0:·3d20·2262·7772·6170·2d6f·7362·7569·6c64··=·"bwrap-osbuild 
0003ebd0:·2220·5d20·2920·2661·6d70·3b26·616d·703b··"·]·)·&amp;&amp; 
0003ebe0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003ebf0:·6b65·726e·656c·2029·3b20·7468·656e·0a0a··kernel·);·then.. 
0003ec00:·6966·205b·5b20·2224·4f53·4341·505f·424f··if·[[·"$OSCAP_BO 
0003ec10:·4f54·435f·4255·494c·4422·203d·3d20·2259··OTC_BUILD"·==·"Y 
0003ec20:·4553·2220·5d5d·3b20·7468·656e·0a09·6361··ES"·]];·then..ca 
0003ec30:·7420·2667·743b·202f·7573·722f·6c69·622f··t·&gt;·/usr/lib/ 
0003ec40:·626f·6f74·632f·6b61·7267·732e·642f·3031··bootc/kargs.d/01 
0003ec50:·2d66·6970·732e·746f·6d6c·2026·6c74·3b26··-fips.toml·&lt;& 
0003ec60:·6c74·3b20·454f·460a·6b61·7267·7320·3d20··lt;·EOF.kargs·=· 
0003ec70:·5b22·6669·7073·3d31·225d·0a45·4f46·0a66··["fips=1"].EOF.f 
0003ec80:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003ec90:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003eca0:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003ecb0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth0003eb70:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
0003ecc0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi0003eb80:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 0003eb90:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 0003eba0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003ebb0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003ebc0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003ebd0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003ebe0:·6765·743d·2223·6964·6d32·3430·3322·2074··get="#idm2403"·t
 0003ebf0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003ec00:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003ec10:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003ec20:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003ec30:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003ec40:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003ec50:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003ec60:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003ec70:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003ec80:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003ec90:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003eca0:·646d·3234·3033·223e·3c70·7265·3e3c·636f··dm2403"><pre><co
 0003ecb0:·6465·3e0a·5b63·7573·746f·6d69·7a61·7469··de>.[customizati
 0003ecc0:·6f6e·735d·0a66·6970·7320·3d20·7472·7565··ons].fips·=·true
0003ecd0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003ecd0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003ece0:·6469·763e·3c2f·6469·763e·3c2f·7464·3e3c··div></div></td><0003ece0:·6469·763e·3c2f·6469·763e·3c2f·7464·3e3c··div></div></td><
0003ecf0:·2f74·723e·3c2f·7462·6f64·793e·3c2f·7461··/tr></tbody></ta0003ecf0:·2f74·723e·3c2f·7462·6f64·793e·3c2f·7461··/tr></tbody></ta
0003ed00:·626c·653e·3c2f·7464·3e3c·2f74·723e·3c74··ble></td></tr><t0003ed00:·626c·653e·3c2f·7464·3e3c·2f74·723e·3c74··ble></td></tr><t
0003ed10:·7220·6461·7461·2d74·742d·6964·3d22·6368··r·data-tt-id="ch0003ed10:·7220·6461·7461·2d74·742d·6964·3d22·6368··r·data-tt-id="ch
0003ed20:·696c·6472·656e·2d78·6363·6466·5f6f·7267··ildren-xccdf_org0003ed20:·696c·6472·656e·2d78·6363·6466·5f6f·7267··ildren-xccdf_org
0003ed30:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont0003ed30:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
Offset 16958, 179 lines modifiedOffset 16958, 179 lines modified
000423d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe000423d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
000423e0:·743d·2223·6964·6d32·3536·3622·2074·6162··t="#idm2566"·tab000423e0:·743d·2223·6964·6d32·3536·3622·2074·6162··t="#idm2566"·tab
000423f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="000423f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00042400:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00042400:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00042410:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00042410:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00042420:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00042420:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00042430:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00042430:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00042440:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00042440:·2122·3e52·656d·6564·6961·7469·6f6e·204b··!">Remediation·K
00042450:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
00042460:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00042470:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00042480:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00042490:·643d·2269·646d·3235·3636·223e·3c74·6162··d="idm2566"><tab 
000424a0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
000424b0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
000424c0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
000424d0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
000424e0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00042450:·7562·6572·6e65·7465·7320·736e·6970·7065··ubernetes·snippe
 00042460:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 00042470:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 00042480:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 00042490:·2220·6964·3d22·6964·6d32·3536·3622·3e3c··"·id="idm2566"><
 000424a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 000424b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 000424c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
Max diff block lines reached; 1733600/1764566 bytes (98.25%) of diff not shown.
190 KB
html2text {}
    
Offset 332, 31 lines modifiedOffset 332, 31 lines modified
332 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode332 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
333 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877333 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
334 ············_\x8i_\x8s_\x8m······1446334 ············_\x8i_\x8s_\x8m······1446
335 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1335 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
336 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12336 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
337 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1337 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
338 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176338 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
339 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
340 [customizations] 
341 fips·=·true 
342 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8339 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
343 #·Remediation·is·applicable·only·in·certain·platforms340 #·Remediation·is·applicable·only·in·certain·platforms
344 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then341 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
345 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then342 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
346 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF343 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
347 kargs·=·["fips=1"]344 kargs·=·["fips=1"]
348 EOF345 EOF
349 fi346 fi
  
350 else347 else
351 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'348 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
352 fi349 fi
 350 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 351 [customizations]
 352 fips·=·true
353 Group  ·System·Cryptographic·Policies·  Group·contains·6·rules353 Group  ·System·Cryptographic·Policies·  Group·contains·6·rules
354 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:354 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
355 ····*·GnuTLS·library355 ····*·GnuTLS·library
356 ····*·OpenSSL·library356 ····*·OpenSSL·library
357 ····*·NSS·library357 ····*·NSS·library
358 ····*·OpenJDK358 ····*·OpenJDK
359 ····*·Libkrb5359 ····*·Libkrb5
Offset 498, 14 lines modifiedOffset 498, 39 lines modified
498 »       echo·"to·see·what·package·to·(re)install"·>&2498 »       echo·"to·see·what·package·to·(re)install"·>&2
  
499 »       false··#·end·with·an·error·code499 »       false··#·end·with·an·error·code
500 elif·test·"$rc"·!=·0;·then500 elif·test·"$rc"·!=·0;·then
501 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2501 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
502 »       false··#·end·with·an·error·code502 »       false··#·end·with·an·error·code
503 fi503 fi
 504 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 505 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 506 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 507 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 508 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 509 ---
 510 apiVersion:·machineconfiguration.openshift.io/v1
 511 kind:·MachineConfig
 512 spec:
 513 ··config:
 514 ····ignition:
 515 ······version:·3.1.0
 516 ····systemd:
 517 ······units:
 518 ········-·name:·configure-crypto-policy.service
 519 ··········enabled:·true
 520 ··········contents:·|
 521 ············[Unit]
 522 ············Before=kubelet.service
 523 ············[Service]
 524 ············Type=oneshot
 525 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 526 ············RemainAfterExit=yes
 527 ············[Install]
 528 ············WantedBy=multi-user.target
504 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
505 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
506 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low531 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
507 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false532 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
508 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict533 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
509 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable534 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
510 ··set_fact:535 ··set_fact:
Offset 550, 39 lines modifiedOffset 575, 14 lines modified
550 ··-·PCI-DSSv4-2.2.7575 ··-·PCI-DSSv4-2.2.7
551 ··-·configure_crypto_policy576 ··-·configure_crypto_policy
552 ··-·high_severity577 ··-·high_severity
553 ··-·low_complexity578 ··-·low_complexity
554 ··-·low_disruption579 ··-·low_disruption
555 ··-·no_reboot_needed580 ··-·no_reboot_needed
556 ··-·restrict_strategy581 ··-·restrict_strategy
557 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
558 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
559 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
560 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
561 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
562 --- 
563 apiVersion:·machineconfiguration.openshift.io/v1 
564 kind:·MachineConfig 
565 spec: 
566 ··config: 
567 ····ignition: 
568 ······version:·3.1.0 
569 ····systemd: 
570 ······units: 
571 ········-·name:·configure-crypto-policy.service 
572 ··········enabled:·true 
573 ··········contents:·| 
574 ············[Unit] 
575 ············Before=kubelet.service 
576 ············[Service] 
577 ············Type=oneshot 
578 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
579 ············RemainAfterExit=yes 
580 ············[Install] 
581 ············WantedBy=multi-user.target 
582 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*582 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
583 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured·correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies·targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,·Kerberos·is·configured·to·use·the·system-wide·crypto·policy·settings.583 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured·correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies·targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,·Kerberos·is·configured·to·use·the·system-wide·crypto·policy·settings.
584 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·Kerberos·violate·expectations,·and·makes·system·configuration·more·fragmented.584 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·Kerberos·violate·expectations,·and·makes·system·configuration·more·fragmented.
585 Severity: ··high585 Severity: ··high
586 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy586 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy
587 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000803587 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000803
588 ············_\x8i_\x8s_\x8m······0418,·1055,·1402588 ············_\x8i_\x8s_\x8m······0418,·1055,·1402
Offset 2503, 19 lines modifiedOffset 2503, 21 lines modified
2503 The·rng-tools·package·can·be·installed·with·the·following·command:2503 The·rng-tools·package·can·be·installed·with·the·following·command:
2504 $·sudo·dnf·install·rng-tools2504 $·sudo·dnf·install·rng-tools
2505 Rationale:··rng-tools·provides·hardware·random·number·generator·tools,·such·as·those·used·in·the·formation·of·x509/PKI·certificates.2505 Rationale:··rng-tools·provides·hardware·random·number·generator·tools,·such·as·those·used·in·the·formation·of·x509/PKI·certificates.
2506 Severity: ··low2506 Severity: ··low
2507 Rule·ID:····xccdf_org.ssgproject.content_rule_package_rng-tools_installed2507 Rule·ID:····xccdf_org.ssgproject.content_rule_package_rng-tools_installed
2508 References:·_\x8d_\x8i_\x8s_\x8a···CCI-0003662508 References:·_\x8d_\x8i_\x8s_\x8a···CCI-000366
2509 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002272509 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
2510 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82510 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 2511 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2512 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2513 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 187826/194037 bytes (96.80%) of diff not shown.
1.52 MB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-pci-dss.html
    
Offset 16631, 278 lines modifiedOffset 16631, 278 lines modified
00040f60:·6574·3d22·2369·646d·3231·3035·2220·7461··et="#idm2105"·ta00040f60:·6574·3d22·2369·646d·3231·3035·2220·7461··et="#idm2105"·ta
00040f70:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00040f70:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00040f80:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00040f80:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00040f90:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00040f90:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00040fa0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00040fa0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00040fb0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00040fb0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00040fc0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00040fc0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00040fd0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
00040fe0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
00040ff0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00041000:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00041010:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00041020:·6d32·3130·3522·3e3c·7072·653e·3c63·6f64··m2105"><pre><cod 
00041030:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
00041040:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
00041050:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
00041060:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
00041070:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
00041080:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
00041090:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
000410a0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
000410b0:·646d·3231·3036·2220·7461·6269·6e64·6578··dm2106"·tabindex 
000410c0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
000410d0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
000410e0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
000410f0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
00041100:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
00041110:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
00041120:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b00040fd0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
00041130:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00040fe0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
00041140:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00040ff0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
00041150:·6c61·7073·6522·2069·643d·2269·646d·3231··lapse"·id="idm2100041000:·6c61·7073·6522·2069·643d·2269·646d·3231··lapse"·id="idm21
00041160:·3036·223e·3c74·6162·6c65·2063·6c61·7373··06"><table·class00041010:·3035·223e·3c74·6162·6c65·2063·6c61·7373··05"><table·class
00041170:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00041020:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
00041180:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00041030:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
00041190:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde00041040:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
000411a0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00041050:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
000411b0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00041060:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
000411c0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00041070:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
000411d0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio00041080:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
000411e0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</00041090:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
000411f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>000410a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00041200:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>000410b0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
00041210:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><000410c0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
00041220:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:000410d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
00041230:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<000410e0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
00041240:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table000410f0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
00041250:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re00041100:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 00041110:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
00041260:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
00041270:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
00041280:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
00041290:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
000412a0:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
000412b0:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
000412c0:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
000412d0:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
000412e0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
000412f0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
00041300:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
00041310:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
00041320:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
00041330:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
00041340:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d00041120:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
00041350:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn00041130:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
00041360:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da00041140:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
00041370:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla00041150:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
00041380:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00041160:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
00041390:·3d22·2369·646d·3231·3037·2220·7461·6269··="#idm2107"·tabi00041170:·6574·3d22·2369·646d·3231·3036·2220·7461··et="#idm2106"·ta
000413a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00041180:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
000413b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00041190:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
000413c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit000411a0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
000413d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·000411b0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
000413e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!000411c0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
000413f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An000411d0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00041400:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
00041410:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00041420:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
00041430:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
00041440:·3d22·6964·6d32·3130·3722·3e3c·7461·626c··="idm2107"><tabl 
00041450:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00041460:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00041470:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00041480:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00041490:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
000414a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
000414b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
000414c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
000414d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
000414e0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
000414f0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00041500:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00041510:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00041520:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00041530:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00041540:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
00041550:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
00041560:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
00041570:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
00041580:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
00041590:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
000415a0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
000415b0:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI 
000415c0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.·· 
000415d0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5 
000415e0:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st 
000415f0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c 
00041600:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo 
00041610:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··- 
00041620:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity 
00041630:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n 
00041640:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag 
00041650:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed 
00041660:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure 
00041670:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install 
00041680:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.·· 
00041690:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.··· 
000416a0:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present. 
000416b0:·2020·7768·656e·3a20·2722·6b65·726e·656c····when:·'"kernel 
000416c0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
000416d0:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t 
000416e0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5. 
000416f0:·3130·2e31·2e33·0a20·202d·204e·4953·542d··10.1.3.··-·NIST- 
00041700:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
00041710:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
00041720:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
00041730:·342d·3131·2e35·2e32·0a20·202d·2065·6e61··4-11.5.2.··-·ena 
Max diff block lines reached; 1435177/1472189 bytes (97.49%) of diff not shown.
114 KB
html2text {}
    
Offset 498, 19 lines modifiedOffset 498, 21 lines modified
498 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3498 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
499 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)499 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
500 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3500 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
501 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5501 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
502 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199502 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
503 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79503 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
504 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2504 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
505 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8505 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 506 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 507 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 508 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 509 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 510 package·install·aide
506 [[packages]] 
507 name·=·"aide" 
508 version·=·"*" 
509 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8511 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
510 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low512 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
511 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low513 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
512 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false514 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
513 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable515 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
514 #·Remediation·is·applicable·only·in·certain·platforms516 #·Remediation·is·applicable·only·in·certain·platforms
515 if·rpm·--quiet·-q·kernel;·then517 if·rpm·--quiet·-q·kernel;·then
Offset 554, 14 lines modifiedOffset 556, 26 lines modified
554 ··-·PCI-DSSv4-11.5.2556 ··-·PCI-DSSv4-11.5.2
555 ··-·enable_strategy557 ··-·enable_strategy
556 ··-·low_complexity558 ··-·low_complexity
557 ··-·low_disruption559 ··-·low_disruption
558 ··-·medium_severity560 ··-·medium_severity
559 ··-·no_reboot_needed561 ··-·no_reboot_needed
560 ··-·package_aide_installed562 ··-·package_aide_installed
 563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 564 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 565 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 566 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 567 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 568 package·--add=aide
 569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 570 [[packages]]
 571 name·=·"aide"
 572 version·=·"*"
561 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
562 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low574 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
563 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low575 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
564 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false576 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
565 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable577 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
566 dnf·install·aide578 dnf·install·aide
Offset 573, 28 lines modifiedOffset 587, 14 lines modified
573 include·install_aide587 include·install_aide
  
574 class·install_aide·{588 class·install_aide·{
575 ··package·{·'aide':589 ··package·{·'aide':
576 ····ensure·=>·'installed',590 ····ensure·=>·'installed',
577 ··}591 ··}
578 }592 }
579 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
580 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
581 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
582 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
583 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
584 package·install·aide 
585 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
586 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
587 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
588 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
589 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
590 package·--add=aide 
591 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*593 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
592 Run·the·following·command·to·generate·a·new·database:594 Run·the·following·command·to·generate·a·new·database:
593 $·sudo·/usr/sbin/aide·--init595 $·sudo·/usr/sbin/aide·--init
594 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:596 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
595 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz597 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
596 To·initiate·a·manual·check,·run·the·following·command:598 To·initiate·a·manual·check,·run·the·following·command:
597 $·sudo·/usr/sbin/aide·--check599 $·sudo·/usr/sbin/aide·--check
Offset 1034, 14 lines modifiedOffset 1034, 39 lines modified
1034 »       echo·"to·see·what·package·to·(re)install"·>&21034 »       echo·"to·see·what·package·to·(re)install"·>&2
  
1035 »       false··#·end·with·an·error·code1035 »       false··#·end·with·an·error·code
1036 elif·test·"$rc"·!=·0;·then1036 elif·test·"$rc"·!=·0;·then
1037 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&21037 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
1038 »       false··#·end·with·an·error·code1038 »       false··#·end·with·an·error·code
1039 fi1039 fi
 1040 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1041 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1042 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1043 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 1044 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 1045 ---
 1046 apiVersion:·machineconfiguration.openshift.io/v1
 1047 kind:·MachineConfig
 1048 spec:
 1049 ··config:
 1050 ····ignition:
 1051 ······version:·3.1.0
 1052 ····systemd:
 1053 ······units:
 1054 ········-·name:·configure-crypto-policy.service
 1055 ··········enabled:·true
 1056 ··········contents:·|
 1057 ············[Unit]
 1058 ············Before=kubelet.service
 1059 ············[Service]
 1060 ············Type=oneshot
 1061 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 1062 ············RemainAfterExit=yes
 1063 ············[Install]
 1064 ············WantedBy=multi-user.target
1040 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81065 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1041 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1066 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1042 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1067 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1043 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1068 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1044 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict1069 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
1045 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable1070 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
1046 ··set_fact:1071 ··set_fact:
Offset 1086, 39 lines modifiedOffset 1111, 14 lines modified
1086 ··-·PCI-DSSv4-2.2.71111 ··-·PCI-DSSv4-2.2.7
1087 ··-·configure_crypto_policy1112 ··-·configure_crypto_policy
1088 ··-·high_severity1113 ··-·high_severity
1089 ··-·low_complexity1114 ··-·low_complexity
1090 ··-·low_disruption1115 ··-·low_disruption
1091 ··-·no_reboot_needed1116 ··-·no_reboot_needed
Max diff block lines reached; 111328/116363 bytes (95.67%) of diff not shown.
1.24 MB
./usr/share/doc/ssg-nondebian/ssg-fedora-guide-standard.html
    
Offset 17734, 178 lines modifiedOffset 17734, 178 lines modified
00045450:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00045450:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00045460:·6d32·3536·3622·2074·6162·696e·6465·783d··m2566"·tabindex=00045460:·6d32·3536·3622·2074·6162·696e·6465·783d··m2566"·tabindex=
00045470:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button00045470:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
00045480:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=00045480:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
00045490:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A00045490:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
000454a0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea000454a0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
000454b0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem000454b0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
000454c0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible000454c0:·6564·6961·7469·6f6e·204b·7562·6572·6e65··ediation·Kuberne
000454d0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
000454e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
000454f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
00045500:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
00045510:·3235·3636·223e·3c74·6162·6c65·2063·6c61··2566"><table·cla 
00045520:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
00045530:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
00045540:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
00045550:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
00045560:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>000454d0:·7465·7320·736e·6970·7065·7420·e287·b23c··tes·snippet·...<
 000454e0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 000454f0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00045500:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00045510:·6964·6d32·3536·3622·3e3c·7461·626c·6520··idm2566"><table·
 00045520:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00045530:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00045540:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00045550:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 00045560:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 00045570:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00045580:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 00045590:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00045570:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr000455a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 000455b0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 000455c0:·3e3c·7464·3e74·7275·653c·2f74·643e·3c2f··><td>true</td></
00045580:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
00045590:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
000455a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
000455b0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
000455c0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
000455d0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg000455d0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
000455e0:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr000455e0:·6567·793a·3c2f·7468·3e3c·7464·3e72·6573··egy:</th><td>res
000455f0:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t000455f0:·7472·6963·743c·2f74·643e·3c2f·7472·3e3c··trict</td></tr><
00045600:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>00045600:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 00045610:·653e·2d2d·2d0a·6170·6956·6572·7369·6f6e··e>---.apiVersion
 00045620:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu
 00045630:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift
 00045640:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac
 00045650:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:
 00045660:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i
 00045670:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v
 00045680:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··
 00045690:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····
 000456a0:·2075·6e69·7473·3a0a·2020·2020·2020·2020···units:.········
 000456b0:·2d20·6e61·6d65·3a20·636f·6e66·6967·7572··-·name:·configur
00045610:·2d20·6e61·6d65·3a20·5843·4344·4620·5661··-·name:·XCCDF·Va 
00045620:·6c75·6520·7661·725f·7379·7374·656d·5f63··lue·var_system_c 
00045630:·7279·7074·6f5f·706f·6c69·6379·2023·2070··rypto_policy·#·p 
00045640:·726f·6d6f·7465·2074·6f20·7661·7269·6162··romote·to·variab 
00045650:·6c65·0a20·2073·6574·5f66·6163·743a·0a20··le.··set_fact:.· 
00045660:·2020·2076·6172·5f73·7973·7465·6d5f·6372·····var_system_cr 
00045670:·7970·746f·5f70·6f6c·6963·793a·2021·2173··ypto_policy:·!!s 
00045680:·7472·203c·6162·6272·2074·6974·6c65·3d22··tr·<abbr·title=" 
00045690:·6672·6f6d·2042·656e·6368·6d61·726b·2f56··from·Benchmark/V 
000456a0:·616c·7565·3a20·7863·6364·665f·6f72·672e··alue:·xccdf_org. 
000456b0:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte 
000456c0:·6e74·5f76·616c·7565·5f76·6172·5f73·7973··nt_value_var_sys 
000456d0:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic 
000456e0:·7922·3e44·4546·4155·4c54·3c2f·6162·6272··y">DEFAULT</abbr 
000456f0:·3e0a·2020·7461·6773·3a0a·2020·2020·2d20··>.··tags:.····-· 
00045700:·616c·7761·7973·0a0a·2d20·6e61·6d65·3a20··always..-·name:· 
00045710:·436f·6e66·6967·7572·6520·5379·7374·656d··Configure·System 
00045720:·2043·7279·7074·6f67·7261·7068·7920·506f···Cryptography·Po 
00045730:·6c69·6379·0a20·206c·696e·6569·6e66·696c··licy.··lineinfil 
00045740:·653a·0a20·2020·2070·6174·683a·202f·6574··e:.····path:·/et 
00045750:·632f·6372·7970·746f·2d70·6f6c·6963·6965··c/crypto-policie 
00045760:·732f·636f·6e66·6967·0a20·2020·2072·6567··s/config.····reg 
00045770:·6578·703a·205e·283f·2123·2928·5c53·2b29··exp:·^(?!#)(\S+) 
00045780:·240a·2020·2020·6c69·6e65·3a20·277b·7b20··$.····line:·'{{· 
00045790:·7661·725f·7379·7374·656d·5f63·7279·7074··var_system_crypt 
000457a0:·6f5f·706f·6c69·6379·207d·7d27·0a20·2020··o_policy·}}'.··· 
000457b0:·2063·7265·6174·653a·2074·7275·650a·2020···create:·true.·· 
000457c0:·7461·6773·3a0a·2020·2d20·4e49·5354·2d38··tags:.··-·NIST-8 
000457d0:·3030·2d35·332d·4143·2d31·3728·3229·0a20··00-53-AC-17(2).· 
000457e0:·202d·204e·4953·542d·3830·302d·3533·2d41···-·NIST-800-53-A 
000457f0:·432d·3137·2861·290a·2020·2d20·4e49·5354··C-17(a).··-·NIST 
00045800:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a). 
00045810:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
00045820:·4d41·2d34·2836·290a·2020·2d20·4e49·5354··MA-4(6).··-·NIST 
00045830:·2d38·3030·2d35·332d·5343·2d31·3228·3229··-800-53-SC-12(2) 
00045840:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
00045850:·2d53·432d·3132·2833·290a·2020·2d20·4e49··-SC-12(3).··-·NI 
00045860:·5354·2d38·3030·2d35·332d·5343·2d31·330a··ST-800-53-SC-13. 
00045870:·2020·2d20·5043·492d·4453·5376·342d·322e····-·PCI-DSSv4-2. 
00045880:·320a·2020·2d20·5043·492d·4453·5376·342d··2.··-·PCI-DSSv4- 
00045890:·322e·322e·370a·2020·2d20·636f·6e66·6967··2.2.7.··-·config 
000458a0:·7572·655f·6372·7970·746f·5f70·6f6c·6963··ure_crypto_polic 
000458b0:·790a·2020·2d20·6869·6768·5f73·6576·6572··y.··-·high_sever 
000458c0:·6974·790a·2020·2d20·6c6f·775f·636f·6d70··ity.··-·low_comp 
000458d0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d 
000458e0:·6973·7275·7074·696f·6e0a·2020·2d20·6e6f··isruption.··-·no 
000458f0:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.· 
00045900:·202d·2072·6573·7472·6963·745f·7374·7261···-·restrict_stra 
00045910:·7465·6779·0a0a·2d20·6e61·6d65·3a20·5665··tegy..-·name:·Ve 
00045920:·7269·6679·2074·6861·7420·4372·7970·746f··rify·that·Crypto 
00045930:·2050·6f6c·6963·7920·6973·2053·6574·2028···Policy·is·Set·( 
00045940:·7275·6e74·696d·6529·0a20·2063·6f6d·6d61··runtime).··comma 
00045950:·6e64·3a20·2f75·7372·2f62·696e·2f75·7064··nd:·/usr/bin/upd 
00045960:·6174·652d·6372·7970·746f·2d70·6f6c·6963··ate-crypto-polic000456c0:·652d·6372·7970·746f·2d70·6f6c·6963·792e··e-crypto-policy.
 000456d0:·7365·7276·6963·650a·2020·2020·2020·2020··service.········
 000456e0:·2020·656e·6162·6c65·643a·2074·7275·650a····enabled:·true.
 000456f0:·2020·2020·2020·2020·2020·636f·6e74·656e············conten
 00045700:·7473·3a20·7c0a·2020·2020·2020·2020·2020··ts:·|.··········
 00045710:·2020·5b55·6e69·745d·0a20·2020·2020·2020····[Unit].·······
 00045720:·2020·2020·2042·6566·6f72·653d·6b75·6265·······Before=kube
 00045730:·6c65·742e·7365·7276·6963·650a·2020·2020··let.service.····
 00045740:·2020·2020·2020·2020·5b53·6572·7669·6365··········[Service
 00045750:·5d0a·2020·2020·2020·2020·2020·2020·5479··].············Ty
 00045760:·7065·3d6f·6e65·7368·6f74·0a20·2020·2020··pe=oneshot.·····
 00045770:·2020·2020·2020·2045·7865·6353·7461·7274·········ExecStart
 00045780:·3d75·7064·6174·652d·6372·7970·746f·2d70··=update-crypto-p
00045970:·6965·7320·2d2d·7365·7420·7b7b·2076·6172··ies·--set·{{·var00045790:·6f6c·6963·6965·7320·2d2d·7365·7420·7b7b··olicies·--set·{{
00045980:·5f73·7973·7465·6d5f·6372·7970·746f·5f70··_system_crypto_p000457a0:·2e76·6172·5f73·7973·7465·6d5f·6372·7970··.var_system_cryp
 000457b0:·746f·5f70·6f6c·6963·797d·7d0a·2020·2020··to_policy}}.····
 000457c0:·2020·2020·2020·2020·5265·6d61·696e·4166··········RemainAf
 000457d0:·7465·7245·7869·743d·7965·730a·2020·2020··terExit=yes.····
 000457e0:·2020·2020·2020·2020·5b49·6e73·7461·6c6c··········[Install
 000457f0:·5d0a·2020·2020·2020·2020·2020·2020·5761··].············Wa
 00045800:·6e74·6564·4279·3d6d·756c·7469·2d75·7365··ntedBy=multi-use
Max diff block lines reached; 1189335/1212547 bytes (98.09%) of diff not shown.
86.7 KB
html2text {}
    
Offset 756, 14 lines modifiedOffset 756, 39 lines modified
756 »       echo·"to·see·what·package·to·(re)install"·>&2756 »       echo·"to·see·what·package·to·(re)install"·>&2
  
757 »       false··#·end·with·an·error·code757 »       false··#·end·with·an·error·code
758 elif·test·"$rc"·!=·0;·then758 elif·test·"$rc"·!=·0;·then
759 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2759 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
760 »       false··#·end·with·an·error·code760 »       false··#·end·with·an·error·code
761 fi761 fi
 762 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 763 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 764 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 765 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 766 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 767 ---
 768 apiVersion:·machineconfiguration.openshift.io/v1
 769 kind:·MachineConfig
 770 spec:
 771 ··config:
 772 ····ignition:
 773 ······version:·3.1.0
 774 ····systemd:
 775 ······units:
 776 ········-·name:·configure-crypto-policy.service
 777 ··········enabled:·true
 778 ··········contents:·|
 779 ············[Unit]
 780 ············Before=kubelet.service
 781 ············[Service]
 782 ············Type=oneshot
 783 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 784 ············RemainAfterExit=yes
 785 ············[Install]
 786 ············WantedBy=multi-user.target
762 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8787 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
763 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low788 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
764 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low789 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
765 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false790 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
766 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict791 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
767 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable792 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
768 ··set_fact:793 ··set_fact:
Offset 808, 39 lines modifiedOffset 833, 14 lines modified
808 ··-·PCI-DSSv4-2.2.7833 ··-·PCI-DSSv4-2.2.7
809 ··-·configure_crypto_policy834 ··-·configure_crypto_policy
810 ··-·high_severity835 ··-·high_severity
811 ··-·low_complexity836 ··-·low_complexity
812 ··-·low_disruption837 ··-·low_disruption
813 ··-·no_reboot_needed838 ··-·no_reboot_needed
814 ··-·restrict_strategy839 ··-·restrict_strategy
815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
816 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
817 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
818 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
819 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
820 --- 
821 apiVersion:·machineconfiguration.openshift.io/v1 
822 kind:·MachineConfig 
823 spec: 
824 ··config: 
825 ····ignition: 
826 ······version:·3.1.0 
827 ····systemd: 
828 ······units: 
829 ········-·name:·configure-crypto-policy.service 
830 ··········enabled:·true 
831 ··········contents:·| 
832 ············[Unit] 
833 ············Before=kubelet.service 
834 ············[Service] 
835 ············Type=oneshot 
836 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
837 ············RemainAfterExit=yes 
838 ············[Install] 
839 ············WantedBy=multi-user.target 
840 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*840 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·K\x8Ke\x8er\x8rb\x8be\x8er\x8ro\x8os\x8s·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
841 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured·correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies·targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,·Kerberos·is·configured·to·use·the·system-wide·crypto·policy·settings.841 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·Kerberos·is·supported·by·crypto·policy,·but·it's·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·for·Kerberos·are·configured·correctly,·examine·that·there·is·a·symlink·at·/etc/krb5.conf.d/crypto-policies·targeting·/etc/cypto-policies/back-ends/krb5.config.·If·the·symlink·exists,·Kerberos·is·configured·to·use·the·system-wide·crypto·policy·settings.
842 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·Kerberos·violate·expectations,·and·makes·system·configuration·more·fragmented.842 Rationale:··Overriding·the·system·crypto·policy·makes·the·behavior·of·Kerberos·violate·expectations,·and·makes·system·configuration·more·fragmented.
843 Severity: ··high843 Severity: ··high
844 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy844 Rule·ID:····xccdf_org.ssgproject.content_rule_configure_kerberos_crypto_policy
845 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000803845 ············_\x8d_\x8i_\x8s_\x8a·····CCI-000803
846 ············_\x8i_\x8s_\x8m······0418,·1055,·1402846 ············_\x8i_\x8s_\x8m······0418,·1055,·1402
Offset 2466, 14 lines modifiedOffset 2466, 38 lines modified
2466 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"2466 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
2467 fi2467 fi
2468 fi2468 fi
  
2469 else2469 else
2470 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2470 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2471 fi2471 fi
 2472 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2473 ---
 2474 apiVersion:·machineconfiguration.openshift.io/v1
 2475 kind:·MachineConfig
 2476 spec:
 2477 ··config:
 2478 ····ignition:
 2479 ······version:·3.1.0
 2480 ····storage:
 2481 ······files:
 2482 ······-·contents:
 2483 ··········source:
 2484 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 2485 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 2486 ········mode:·0644
 2487 ········path:·/etc/pam.d/password-auth
 2488 ········overwrite:·true
 2489 ······-·contents:
 2490 ··········source:
 2491 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 2492 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 2493 ········mode:·0644
 2494 ········path:·/etc/pam.d/system-auth
 2495 ········overwrite:·true
2472 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82496 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2473 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2497 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2474 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2498 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2475 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2499 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2476 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure2500 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
2477 -·name:·Gather·the·package·facts2501 -·name:·Gather·the·package·facts
2478 ··package_facts:2502 ··package_facts:
Offset 2612, 38 lines modifiedOffset 2636, 14 lines modified
2612 ··-·PCI-DSSv4-8.3.12636 ··-·PCI-DSSv4-8.3.1
2613 ··-·configure_strategy2637 ··-·configure_strategy
2614 ··-·high_severity2638 ··-·high_severity
2615 ··-·low_complexity2639 ··-·low_complexity
2616 ··-·medium_disruption2640 ··-·medium_disruption
2617 ··-·no_empty_passwords2641 ··-·no_empty_passwords
2618 ··-·no_reboot_needed2642 ··-·no_reboot_needed
2619 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
Max diff block lines reached; 67351/88805 bytes (75.84%) of diff not shown.
247 KB
./usr/share/doc/ssg-nondebian/ssg-kylinserver10-guide-standard.html
    
Offset 15063, 95 lines modifiedOffset 15063, 95 lines modified
0003ad60:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003ad60:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003ad70:·743d·2223·6964·6d37·3330·2220·7461·6269··t="#idm730"·tabi0003ad70:·743d·2223·6964·6d37·3330·2220·7461·6269··t="#idm730"·tabi
0003ad80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003ad80:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003ad90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003ad90:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003ada0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003ada0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003adb0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003adb0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003adc0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003adc0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003add0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003add0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
 0003ade0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·..
 0003adf0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003ae00:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003ade0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003adf0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003ae00:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003ae10:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003ae20:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003ae30:·3330·223e·3c70·7265·3e3c·636f·6465·3e0a··30"><pre><code>. 
0003ae40:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003ae50:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003ae60:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003ae70:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003ae80:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003ae90:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003aea0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003ae10:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003ae20:·3d22·6964·6d37·3330·223e·3c74·6162·6c65··="idm730"><table
 0003ae30:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003ae40:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003ae50:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003ae60:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003ae70:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003ae80:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003ae90:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003aea0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003aeb0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003aec0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003aed0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003aee0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003aef0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003aeb0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003aec0:·3331·2220·7461·6269·6e64·6578·3d22·3022··31"·tabindex="0" 
0003aed0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003aee0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003aef0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003af00:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003af10:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003af20:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003af30:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003af40:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003af50:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003af60:·6170·7365·2220·6964·3d22·6964·6d37·3331··apse"·id="idm731 
0003af70:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003af80:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003af90:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003afa0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003afb0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003afc0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003afd0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003afe0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003aff0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b000:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b010:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003b020:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003af00:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003af10:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003af20:·653e·2d20·6e61·6d65·3a20·4761·7468·6572··e>-·name:·Gather
 0003af30:·2074·6865·2070·6163·6b61·6765·2066·6163···the·package·fac
 0003af40:·7473·0a20·2070·6163·6b61·6765·5f66·6163··ts.··package_fac
 0003af50:·7473·3a0a·2020·2020·6d61·6e61·6765·723a··ts:.····manager:
0003b030:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003b040:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003b050:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b060:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name 
0003b070:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac 
0003b080:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac 
0003b090:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.···· 
0003b0a0:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.·· 
0003b0b0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5 
0003b0c0:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST 
0003b0d0:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a). 
0003b0e0:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req- 
0003b0f0:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS 
0003b100:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en 
0003b110:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.·· 
0003b120:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity 
0003b130:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt 
0003b140:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s 
0003b150:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r 
0003b160:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··- 
0003b170:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in 
0003b180:·7374·616c·6c65·640a·0a2d·206e·616d·653a··stalled..-·name: 
0003b190:·2045·6e73·7572·6520·6169·6465·2069·7320···Ensure·aide·is· 
0003b1a0:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack 
0003b1b0:·6167·653a·0a20·2020·206e·616d·653a·2061··age:.····name:·a 
0003b1c0:·6964·650a·2020·2020·7374·6174·653a·2070··ide.····state:·p 
0003b1d0:·7265·7365·6e74·0a20·2077·6865·6e3a·2027··resent.··when:·' 
0003b1e0:·226b·6572·6e65·6c22·2069·6e20·616e·7369··"kernel"·in·ansi 
0003b1f0:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag 
0003b200:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·0003af60:·2061·7574·6f0a·2020·7461·6773·3a0a·2020···auto.··tags:.··
0003b210:·434a·4953·2d35·2e31·302e·312e·330a·2020··CJIS-5.10.1.3.··0003af70:·2d20·434a·4953·2d35·2e31·302e·312e·330a··-·CJIS-5.10.1.3.
0003b220:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM0003af80:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003b230:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS0003af90:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI-
0003b240:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P0003afa0:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-
0003b250:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.0003afb0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.
0003b260:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat0003afc0:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str
0003b270:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp0003afd0:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co
0003b280:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d0003afe0:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low
0003b290:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me0003aff0:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
0003b2a0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··0003b000:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.
0003b2b0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need0003b010:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
0003b2c0:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a0003b020:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package
0003b2d0:·6964·655f·696e·7374·616c·6c65·640a·3c2f··ide_installed.</0003b030:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed.
 0003b040:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure·
 0003b050:·6169·6465·2069·7320·696e·7374·616c·6c65··aide·is·installe
 0003b060:·640a·2020·7061·636b·6167·653a·0a20·2020··d.··package:.···
 0003b070:·206e·616d·653a·2061·6964·650a·2020·2020···name:·aide.····
 0003b080:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
 0003b090:·2077·6865·6e3a·2027·226b·6572·6e65·6c22···when:·'"kernel"
 0003b0a0:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 0003b0b0:·732e·7061·636b·6167·6573·270a·2020·7461··s.packages'.··ta
 0003b0c0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1
 0003b0d0:·302e·312e·330a·2020·2d20·4e49·5354·2d38··0.1.3.··-·NIST-8
 0003b0e0:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
 0003b0f0:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11
 0003b100:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4
 0003b110:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab
 0003b120:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-·
 0003b130:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
 0003b140:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio
Max diff block lines reached; 218670/230426 bytes (94.90%) of diff not shown.
22.1 KB
html2text {}
    
Offset 116, 19 lines modifiedOffset 116, 14 lines modified
116 ···························A.15.2.1,·A.8.2.3116 ···························A.15.2.1,·A.8.2.3
117 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)117 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
118 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3118 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
120 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199120 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
121 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79121 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
124 [[packages]] 
125 name·=·"aide" 
126 version·=·"*" 
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
132 -·name:·Gather·the·package·facts128 -·name:·Gather·the·package·facts
133 ··package_facts:129 ··package_facts:
Offset 157, 14 lines modifiedOffset 152, 19 lines modified
157 ··-·PCI-DSSv4-11.5.2152 ··-·PCI-DSSv4-11.5.2
158 ··-·enable_strategy153 ··-·enable_strategy
159 ··-·low_complexity154 ··-·low_complexity
160 ··-·low_disruption155 ··-·low_disruption
161 ··-·medium_severity156 ··-·medium_severity
162 ··-·no_reboot_needed157 ··-·no_reboot_needed
163 ··-·package_aide_installed158 ··-·package_aide_installed
 159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 160 [[packages]]
 161 name·=·"aide"
 162 version·=·"*"
164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
169 include·install_aide168 include·install_aide
  
Offset 1303, 19 lines modifiedOffset 1303, 14 lines modified
1303 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·b\x8bi\x8in\x8nu\x8ut\x8ti\x8il\x8ls\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1303 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·b\x8bi\x8in\x8nu\x8ut\x8ti\x8il\x8ls\x8s·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1304 The·binutils·package·can·be·installed·with·the·following·command:1304 The·binutils·package·can·be·installed·with·the·following·command:
1305 $·sudo·dnf·install·binutils1305 $·sudo·dnf·install·binutils
1306 Rationale:·binutils·is·a·collection·of·binary·utilities·required·for·foundational·system1306 Rationale:·binutils·is·a·collection·of·binary·utilities·required·for·foundational·system
1307 ···········operator·activities,·such·as·ld,·nm,·objcopy·and·readelf.1307 ···········operator·activities,·such·as·ld,·nm,·objcopy·and·readelf.
1308 Severity: ·medium1308 Severity: ·medium
1309 Rule·ID:···xccdf_org.ssgproject.content_rule_package_binutils_installed1309 Rule·ID:···xccdf_org.ssgproject.content_rule_package_binutils_installed
1310 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1311 [[packages]] 
1312 name·=·"binutils" 
1313 version·=·"*" 
1314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81310 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1315 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1311 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1316 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1312 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1317 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1313 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1318 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1314 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1319 -·name:·Ensure·binutils·is·installed1315 -·name:·Ensure·binutils·is·installed
1320 ··package:1316 ··package:
Offset 1324, 14 lines modifiedOffset 1319, 19 lines modified
1324 ··tags:1319 ··tags:
1325 ··-·enable_strategy1320 ··-·enable_strategy
1326 ··-·low_complexity1321 ··-·low_complexity
1327 ··-·low_disruption1322 ··-·low_disruption
1328 ··-·medium_severity1323 ··-·medium_severity
1329 ··-·no_reboot_needed1324 ··-·no_reboot_needed
1330 ··-·package_binutils_installed1325 ··-·package_binutils_installed
 1326 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1327 [[packages]]
 1328 name·=·"binutils"
 1329 version·=·"*"
1331 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81330 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1332 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1331 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1333 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1332 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1334 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1333 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1335 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1334 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1336 include·install_binutils1335 include·install_binutils
  
Offset 6527, 18 lines modifiedOffset 6527, 14 lines modified
6527 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,6527 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,
6528 ···························SR·7.26528 ···························SR·7.2
6529 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,6529 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,
6530 ···························A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.16530 ···························A.14.2.7,·A.15.2.1,·A.15.2.2,·A.17.2.1
6531 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)6531 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
6532 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-16532 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
6533 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002276533 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
6534 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6535 [customizations.services] 
6536 enabled·=·["rsyslog"] 
6537 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86534 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6538 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6535 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6539 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6536 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6540 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6537 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6541 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6538 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6542 -·name:·Gather·the·package·facts6539 -·name:·Gather·the·package·facts
6543 ··package_facts:6540 ··package_facts:
Offset 6574, 14 lines modifiedOffset 6570, 18 lines modified
6574 ··-·NIST-800-53-CM-6(a)6570 ··-·NIST-800-53-CM-6(a)
6575 ··-·enable_strategy6571 ··-·enable_strategy
6576 ··-·low_complexity6572 ··-·low_complexity
6577 ··-·low_disruption6573 ··-·low_disruption
6578 ··-·medium_severity6574 ··-·medium_severity
6579 ··-·no_reboot_needed6575 ··-·no_reboot_needed
6580 ··-·service_rsyslog_enabled6576 ··-·service_rsyslog_enabled
 6577 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 6578 [customizations.services]
 6579 enabled·=·["rsyslog"]
6581 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86580 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6582 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6581 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6583 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6582 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6584 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6583 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6585 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6584 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6586 include·enable_rsyslog6585 include·enable_rsyslog
  
Offset 6697, 18 lines modifiedOffset 6697, 14 lines modified
6697 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)6697 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)
6698 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-16698 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
6699 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.16699 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
6700 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-6700 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-
6701 ···························GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-002326701 ···························GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
6702 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A216702 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
6703 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.26703 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
6704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 17080/22562 bytes (75.70%) of diff not shown.
686 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-anssi_bp28_enhanced.html
    
Offset 15053, 217 lines modifiedOffset 15053, 217 lines modified
0003acc0:·7461·7267·6574·3d22·2369·646d·3530·3937··target="#idm50970003acc0:·7461·7267·6574·3d22·2369·646d·3530·3937··target="#idm5097
0003acd0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003acd0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003ace0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003ace0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003acf0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003acf0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003ad00:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003ad00:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003ad10:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003ad10:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003ad20:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003ad20:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003ad30:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
0003ad30:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003ad40:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003ad50:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003ad60:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003ad70:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003ad80:·3d22·6964·6d35·3039·3722·3e3c·7072·653e··="idm5097"><pre> 
0003ad90:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003ada0:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003adb0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003adc0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003add0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003ade0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003adf0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003ae00:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003ae10:·3d22·2369·646d·3530·3938·2220·7461·6269··="#idm5098"·tabi 
0003ae20:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003ae30:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003ae40:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003ae50:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003ae60:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003ae70:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003ae80:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003ae90:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003aea0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003aeb0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003aec0:·646d·3530·3938·223e·3c74·6162·6c65·2063··dm5098"><table·c 
0003aed0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003aee0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003aef0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003af00:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003af10:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003af20:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003af30:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003af40:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003af50:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003af60:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003af70:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003af80:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003af90:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003afa0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003afb0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003afc0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003afd0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003afe0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003aff0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q 
0003b000:·7569·6574·202d·7120·6b65·726e·656c·207c··uiet·-q·kernel·| 
0003b010:·7c20·7270·6d20·2d2d·7175·6965·7420·2d71··|·rpm·--quiet·-q 
0003b020:·206b·6572·6e65·6c2d·7565·6b3b·2074·6865···kernel-uek;·the 
0003b030:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003b040:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003b050:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins 
0003b060:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003b070:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003b080:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b090:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b0a0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b0b0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b0c0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b0d0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b0e0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b0f0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b100:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b110:·743d·2223·6964·6d35·3039·3922·2074·6162··t="#idm5099"·tab 
0003b120:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b130:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b140:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b150:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b160:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b170:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b180:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b190:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003ad40:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b1a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003ad50:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b1b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b1c0:·643d·2269·646d·3530·3939·223e·3c74·6162··d="idm5099"><tab 
0003b1d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b1e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b1f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b200:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b210:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b220:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b230:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b240:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b250:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b260:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b270:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b280:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b290:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b2a0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b2b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b2c0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003b2d0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f 
0003b2e0:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f 
0003b2f0:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage 
0003b300:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:. 
0003b310:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003b320:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5 
0003b330:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC 
0003b340:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.· 
0003b350:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11. 
0003b360:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s 
0003b370:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_ 
0003b380:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l 
0003b390:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.·· 
0003b3a0:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit 
0003b3b0:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_ 
0003b3c0:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa 
0003b3d0:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe 
0003b3e0:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur 
0003b3f0:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal 
0003b400:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.· 
0003b410:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.·· 
0003b420:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present 
0003b430:·0a20·2077·6865·6e3a·2028·226b·6572·6e65··.··when:·("kerne 
0003b440:·6c22·2069·6e20·616e·7369·626c·655f·6661··l"·in·ansible_fa 
0003b450:·6374·732e·7061·636b·6167·6573·206f·7220··cts.packages·or· 
0003b460:·226b·6572·6e65·6c2d·7565·6b22·2069·6e20··"kernel-uek"·in· 
0003b470:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
0003b480:·636b·6167·6573·290a·2020·7461·6773·3a0a··ckages).··tags:. 
0003b490:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
Max diff block lines reached; 612526/641120 bytes (95.54%) of diff not shown.
59.3 KB
html2text {}
    
Offset 116, 19 lines modifiedOffset 116, 14 lines modified
116 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3116 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
117 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)117 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
118 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3118 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
120 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199120 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
121 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79121 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
124 [[packages]] 
125 name·=·"aide" 
126 version·=·"*" 
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
132 #·Remediation·is·applicable·only·in·certain·platforms128 #·Remediation·is·applicable·only·in·certain·platforms
133 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then129 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 172, 33 lines modifiedOffset 167, 38 lines modified
172 ··-·PCI-DSSv4-11.5.2167 ··-·PCI-DSSv4-11.5.2
173 ··-·enable_strategy168 ··-·enable_strategy
174 ··-·low_complexity169 ··-·low_complexity
175 ··-·low_disruption170 ··-·low_disruption
176 ··-·medium_severity171 ··-·medium_severity
177 ··-·no_reboot_needed172 ··-·no_reboot_needed
178 ··-·package_aide_installed173 ··-·package_aide_installed
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 179 package·--add=aide
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 181 [[packages]]
 182 name·=·"aide"
 183 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
184 include·install_aide189 include·install_aide
  
185 class·install_aide·{190 class·install_aide·{
186 ··package·{·'aide':191 ··package·{·'aide':
187 ····ensure·=>·'installed',192 ····ensure·=>·'installed',
188 ··}193 ··}
189 }194 }
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
195 package·--add=aide 
196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*195 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
197 Run·the·following·command·to·generate·a·new·database:196 Run·the·following·command·to·generate·a·new·database:
198 $·sudo·/usr/sbin/aide·--init197 $·sudo·/usr/sbin/aide·--init
199 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the198 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
200 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these199 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
201 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their200 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
202 integrity.·The·newly-generated·database·can·be·installed·as·follows:201 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 632, 19 lines modifiedOffset 632, 14 lines modified
632 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235632 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
633 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386633 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
634 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)634 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
635 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1635 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
636 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125636 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
637 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33637 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
638 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2638 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
640 [[packages]] 
641 name·=·"sudo" 
642 version·=·"*" 
643 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
644 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low640 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
645 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low641 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
646 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false642 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
647 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable643 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
648 #·Remediation·is·applicable·only·in·certain·platforms644 #·Remediation·is·applicable·only·in·certain·platforms
649 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then645 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 686, 33 lines modifiedOffset 681, 38 lines modified
686 ··-·PCI-DSSv4-2.2.6681 ··-·PCI-DSSv4-2.2.6
687 ··-·enable_strategy682 ··-·enable_strategy
688 ··-·low_complexity683 ··-·low_complexity
689 ··-·low_disruption684 ··-·low_disruption
690 ··-·medium_severity685 ··-·medium_severity
691 ··-·no_reboot_needed686 ··-·no_reboot_needed
692 ··-·package_sudo_installed687 ··-·package_sudo_installed
 688 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 689 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 690 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 691 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 692 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 693 package·--add=sudo
 694 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 695 [[packages]]
 696 name·=·"sudo"
 697 version·=·"*"
693 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
694 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low699 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
695 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low700 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
696 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false701 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
697 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable702 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
698 include·install_sudo703 include·install_sudo
  
699 class·install_sudo·{704 class·install_sudo·{
700 ··package·{·'sudo':705 ··package·{·'sudo':
701 ····ensure·=>·'installed',706 ····ensure·=>·'installed',
702 ··}707 ··}
703 }708 }
704 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
705 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
706 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
707 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
708 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
709 package·--add=sudo 
710 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*709 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
711 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:710 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
712 $·sudo·chgrp·root·/etc/sudoers.d711 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 55434/60674 bytes (91.36%) of diff not shown.
721 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-anssi_bp28_high.html
    
Offset 15058, 218 lines modifiedOffset 15058, 218 lines modified
0003ad10:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm50003ad10:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5
0003ad20:·3039·3722·2074·6162·696e·6465·783d·2230··097"·tabindex="00003ad20:·3039·3722·2074·6162·696e·6465·783d·2230··097"·tabindex="0
0003ad30:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003ad30:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003ad40:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003ad40:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003ad50:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003ad50:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003ad60:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003ad60:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003ad70:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003ad70:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003ad80:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B0003ad80:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
0003ad90:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
0003ada0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003adb0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003adc0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003add0:·2069·643d·2269·646d·3530·3937·223e·3c70···id="idm5097"><p 
0003ade0:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
0003adf0:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a 
0003ae00:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·" 
0003ae10:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
0003ae20:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003ae30:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003ae40:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003ae50:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003ae60:·6765·743d·2223·6964·6d35·3039·3822·2074··get="#idm5098"·t 
0003ae70:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003ae80:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003ae90:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003aea0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003aeb0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003aec0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003aed0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003aee0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003aef0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003af00:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003af10:·3d22·6964·6d35·3039·3822·3e3c·7461·626c··="idm5098"><tabl 
0003af20:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003af30:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003af40:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003af50:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003af60:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003af70:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003af80:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003af90:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003afa0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003afb0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003afc0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003afd0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003afe0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003aff0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b000:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b010:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003b020:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003b030:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003b040:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm· 
0003b050:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003b060:·6c20·7c7c·2072·706d·202d·2d71·7569·6574··l·||·rpm·--quiet 
0003b070:·202d·7120·6b65·726e·656c·2d75·656b·3b20···-q·kernel-uek;· 
0003b080:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003b090:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003b0a0:·203b·2074·6865·6e0a·2020·2020·646e·6620···;·then.····dnf· 
0003b0b0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003b0c0:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003b0d0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003b0e0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003b0f0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003b100:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003b110:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003b120:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b130:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b140:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b150:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b160:·7267·6574·3d22·2369·646d·3530·3939·2220··rget="#idm5099"· 
0003b170:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b180:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b190:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b1a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b1b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b1c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b1d0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003b1e0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003ad90:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
0003b1f0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003ada0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003b200:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003adb0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003b210:·2220·6964·3d22·6964·6d35·3039·3922·3e3c··"·id="idm5099"><0003adc0:·7365·2220·6964·3d22·6964·6d35·3039·3722··se"·id="idm5097"
0003b220:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003add0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003b230:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b240:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b250:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b260:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b270:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b280:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b290:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b2a0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b2b0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b2c0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b2d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b2e0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b2f0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b300:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b310:·3e3c·636f·6465·3e2d·206e·616d·653a·2047··><code>-·name:·G 
0003b320:·6174·6865·7220·7468·6520·7061·636b·6167··ather·the·packag 
0003b330:·6520·6661·6374·730a·2020·7061·636b·6167··e·facts.··packag 
0003b340:·655f·6661·6374·733a·0a20·2020·206d·616e··e_facts:.····man 
0003b350:·6167·6572·3a20·6175·746f·0a20·2074·6167··ager:·auto.··tag 
0003b360:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10 
0003b370:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80 
0003b380:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
0003b390:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11. 
0003b3a0:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4- 
0003b3b0:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl 
0003b3c0:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l 
0003b3d0:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.·· 
0003b3e0:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption 
0003b3f0:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve 
0003b400:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo 
0003b410:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa 
0003b420:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta 
0003b430:·6c6c·6564·0a0a·2d20·6e61·6d65·3a20·456e··lled..-·name:·En 
0003b440:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins 
0003b450:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package 
0003b460:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide 
0003b470:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres 
0003b480:·656e·740a·2020·7768·656e·3a20·2822·6b65··ent.··when:·("ke 
0003b490:·726e·656c·2220·696e·2061·6e73·6962·6c65··rnel"·in·ansible 
0003b4a0:·5f66·6163·7473·2e70·6163·6b61·6765·7320··_facts.packages· 
0003b4b0:·6f72·2022·6b65·726e·656c·2d75·656b·2220··or·"kernel-uek"· 
0003b4c0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
0003b4d0:·2e70·6163·6b61·6765·7329·0a20·2074·6167··.packages).··tag 
0003b4e0:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10 
0003b4f0:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80 
Max diff block lines reached; 642970/671702 bytes (95.72%) of diff not shown.
64.6 KB
html2text {}
    
Offset 117, 19 lines modifiedOffset 117, 14 lines modified
117 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3117 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)118 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3119 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79122 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
125 [[packages]] 
126 name·=·"aide" 
127 version·=·"*" 
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
133 #·Remediation·is·applicable·only·in·certain·platforms129 #·Remediation·is·applicable·only·in·certain·platforms
134 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then130 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 173, 33 lines modifiedOffset 168, 38 lines modified
173 ··-·PCI-DSSv4-11.5.2168 ··-·PCI-DSSv4-11.5.2
174 ··-·enable_strategy169 ··-·enable_strategy
175 ··-·low_complexity170 ··-·low_complexity
176 ··-·low_disruption171 ··-·low_disruption
177 ··-·medium_severity172 ··-·medium_severity
178 ··-·no_reboot_needed173 ··-·no_reboot_needed
179 ··-·package_aide_installed174 ··-·package_aide_installed
 175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 180 package·--add=aide
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 182 [[packages]]
 183 name·=·"aide"
 184 version·=·"*"
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
185 include·install_aide190 include·install_aide
  
186 class·install_aide·{191 class·install_aide·{
187 ··package·{·'aide':192 ··package·{·'aide':
188 ····ensure·=>·'installed',193 ····ensure·=>·'installed',
189 ··}194 ··}
190 }195 }
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
196 package·--add=aide 
197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
198 Run·the·following·command·to·generate·a·new·database:197 Run·the·following·command·to·generate·a·new·database:
199 $·sudo·/usr/sbin/aide·--init198 $·sudo·/usr/sbin/aide·--init
200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the199 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
201 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these200 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
202 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their201 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
203 integrity.·The·newly-generated·database·can·be·installed·as·follows:202 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 1170, 19 lines modifiedOffset 1170, 14 lines modified
1170 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351170 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1171 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861171 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1172 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1172 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1173 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11173 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1174 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251174 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1175 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331175 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1176 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21176 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1178 [[packages]] 
1179 name·=·"sudo" 
1180 version·=·"*" 
1181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1186 #·Remediation·is·applicable·only·in·certain·platforms1182 #·Remediation·is·applicable·only·in·certain·platforms
1187 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1183 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1224, 33 lines modifiedOffset 1219, 38 lines modified
1224 ··-·PCI-DSSv4-2.2.61219 ··-·PCI-DSSv4-2.2.6
1225 ··-·enable_strategy1220 ··-·enable_strategy
1226 ··-·low_complexity1221 ··-·low_complexity
1227 ··-·low_disruption1222 ··-·low_disruption
1228 ··-·medium_severity1223 ··-·medium_severity
1229 ··-·no_reboot_needed1224 ··-·no_reboot_needed
1230 ··-·package_sudo_installed1225 ··-·package_sudo_installed
 1226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1227 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1228 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1229 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1230 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1231 package·--add=sudo
 1232 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1233 [[packages]]
 1234 name·=·"sudo"
 1235 version·=·"*"
1231 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81236 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1232 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1237 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1233 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1238 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1234 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1239 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1235 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1240 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1236 include·install_sudo1241 include·install_sudo
  
1237 class·install_sudo·{1242 class·install_sudo·{
1238 ··package·{·'sudo':1243 ··package·{·'sudo':
1239 ····ensure·=>·'installed',1244 ····ensure·=>·'installed',
1240 ··}1245 ··}
1241 }1246 }
1242 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1243 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1244 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1245 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1246 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1247 package·--add=sudo 
1248 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1247 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1249 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:1248 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
1250 $·sudo·chgrp·root·/etc/sudoers.d1249 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 60867/66111 bytes (92.07%) of diff not shown.
547 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-anssi_bp28_intermediary.html
    
Offset 15049, 217 lines modifiedOffset 15049, 217 lines modified
0003ac80:·6765·743d·2223·6964·6d35·3039·3722·2074··get="#idm5097"·t0003ac80:·6765·743d·2223·6964·6d35·3039·3722·2074··get="#idm5097"·t
0003ac90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003ac90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003aca0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003aca0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003acb0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003acb0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003acc0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003acc0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003acd0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003acd0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003ace0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003ace0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003acf0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
0003acf0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003ad00:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003ad10:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003ad20:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003ad30:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003ad40:·646d·3530·3937·223e·3c70·7265·3e3c·636f··dm5097"><pre><co 
0003ad50:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003ad60:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003ad70:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003ad80:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003ad90:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003ada0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003adb0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003adc0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003add0:·6964·6d35·3039·3822·2074·6162·696e·6465··idm5098"·tabinde 
0003ade0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003adf0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003ae00:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003ae10:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003ae20:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003ae30:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003ae40:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003ae50:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003ae60:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003ae70:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003ae80:·3039·3822·3e3c·7461·626c·6520·636c·6173··098"><table·clas 
0003ae90:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003aea0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003aeb0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003aec0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003aed0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003aee0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003aef0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003af00:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003af10:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003af20:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003af30:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003af40:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003af50:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003af60:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003af70:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003af80:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003af90:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003afa0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003afb0:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003afc0:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r 
0003afd0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003afe0:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then.. 
0003aff0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b000:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b010:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal 
0003b020:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b030:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b040:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b050:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b060:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b070:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b080:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b090:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b0a0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b0b0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b0c0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b0d0:·2369·646d·3530·3939·2220·7461·6269·6e64··#idm5099"·tabind 
0003b0e0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b0f0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b100:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b110:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b120:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b130:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
0003b140:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b150:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003ad00:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b160:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003ad10:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b170:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003ad20:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b180:·6964·6d35·3039·3922·3e3c·7461·626c·6520··idm5099"><table·0003ad30:·3d22·6964·6d35·3039·3722·3e3c·7461·626c··="idm5097"><tabl
0003b190:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003ad40:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003b1a0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003ad50:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003b1b0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003ad60:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003b1c0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003ad70:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003b1d0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003ad80:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003b1e0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003ad90:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b1f0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003ada0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b200:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003adb0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b210:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003adc0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b220:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003add0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003b230:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003b240:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b250:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003b260:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003b270:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003b280:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather· 
0003b290:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact 
0003b2a0:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact 
0003b2b0:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:· 
0003b2c0:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··- 
0003b2d0:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003b2e0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0003b2f0:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D 
0003b300:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-· 
0003b310:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2 
0003b320:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0003b330:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0003b340:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
0003b350:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m 
0003b360:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.· 
0003b370:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
0003b380:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_ 
0003b390:·6169·6465·5f69·6e73·7461·6c6c·6564·0a0a··aide_installed.. 
0003b3a0:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a 
0003b3b0:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed 
0003b3c0:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.···· 
0003b3d0:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s 
0003b3e0:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.·· 
0003b3f0:·7768·656e·3a20·2822·6b65·726e·656c·2220··when:·("kernel"· 
0003b400:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
0003b410:·2e70·6163·6b61·6765·7320·6f72·2022·6b65··.packages·or·"ke 
0003b420:·726e·656c·2d75·656b·2220·696e·2061·6e73··rnel-uek"·in·ans 
0003b430:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
0003b440:·6765·7329·0a20·2074·6167·733a·0a20·202d··ges).··tags:.··- 
0003b450:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
Max diff block lines reached; 482110/510704 bytes (94.40%) of diff not shown.
47.9 KB
html2text {}
    
Offset 115, 19 lines modifiedOffset 115, 14 lines modified
115 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3115 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
116 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)116 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
117 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3117 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
119 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199119 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
120 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79120 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
123 [[packages]] 
124 name·=·"aide" 
125 version·=·"*" 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
131 #·Remediation·is·applicable·only·in·certain·platforms127 #·Remediation·is·applicable·only·in·certain·platforms
132 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then128 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 171, 33 lines modifiedOffset 166, 38 lines modified
171 ··-·PCI-DSSv4-11.5.2166 ··-·PCI-DSSv4-11.5.2
172 ··-·enable_strategy167 ··-·enable_strategy
173 ··-·low_complexity168 ··-·low_complexity
174 ··-·low_disruption169 ··-·low_disruption
175 ··-·medium_severity170 ··-·medium_severity
176 ··-·no_reboot_needed171 ··-·no_reboot_needed
177 ··-·package_aide_installed172 ··-·package_aide_installed
 173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 178 package·--add=aide
 179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 180 [[packages]]
 181 name·=·"aide"
 182 version·=·"*"
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
183 include·install_aide188 include·install_aide
  
184 class·install_aide·{189 class·install_aide·{
185 ··package·{·'aide':190 ··package·{·'aide':
186 ····ensure·=>·'installed',191 ····ensure·=>·'installed',
187 ··}192 ··}
188 }193 }
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
194 package·--add=aide 
195 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
196 Run·the·following·command·to·generate·a·new·database:195 Run·the·following·command·to·generate·a·new·database:
197 $·sudo·/usr/sbin/aide·--init196 $·sudo·/usr/sbin/aide·--init
198 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the197 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
199 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these198 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
200 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their199 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
201 integrity.·The·newly-generated·database·can·be·installed·as·follows:200 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 598, 19 lines modifiedOffset 598, 14 lines modified
598 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235598 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
599 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386599 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
600 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)600 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
601 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1601 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
602 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125602 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
603 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33603 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
604 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2604 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
605 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
606 [[packages]] 
607 name·=·"sudo" 
608 version·=·"*" 
609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8605 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low606 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low607 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false608 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable609 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
614 #·Remediation·is·applicable·only·in·certain·platforms610 #·Remediation·is·applicable·only·in·certain·platforms
615 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then611 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 652, 33 lines modifiedOffset 647, 38 lines modified
652 ··-·PCI-DSSv4-2.2.6647 ··-·PCI-DSSv4-2.2.6
653 ··-·enable_strategy648 ··-·enable_strategy
654 ··-·low_complexity649 ··-·low_complexity
655 ··-·low_disruption650 ··-·low_disruption
656 ··-·medium_severity651 ··-·medium_severity
657 ··-·no_reboot_needed652 ··-·no_reboot_needed
658 ··-·package_sudo_installed653 ··-·package_sudo_installed
 654 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 655 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 656 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 657 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 658 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 659 package·--add=sudo
 660 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 661 [[packages]]
 662 name·=·"sudo"
 663 version·=·"*"
659 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8664 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
660 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low665 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
661 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low666 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
662 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false667 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
663 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable668 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
664 include·install_sudo669 include·install_sudo
  
665 class·install_sudo·{670 class·install_sudo·{
666 ··package·{·'sudo':671 ··package·{·'sudo':
667 ····ensure·=>·'installed',672 ····ensure·=>·'installed',
668 ··}673 ··}
669 }674 }
670 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
671 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
672 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
673 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
674 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
675 package·--add=sudo 
676 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*675 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
677 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:676 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
678 $·sudo·chgrp·root·/etc/sudoers.d677 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 43802/49042 bytes (89.32%) of diff not shown.
87.0 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-anssi_bp28_minimal.html
    
Offset 14735, 227 lines modifiedOffset 14735, 227 lines modified
000398e0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i000398e0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
000398f0:·646d·3831·3236·2220·7461·6269·6e64·6578··dm8126"·tabindex000398f0:·646d·3831·3236·2220·7461·6269·6e64·6578··dm8126"·tabindex
00039900:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00039900:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00039910:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00039910:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00039920:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00039920:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00039930:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00039930:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00039940:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00039940:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
00039950:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil00039950:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 00039960:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 00039970:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00039980:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00039990:·6c61·7073·6522·2069·643d·2269·646d·3831··lapse"·id="idm81
 000399a0:·3236·223e·3c74·6162·6c65·2063·6c61·7373··26"><table·class
 000399b0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
00039960:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
00039970:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
00039980:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00039990:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
000399a0:·7365·2220·6964·3d22·6964·6d38·3132·3622··se"·id="idm8126" 
000399b0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
000399c0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
000399d0:·2022·646e·662d·6175·746f·6d61·7469·6322···"dnf-automatic" 
000399e0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
000399f0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
00039a00:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
00039a10:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
00039a20:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00039a30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
00039a40:·2223·6964·6d38·3132·3722·2074·6162·696e··"#idm8127"·tabin 
00039a50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
00039a60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
00039a70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
00039a80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
00039a90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
00039aa0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
00039ab0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
00039ac0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00039ad0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00039ae0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00039af0:·6d38·3132·3722·3e3c·7461·626c·6520·636c··m8127"><table·cl 
00039b00:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
00039b10:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00039b20:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co000399c0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 000399d0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 000399e0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 000399f0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00039b30:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00039b40:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00039b50:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00039b60:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00039b70:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
00039b80:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00039a00:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00039a10:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00039b90:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
00039ba0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
00039bb0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
00039bc0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
00039bd0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
00039be0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
00039bf0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
00039c00:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
00039c10:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
00039c20:·6f72·6d73·0a69·6620·2120·2820·7b20·7270··orms.if·!·(·{·rp 
00039c30:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker 
00039c40:·6e65·6c20·3b7d·2026·616d·703b·2661·6d70··nel·;}·&amp;&amp 
00039c50:·3b20·7b20·7270·6d20·2d2d·7175·6965·7420··;·{·rpm·--quiet· 
00039c60:·2d71·2072·706d·2d6f·7374·7265·6520·3b7d··-q·rpm-ostree·;} 
00039c70:·2026·616d·703b·2661·6d70·3b20·7b20·7270···&amp;&amp;·{·rp 
00039c80:·6d20·2d2d·7175·6965·7420·2d71·2062·6f6f··m·--quiet·-q·boo 
00039c90:·7463·203b·7d20·2661·6d70·3b26·616d·703b··tc·;}·&amp;&amp; 
00039ca0:·207b·2021·2072·706d·202d·2d71·7569·6574···{·!·rpm·--quiet 
00039cb0:·202d·7120·6f70·656e·7368·6966·742d·6b75···-q·openshift-ku 
00039cc0:·6265·6c65·7420·3b7d·2029·3b20·7468·656e··belet·;}·);·then 
00039cd0:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
00039ce0:·7175·6965·7420·2264·6e66·2d61·7574·6f6d··quiet·"dnf-autom 
00039cf0:·6174·6963·2220·3b20·7468·656e·0a20·2020··atic"·;·then.··· 
00039d00:·2064·6e66·2069·6e73·7461·6c6c·202d·7920···dnf·install·-y· 
00039d10:·2264·6e66·2d61·7574·6f6d·6174·6963·220a··"dnf-automatic". 
00039d20:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
00039d30:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
00039d40:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
00039d50:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
00039d60:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
00039d70:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
00039d80:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
00039d90:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
00039da0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
00039db0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
00039dc0:·6574·3d22·2369·646d·3831·3238·2220·7461··et="#idm8128"·ta 
00039dd0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00039de0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00039df0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00039e00:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00039e10:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00039e20:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
00039e30:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
00039e40:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00039e50:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00039e60:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00039e70:·6964·3d22·6964·6d38·3132·3822·3e3c·7461··id="idm8128"><ta 
00039e80:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
00039e90:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
00039ea0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
00039eb0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
00039ec0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
00039ed0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</00039a20:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00039ee0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00039ef0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
00039f00:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00039f10:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
00039f20:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
00039f30:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00039a30:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00039f40:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
00039f50:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
00039f60:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
00039f70:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat 
00039f80:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package· 
00039f90:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_ 
00039fa0:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag 
00039fb0:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags: 
00039fc0:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
00039fd0:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
00039fe0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
00039ff0:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m 
0003a000:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.· 
0003a010:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
0003a020:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_ 
Max diff block lines reached; 48154/78128 bytes (61.63%) of diff not shown.
10.6 KB
html2text {}
    
Offset 83, 19 lines modifiedOffset 83, 14 lines modified
83 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade83 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
84 ············suitable·for·automatic,·regular·execution.84 ············suitable·for·automatic,·regular·execution.
85 Severity: ··medium85 Severity: ··medium
86 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed86 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
87 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.287 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
88 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008088 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
89 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R6189 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
90 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
91 [[packages]] 
92 name·=·"dnf-automatic" 
93 version·=·"*" 
94 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
95 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low91 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
96 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low92 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
97 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false93 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
98 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable94 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
99 #·Remediation·is·applicable·only·in·certain·platforms95 #·Remediation·is·applicable·only·in·certain·platforms
100 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-96 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 135, 33 lines modifiedOffset 130, 38 lines modified
135 ··tags:130 ··tags:
136 ··-·enable_strategy131 ··-·enable_strategy
137 ··-·low_complexity132 ··-·low_complexity
138 ··-·low_disruption133 ··-·low_disruption
139 ··-·medium_severity134 ··-·medium_severity
140 ··-·no_reboot_needed135 ··-·no_reboot_needed
141 ··-·package_dnf-automatic_installed136 ··-·package_dnf-automatic_installed
 137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 142 package·--add=dnf-automatic
 143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 144 [[packages]]
 145 name·=·"dnf-automatic"
 146 version·=·"*"
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 include·install_dnf-automatic152 include·install_dnf-automatic
  
148 class·install_dnf-automatic·{153 class·install_dnf-automatic·{
149 ··package·{·'dnf-automatic':154 ··package·{·'dnf-automatic':
150 ····ensure·=>·'installed',155 ····ensure·=>·'installed',
151 ··}156 ··}
152 }157 }
153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
158 package·--add=dnf-automatic 
159 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*158 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
160 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed159 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
161 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/160 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
162 automatic.conf.161 automatic.conf.
163 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation162 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
164 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and163 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
165 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in164 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10898, 33 lines modifiedOffset 10898, 33 lines modified
10898 ··tags:10898 ··tags:
10899 ··-·disable_strategy10899 ··-·disable_strategy
10900 ··-·low_complexity10900 ··-·low_complexity
10901 ··-·low_disruption10901 ··-·low_disruption
10902 ··-·medium_severity10902 ··-·medium_severity
10903 ··-·no_reboot_needed10903 ··-·no_reboot_needed
10904 ··-·package_kea_removed10904 ··-·package_kea_removed
 10905 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10906 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10907 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10908 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10909 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10910 package·--remove=kea
10905 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10906 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10912 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10907 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10913 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10908 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10914 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10909 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10915 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10910 include·remove_kea10916 include·remove_kea
  
10911 class·remove_kea·{10917 class·remove_kea·{
10912 ··package·{·'kea':10918 ··package·{·'kea':
10913 ····ensure·=>·'purged',10919 ····ensure·=>·'purged',
10914 ··}10920 ··}
10915 }10921 }
10916 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10917 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10918 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10919 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10920 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10921 package·--remove=kea 
10922 Group  ·Obsolete·Services·  Group·contains·2·groups·and·4·rules10922 Group  ·Obsolete·Services·  Group·contains·2·groups·and·4·rules
10923 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically10923 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically
10924 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service10924 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service
10925 has·been·the·best·available·guidance·for·some·time.·As·a·result·of·this,·many·of·these10925 has·been·the·best·available·guidance·for·some·time.·As·a·result·of·this,·many·of·these
10926 services·are·not·installed·as·part·of·Oracle·Linux·10·by·default.10926 services·are·not·installed·as·part·of·Oracle·Linux·10·by·default.
  
10927 Organizations·which·are·running·these·services·should·switch·to·more·secure·equivalents·as10927 Organizations·which·are·running·these·services·should·switch·to·more·secure·equivalents·as
Offset 11007, 33 lines modifiedOffset 11007, 33 lines modified
11007 ··-·PCI-DSSv4-2.2.411007 ··-·PCI-DSSv4-2.2.4
11008 ··-·disable_strategy11008 ··-·disable_strategy
11009 ··-·high_severity11009 ··-·high_severity
11010 ··-·low_complexity11010 ··-·low_complexity
11011 ··-·low_disruption11011 ··-·low_disruption
11012 ··-·no_reboot_needed11012 ··-·no_reboot_needed
11013 ··-·package_telnet-server_removed11013 ··-·package_telnet-server_removed
 11014 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11015 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11016 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11017 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11018 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11019 package·--remove=telnet-server
11014 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811020 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11015 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11021 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11016 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11022 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11017 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11023 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11018 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11024 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11019 include·remove_telnet-server11025 include·remove_telnet-server
Max diff block lines reached; 5618/10829 bytes (51.88%) of diff not shown.
508 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-e8.html
    
Offset 22206, 850 lines modifiedOffset 22206, 850 lines modified
00056bd0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00056bd0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00056be0:·6d31·3336·3730·2220·7461·6269·6e64·6578··m13670"·tabindex00056be0:·6d31·3336·3730·2220·7461·6269·6e64·6578··m13670"·tabindex
00056bf0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00056bf0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00056c00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00056c00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00056c10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00056c10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00056c20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00056c20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00056c30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00056c30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
00056c40:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl00056c40:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern
 00056c50:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·...
 00056c60:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00056c70:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00056c50:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a 
00056c60:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00056c70:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00056c80:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00056c90:·6d31·3336·3730·223e·3c74·6162·6c65·2063··m13670"><table·c 
00056ca0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
00056cb0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
00056cc0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
00056cd0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
00056ce0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
00056cf0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00056d00:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
00056d10:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m 
00056d20:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr>< 
00056d30:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00056d40:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00056d50:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00056d60:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00056d70:·636f·6e66·6967·7572·653c·2f74·643e·3c2f··configure</td></ 
00056d80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
00056d90:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4761··<code>-·name:·Ga 
00056da0:·7468·6572·2074·6865·2070·6163·6b61·6765··ther·the·package 
00056db0:·2066·6163·7473·0a20·2070·6163·6b61·6765···facts.··package 
00056dc0:·5f66·6163·7473·3a0a·2020·2020·6d61·6e61··_facts:.····mana 
00056dd0:·6765·723a·2061·7574·6f0a·2020·7461·6773··ger:·auto.··tags 
00056de0:·3a0a·2020·2d20·434a·4953·2d35·2e35·2e32··:.··-·CJIS-5.5.2 
00056df0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17 
00056e00:·312d·332e·312e·310a·2020·2d20·4e49·5354··1-3.1.1.··-·NIST 
00056e10:·2d38·3030·2d31·3731·2d33·2e31·2e35·0a20··-800-171-3.1.5.· 
00056e20:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
00056e30:·4d2d·3628·6129·0a20·202d·204e·4953·542d··M-6(a).··-·NIST- 
00056e40:·3830·302d·3533·2d49·412d·3528·3129·2861··800-53-IA-5(1)(a 
00056e50:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
00056e60:·332d·4941·2d35·2863·290a·2020·2d20·5043··3-IA-5(c).··-·PC 
00056e70:·492d·4453·532d·5265·712d·382e·322e·330a··I-DSS-Req-8.2.3. 
00056e80:·2020·2d20·5043·492d·4453·5376·342d·382e····-·PCI-DSSv4-8. 
00056e90:·330a·2020·2d20·5043·492d·4453·5376·342d··3.··-·PCI-DSSv4- 
00056ea0:·382e·332e·310a·2020·2d20·636f·6e66·6967··8.3.1.··-·config 
00056eb0:·7572·655f·7374·7261·7465·6779·0a20·202d··ure_strategy.··- 
00056ec0:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.· 
00056ed0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
00056ee0:·790a·2020·2d20·6d65·6469·756d·5f64·6973··y.··-·medium_dis 
00056ef0:·7275·7074·696f·6e0a·2020·2d20·6e6f·5f65··ruption.··-·no_e 
00056f00:·6d70·7479·5f70·6173·7377·6f72·6473·0a20··mpty_passwords.· 
00056f10:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
00056f20:·6465·640a·0a2d·206e·616d·653a·2050·7265··ded..-·name:·Pre 
00056f30:·7665·6e74·204c·6f67·696e·2074·6f20·4163··vent·Login·to·Ac 
00056f40:·636f·756e·7473·2057·6974·6820·456d·7074··counts·With·Empt 
00056f50:·7920·5061·7373·776f·7264·202d·2043·6865··y·Password·-·Che 
00056f60:·636b·2069·6620·7379·7374·656d·2072·656c··ck·if·system·rel 
00056f70:·6965·7320·6f6e·0a20·2020·2061·7574·6873··ies·on.····auths 
00056f80:·656c·6563·740a·2020·616e·7369·626c·652e··elect.··ansible. 
00056f90:·6275·696c·7469·6e2e·7374·6174·3a0a·2020··builtin.stat:.·· 
00056fa0:·2020·7061·7468·3a20·2f75·7372·2f62·696e····path:·/usr/bin 
00056fb0:·2f61·7574·6873·656c·6563·740a·2020·7265··/authselect.··re 
00056fc0:·6769·7374·6572·3a20·7265·7375·6c74·5f61··gister:·result_a 
00056fd0:·7574·6873·656c·6563·745f·7072·6573·656e··uthselect_presen 
00056fe0:·740a·2020·7768·656e·3a20·2822·6b65·726e··t.··when:·("kern 
00056ff0:·656c·2220·696e·2061·6e73·6962·6c65·5f66··el"·in·ansible_f 
00057000:·6163·7473·2e70·6163·6b61·6765·7320·6f72··acts.packages·or 
00057010:·2022·6b65·726e·656c·2d75·656b·2220·696e···"kernel-uek"·in 
00057020:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p 
00057030:·6163·6b61·6765·7329·0a20·2074·6167·733a··ackages).··tags: 
00057040:·0a20·202d·2043·4a49·532d·352e·352e·320a··.··-·CJIS-5.5.2. 
00057050:·2020·2d20·4e49·5354·2d38·3030·2d31·3731····-·NIST-800-171 
00057060:·2d33·2e31·2e31·0a20·202d·204e·4953·542d··-3.1.1.··-·NIST- 
00057070:·3830·302d·3137·312d·332e·312e·350a·2020··800-171-3.1.5.·· 
00057080:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
00057090:·2d36·2861·290a·2020·2d20·4e49·5354·2d38··-6(a).··-·NIST-8 
000570a0:·3030·2d35·332d·4941·2d35·2831·2928·6129··00-53-IA-5(1)(a) 
000570b0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
000570c0:·2d49·412d·3528·6329·0a20·202d·2050·4349··-IA-5(c).··-·PCI 
000570d0:·2d44·5353·2d52·6571·2d38·2e32·2e33·0a20··-DSS-Req-8.2.3.· 
000570e0:·202d·2050·4349·2d44·5353·7634·2d38·2e33···-·PCI-DSSv4-8.3 
000570f0:·0a20·202d·2050·4349·2d44·5353·7634·2d38··.··-·PCI-DSSv4-8 
00057100:·2e33·2e31·0a20·202d·2063·6f6e·6669·6775··.3.1.··-·configu 
00057110:·7265·5f73·7472·6174·6567·790a·2020·2d20··re_strategy.··-· 
00057120:·6869·6768·5f73·6576·6572·6974·790a·2020··high_severity.·· 
00057130:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity 
00057140:·0a20·202d·206d·6564·6975·6d5f·6469·7372··.··-·medium_disr 
00057150:·7570·7469·6f6e·0a20·202d·206e·6f5f·656d··uption.··-·no_em 
00057160:·7074·795f·7061·7373·776f·7264·730a·2020··pty_passwords.·· 
00057170:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need 
00057180:·6564·0a0a·2d20·6e61·6d65·3a20·5072·6576··ed..-·name:·Prev 
00057190:·656e·7420·4c6f·6769·6e20·746f·2041·6363··ent·Login·to·Acc 
000571a0:·6f75·6e74·7320·5769·7468·2045·6d70·7479··ounts·With·Empty 
000571b0:·2050·6173·7377·6f72·6420·2d20·5265·6d65···Password·-·Reme 
000571c0:·6469·6174·6520·7573·696e·6720·6175·7468··diate·using·auth 
000571d0:·7365·6c65·6374·0a20·2062·6c6f·636b·3a0a··select.··block:. 
000571e0:·0a20·202d·206e·616d·653a·2050·7265·7665··.··-·name:·Preve 
000571f0:·6e74·204c·6f67·696e·2074·6f20·4163·636f··nt·Login·to·Acco 
00057200:·756e·7473·2057·6974·6820·456d·7074·7920··unts·With·Empty· 
00057210:·5061·7373·776f·7264·202d·2043·6865·636b··Password·-·Check 
00057220:·2069·6e74·6567·7269·7479·206f·6620·6175···integrity·of·au 
00057230:·7468·7365·6c65·6374·0a20·2020·2020·2063··thselect.······c 
00057240:·7572·7265·6e74·2070·726f·6669·6c65·0a20··urrent·profile.· 
00057250:·2020·2061·6e73·6962·6c65·2e62·7569·6c74·····ansible.built 
00057260:·696e·2e63·6f6d·6d61·6e64·3a0a·2020·2020··in.command:.···· 
00057270:·2020·636d·643a·2061·7574·6873·656c·6563····cmd:·authselec 
00057280:·7420·6368·6563·6b0a·2020·2020·7265·6769··t·check.····regi 
00057290:·7374·6572·3a20·7265·7375·6c74·5f61·7574··ster:·result_aut 
000572a0:·6873·656c·6563·745f·6368·6563·6b5f·636d··hselect_check_cm 
000572b0:·640a·2020·2020·6368·616e·6765·645f·7768··d.····changed_wh 
000572c0:·656e·3a20·6661·6c73·650a·2020·2020·6661··en:·false.····fa 
000572d0:·696c·6564·5f77·6865·6e3a·2066·616c·7365··iled_when:·false 
000572e0:·0a0a·2020·2d20·6e61·6d65·3a20·5072·6576··..··-·name:·Prev 
000572f0:·656e·7420·4c6f·6769·6e20·746f·2041·6363··ent·Login·to·Acc 
00057300:·6f75·6e74·7320·5769·7468·2045·6d70·7479··ounts·With·Empty 
00057310:·2050·6173·7377·6f72·6420·2d20·496e·666f···Password·-·Info 
00057320:·726d·6174·6976·6520·6d65·7373·6167·6520··rmative·message· 
00057330:·6261·7365·640a·2020·2020·2020·6f6e·2074··based.······on·t 
00057340:·6865·2061·7574·6873·656c·6563·7420·696e··he·authselect·in 
00057350:·7465·6772·6974·7920·6368·6563·6b20·7265··tegrity·check·re 
00057360:·7375·6c74·0a20·2020·2061·6e73·6962·6c65··sult.····ansible 
00057370:·2e62·7569·6c74·696e·2e61·7373·6572·743a··.builtin.assert: 
00057380:·0a20·2020·2020·2074·6861·743a·0a20·2020··.······that:.··· 
Max diff block lines reached; 426364/471794 bytes (90.37%) of diff not shown.
47.3 KB
html2text {}
    
Offset 1677, 14 lines modifiedOffset 1677, 38 lines modified
1677 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"1677 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
1678 fi1678 fi
1679 fi1679 fi
  
1680 else1680 else
1681 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1681 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1682 fi1682 fi
 1683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1684 ---
 1685 apiVersion:·machineconfiguration.openshift.io/v1
 1686 kind:·MachineConfig
 1687 spec:
 1688 ··config:
 1689 ····ignition:
 1690 ······version:·3.1.0
 1691 ····storage:
 1692 ······files:
 1693 ······-·contents:
 1694 ··········source:
 1695 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1696 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1697 ········mode:·0644
 1698 ········path:·/etc/pam.d/password-auth
 1699 ········overwrite:·true
 1700 ······-·contents:
 1701 ··········source:
 1702 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1703 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1704 ········mode:·0644
 1705 ········path:·/etc/pam.d/system-auth
 1706 ········overwrite:·true
1683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81707 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1684 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1708 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1685 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1709 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1686 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1710 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1687 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure1711 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
1688 -·name:·Gather·the·package·facts1712 -·name:·Gather·the·package·facts
1689 ··package_facts:1713 ··package_facts:
Offset 1823, 38 lines modifiedOffset 1847, 14 lines modified
1823 ··-·PCI-DSSv4-8.3.11847 ··-·PCI-DSSv4-8.3.1
1824 ··-·configure_strategy1848 ··-·configure_strategy
1825 ··-·high_severity1849 ··-·high_severity
1826 ··-·low_complexity1850 ··-·low_complexity
1827 ··-·medium_disruption1851 ··-·medium_disruption
1828 ··-·no_empty_passwords1852 ··-·no_empty_passwords
1829 ··-·no_reboot_needed1853 ··-·no_reboot_needed
1830 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1831 --- 
1832 apiVersion:·machineconfiguration.openshift.io/v1 
1833 kind:·MachineConfig 
1834 spec: 
1835 ··config: 
1836 ····ignition: 
1837 ······version:·3.1.0 
1838 ····storage: 
1839 ······files: 
1840 ······-·contents: 
1841 ··········source: 
1842 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1843 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1844 ········mode:·0644 
1845 ········path:·/etc/pam.d/password-auth 
1846 ········overwrite:·true 
1847 ······-·contents: 
1848 ··········source: 
1849 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1850 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1851 ········mode:·0644 
1852 ········path:·/etc/pam.d/system-auth 
1853 ········overwrite:·true 
1854 Group  ·Restrict·Root·Logins·  Group·contains·1·rule1854 Group  ·Restrict·Root·Logins·  Group·contains·1·rule
1855 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.1855 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.
1856 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·O\x8On\x8nl\x8ly\x8y·R\x8Ro\x8oo\x8ot\x8t·H\x8Ha\x8as\x8s·U\x8UI\x8ID\x8D·0\x80·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1856 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·O\x8On\x8nl\x8ly\x8y·R\x8Ro\x8oo\x8ot\x8t·H\x8Ha\x8as\x8s·U\x8UI\x8ID\x8D·0\x80·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1857 If·any·account·other·than·root·has·a·UID·of·0,·this·misconfiguration·should·be·investigated·and·the·accounts·other·than·root·should·be·removed·or·have·their·UID·changed.1857 If·any·account·other·than·root·has·a·UID·of·0,·this·misconfiguration·should·be·investigated·and·the·accounts·other·than·root·should·be·removed·or·have·their·UID·changed.
1858 If·the·account·is·associated·with·system·commands·or·applications·the·UID·should·be·changed·to·one·greater·than·"0"·but·less·than·"1000."·Otherwise·assign·a·UID·greater·than·"1000"·that·has·not·already·been·assigned.1858 If·the·account·is·associated·with·system·commands·or·applications·the·UID·should·be·changed·to·one·greater·than·"0"·but·less·than·"1000."·Otherwise·assign·a·UID·greater·than·"1000"·that·has·not·already·been·assigned.
1859 Rationale:··An·account·has·root·authority·if·it·has·a·UID·of·0.·Multiple·accounts·with·a·UID·of·0·afford·more·opportunity·for·potential·intruders·to·guess·a·password·for·a·privileged·account.·Proper·configuration·of·sudo·is·recommended·to·afford·multiple·system·administrators·access·to·root·privileges·in·an·accountable·manner.1859 Rationale:··An·account·has·root·authority·if·it·has·a·UID·of·0.·Multiple·accounts·with·a·UID·of·0·afford·more·opportunity·for·potential·intruders·to·guess·a·password·for·a·privileged·account.·Proper·configuration·of·sudo·is·recommended·to·afford·multiple·system·administrators·access·to·root·privileges·in·an·accountable·manner.
1860 Severity: ··high1860 Severity: ··high
Offset 2068, 19 lines modifiedOffset 2068, 14 lines modified
2068 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.312(a)(2)(ii)2068 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.312(a)(2)(ii)
2069 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.42069 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4
2070 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.92070 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
2071 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.12071 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
2072 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)2072 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
2073 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-12073 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
2074 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-002272074 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
2075 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2076 [[packages]] 
2077 name·=·"rsyslog" 
2078 version·=·"*" 
2079 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82075 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2080 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2076 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2081 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2077 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2082 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2078 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2083 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2079 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2084 #·Remediation·is·applicable·only·in·certain·platforms2080 #·Remediation·is·applicable·only·in·certain·platforms
2085 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then2081 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 2118, 33 lines modifiedOffset 2113, 38 lines modified
2118 ··-·NIST-800-53-CM-6(a)2113 ··-·NIST-800-53-CM-6(a)
2119 ··-·enable_strategy2114 ··-·enable_strategy
2120 ··-·low_complexity2115 ··-·low_complexity
2121 ··-·low_disruption2116 ··-·low_disruption
2122 ··-·medium_severity2117 ··-·medium_severity
2123 ··-·no_reboot_needed2118 ··-·no_reboot_needed
2124 ··-·package_rsyslog_installed2119 ··-·package_rsyslog_installed
 2120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2125 package·--add=rsyslog
 2126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2127 [[packages]]
 2128 name·=·"rsyslog"
 2129 version·=·"*"
2125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2130 include·install_rsyslog2135 include·install_rsyslog
  
2131 class·install_rsyslog·{2136 class·install_rsyslog·{
2132 ··package·{·'rsyslog':2137 ··package·{·'rsyslog':
2133 ····ensure·=>·'installed',2138 ····ensure·=>·'installed',
Max diff block lines reached; 26328/48437 bytes (54.36%) of diff not shown.
621 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-hipaa.html
    
Offset 21050, 302 lines modifiedOffset 21050, 302 lines modified
00052390:·612d·7461·7267·6574·3d22·2369·646d·3131··a-target="#idm1100052390:·612d·7461·7267·6574·3d22·2369·646d·3131··a-target="#idm11
000523a0:·3332·3122·2074·6162·696e·6465·783d·2230··321"·tabindex="0000523a0:·3332·3122·2074·6162·696e·6465·783d·2230··321"·tabindex="0
000523b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·000523b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
000523c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f000523c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
000523d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act000523d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
000523e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"000523e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
000523f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed000523f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00052400:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B00052400:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
00052410:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
00052420:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00052430:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00052440:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00052450:·2069·643d·2269·646d·3131·3332·3122·3e3c···id="idm11321">< 
00052460:·7072·653e·3c63·6f64·653e·0a5b·6375·7374··pre><code>.[cust 
00052470:·6f6d·697a·6174·696f·6e73·2e73·6572·7669··omizations.servi 
00052480:·6365·735d·0a6d·6173·6b65·6420·3d20·5b22··ces].masked·=·["00052410:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 00052420:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00052430:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00052440:·7365·2220·6964·3d22·6964·6d31·3133·3231··se"·id="idm11321
 00052450:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00052460:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 00052470:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00052480:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00052490:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 000524a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 000524b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 000524c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 000524d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 000524e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 000524f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00052500:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00052510:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00052520:·7468·3e3c·7464·3e64·6973·6162·6c65·3c2f··th><td>disable</
 00052530:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 00052540:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 00052550:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 00052560:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 00052570:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 00052580:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet·
 00052590:·2d71·206b·6572·6e65·6c20·7c7c·2072·706d··-q·kernel·||·rpm
 000525a0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 000525b0:·656c·2d75·656b·3b20·7468·656e·0a0a·5359··el-uek;·then..SY
 000525c0:·5354·454d·4354·4c5f·4558·4543·3d27·2f75··STEMCTL_EXEC='/u
 000525d0:·7372·2f62·696e·2f73·7973·7465·6d63·746c··sr/bin/systemctl
 000525e0:·270a·6966·205b·5b20·2428·2224·5359·5354··'.if·[[·$("$SYST
 000525f0:·454d·4354·4c5f·4558·4543·2220·6973·2d73··EMCTL_EXEC"·is-s
 00052600:·7973·7465·6d2d·7275·6e6e·696e·6729·2021··ystem-running)·!
 00052610:·3d20·226f·6666·6c69·6e65·2220·5d5d·3b20··=·"offline"·]];·
 00052620:·7468·656e·0a20·2022·2453·5953·5445·4d43··then.··"$SYSTEMC
 00052630:·544c·5f45·5845·4322·2073·746f·7020·2764··TL_EXEC"·stop·'d
 00052640:·6562·7567·2d73·6865·6c6c·2e73·6572·7669··ebug-shell.servi
 00052650:·6365·270a·6669·0a22·2453·5953·5445·4d43··ce'.fi."$SYSTEMC
 00052660:·544c·5f45·5845·4322·2064·6973·6162·6c65··TL_EXEC"·disable
00052490:·6465·6275·672d·7368·656c·6c22·5d0a·3c2f··debug-shell"].</00052670:·2027·6465·6275·672d·7368·656c·6c2e·7365···'debug-shell.se
 00052680:·7276·6963·6527·0a22·2453·5953·5445·4d43··rvice'."$SYSTEMC
 00052690:·544c·5f45·5845·4322·206d·6173·6b20·2764··TL_EXEC"·mask·'d
 000526a0:·6562·7567·2d73·6865·6c6c·2e73·6572·7669··ebug-shell.servi
 000526b0:·6365·270a·2320·4469·7361·626c·6520·736f··ce'.#·Disable·so
 000526c0:·636b·6574·2061·6374·6976·6174·696f·6e20··cket·activation·
 000526d0:·6966·2077·6520·6861·7665·2061·2075·6e69··if·we·have·a·uni
 000526e0:·7420·6669·6c65·2066·6f72·2069·740a·6966··t·file·for·it.if
 000526f0:·2022·2453·5953·5445·4d43·544c·5f45·5845···"$SYSTEMCTL_EXE
 00052700:·4322·202d·7120·6c69·7374·2d75·6e69·742d··C"·-q·list-unit-
 00052710:·6669·6c65·7320·6465·6275·672d·7368·656c··files·debug-shel
 00052720:·6c2e·736f·636b·6574·3b20·7468·656e·0a20··l.socket;·then.·
 00052730:·2020·2069·6620·5b5b·2024·2822·2453·5953·····if·[[·$("$SYS
 00052740:·5445·4d43·544c·5f45·5845·4322·2069·732d··TEMCTL_EXEC"·is-
 00052750:·7379·7374·656d·2d72·756e·6e69·6e67·2920··system-running)·
 00052760:·213d·2022·6f66·666c·696e·6522·205d·5d3b··!=·"offline"·]];
 00052770:·2074·6865·6e0a·2020·2020·2020·2224·5359···then.······"$SY
000524a0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
000524b0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
000524c0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
000524d0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
000524e0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
000524f0:·2369·646d·3131·3332·3222·2074·6162·696e··#idm11322"·tabin 
00052500:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
00052510:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
00052520:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
00052530:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
00052540:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
00052550:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
00052560:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
00052570:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00052580:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00052590:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
000525a0:·6d31·3133·3232·223e·3c74·6162·6c65·2063··m11322"><table·c 
000525b0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
000525c0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
000525d0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
000525e0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
000525f0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
00052600:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00052610:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
00052620:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
00052630:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00052640:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
00052650:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
00052660:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
00052670:·6567·793a·3c2f·7468·3e3c·7464·3e64·6973··egy:</th><td>dis 
00052680:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
00052690:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
000526a0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
000526b0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
000526c0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
000526d0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·-- 
000526e0:·7175·6965·7420·2d71·206b·6572·6e65·6c20··quiet·-q·kernel· 
000526f0:·7c7c·2072·706d·202d·2d71·7569·6574·202d··||·rpm·--quiet·- 
00052700:·7120·6b65·726e·656c·2d75·656b·3b20·7468··q·kernel-uek;·th 
00052710:·656e·0a0a·5359·5354·454d·4354·4c5f·4558··en..SYSTEMCTL_EX 
00052720:·4543·3d27·2f75·7372·2f62·696e·2f73·7973··EC='/usr/bin/sys 
00052730:·7465·6d63·746c·270a·6966·205b·5b20·2428··temctl'.if·[[·$( 
00052740:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC00052780:·5354·454d·4354·4c5f·4558·4543·2220·7374··STEMCTL_EXEC"·st
00052750:·2220·6973·2d73·7973·7465·6d2d·7275·6e6e··"·is-system-runn 
00052760:·696e·6729·2021·3d20·226f·6666·6c69·6e65··ing)·!=·"offline 
00052770:·2220·5d5d·3b20·7468·656e·0a20·2022·2453··"·]];·then.··"$S00052790:·6f70·2027·6465·6275·672d·7368·656c·6c2e··op·'debug-shell.
 000527a0:·736f·636b·6574·270a·2020·2020·6669·0a20··socket'.····fi.·
 000527b0:·2020·2022·2453·5953·5445·4d43·544c·5f45·····"$SYSTEMCTL_E
 000527c0:·5845·4322·206d·6173·6b20·2764·6562·7567··XEC"·mask·'debug
 000527d0:·2d73·6865·6c6c·2e73·6f63·6b65·7427·0a66··-shell.socket'.f
 000527e0:·690a·2320·5468·6520·7365·7276·6963·6520··i.#·The·service·
 000527f0:·6d61·7920·6e6f·7420·6265·2072·756e·6e69··may·not·be·runni
 00052800:·6e67·2062·6563·6175·7365·2069·7420·6861··ng·because·it·ha
 00052810:·7320·6265·656e·2073·7461·7274·6564·2061··s·been·started·a
 00052820:·6e64·2066·6169·6c65·642c·0a23·2073·6f20··nd·failed,.#·so·
 00052830:·6c65·7427·7320·7265·7365·7420·7468·6520··let's·reset·the·
 00052840:·7374·6174·6520·736f·204f·5641·4c20·6368··state·so·OVAL·ch
Max diff block lines reached; 536759/577083 bytes (93.01%) of diff not shown.
57.7 KB
html2text {}
    
Offset 1265, 18 lines modifiedOffset 1265, 14 lines modified
1265 Rule·ID:····xccdf_org.ssgproject.content_rule_service_debug-shell_disabled1265 Rule·ID:····xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
1266 ············_\x8c_\x8u_\x8i····3.4.51266 ············_\x8c_\x8u_\x8i····3.4.5
1267 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-0022351267 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
1268 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1268 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1269 ············_\x8n_\x8i_\x8s_\x8t···CM-61269 ············_\x8n_\x8i_\x8s_\x8t···CM-6
1270 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.11270 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
1271 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271271 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1272 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1273 [customizations.services] 
1274 masked·=·["debug-shell"] 
1275 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81272 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1276 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1273 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1277 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1274 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1278 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1275 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1279 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1276 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1280 #·Remediation·is·applicable·only·in·certain·platforms1277 #·Remediation·is·applicable·only·in·certain·platforms
1281 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1278 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1388, 14 lines modifiedOffset 1384, 18 lines modified
1388 ··-·NIST-800-53-CM-61384 ··-·NIST-800-53-CM-6
1389 ··-·disable_strategy1385 ··-·disable_strategy
1390 ··-·low_complexity1386 ··-·low_complexity
1391 ··-·low_disruption1387 ··-·low_disruption
1392 ··-·medium_severity1388 ··-·medium_severity
1393 ··-·no_reboot_needed1389 ··-·no_reboot_needed
1394 ··-·service_debug-shell_disabled1390 ··-·service_debug-shell_disabled
 1391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1392 [customizations.services]
 1393 masked·=·["debug-shell"]
1395 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81394 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1396 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1395 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1397 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1396 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1398 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1397 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1399 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1398 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1400 include·disable_debug-shell1399 include·disable_debug-shell
  
Offset 1967, 14 lines modifiedOffset 1967, 38 lines modified
1967 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"1967 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
1968 fi1968 fi
1969 fi1969 fi
  
1970 else1970 else
1971 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1971 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1972 fi1972 fi
 1973 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1974 ---
 1975 apiVersion:·machineconfiguration.openshift.io/v1
 1976 kind:·MachineConfig
 1977 spec:
 1978 ··config:
 1979 ····ignition:
 1980 ······version:·3.1.0
 1981 ····storage:
 1982 ······files:
 1983 ······-·contents:
 1984 ··········source:
 1985 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1986 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1987 ········mode:·0644
 1988 ········path:·/etc/pam.d/password-auth
 1989 ········overwrite:·true
 1990 ······-·contents:
 1991 ··········source:
 1992 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1993 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1994 ········mode:·0644
 1995 ········path:·/etc/pam.d/system-auth
 1996 ········overwrite:·true
1973 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81997 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1974 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1998 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1975 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1999 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1976 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2000 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1977 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure2001 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
1978 -·name:·Gather·the·package·facts2002 -·name:·Gather·the·package·facts
1979 ··package_facts:2003 ··package_facts:
Offset 2113, 38 lines modifiedOffset 2137, 14 lines modified
2113 ··-·PCI-DSSv4-8.3.12137 ··-·PCI-DSSv4-8.3.1
2114 ··-·configure_strategy2138 ··-·configure_strategy
2115 ··-·high_severity2139 ··-·high_severity
2116 ··-·low_complexity2140 ··-·low_complexity
2117 ··-·medium_disruption2141 ··-·medium_disruption
2118 ··-·no_empty_passwords2142 ··-·no_empty_passwords
2119 ··-·no_reboot_needed2143 ··-·no_reboot_needed
2120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2121 --- 
2122 apiVersion:·machineconfiguration.openshift.io/v1 
2123 kind:·MachineConfig 
2124 spec: 
2125 ··config: 
2126 ····ignition: 
2127 ······version:·3.1.0 
2128 ····storage: 
2129 ······files: 
2130 ······-·contents: 
2131 ··········source: 
2132 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
2133 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
2134 ········mode:·0644 
2135 ········path:·/etc/pam.d/password-auth 
2136 ········overwrite:·true 
2137 ······-·contents: 
2138 ··········source: 
2139 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
2140 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
2141 ········mode:·0644 
2142 ········path:·/etc/pam.d/system-auth 
2143 ········overwrite:·true 
2144 Group  ·Restrict·Root·Logins·  Group·contains·3·rules2144 Group  ·Restrict·Root·Logins·  Group·contains·3·rules
2145 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.2145 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.
2146 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8ir\x8re\x8ec\x8ct\x8t·r\x8ro\x8oo\x8ot\x8t·L\x8Lo\x8og\x8gi\x8in\x8ns\x8s·N\x8No\x8ot\x8t·A\x8Al\x8ll\x8lo\x8ow\x8we\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2146 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8ir\x8re\x8ec\x8ct\x8t·r\x8ro\x8oo\x8ot\x8t·L\x8Lo\x8og\x8gi\x8in\x8ns\x8s·N\x8No\x8ot\x8t·A\x8Al\x8ll\x8lo\x8ow\x8we\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2147 To·further·limit·access·to·the·root·account,·administrators·can·disable·root·logins·at·the·console·by·editing·the·/etc/securetty·file.·This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does·not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the·system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous·as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in·plain·text·over·the·network.·By·default,·Oracle·Linux·10's·/etc/securetty·file·only·allows·the·root·user·to·login·at·the·console·physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the·contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this·file·by·typing·the·following·command:2147 To·further·limit·access·to·the·root·account,·administrators·can·disable·root·logins·at·the·console·by·editing·the·/etc/securetty·file.·This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does·not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the·system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous·as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in·plain·text·over·the·network.·By·default,·Oracle·Linux·10's·/etc/securetty·file·only·allows·the·root·user·to·login·at·the·console·physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the·contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this·file·by·typing·the·following·command:
2148 $·sudo·echo·>·/etc/securetty2148 $·sudo·echo·>·/etc/securetty
2149 Warning: ·This·rule·only·checks·the·/etc/securetty·file·existence·and·its·content.·If·you·need·to·restrict·user·access·using·the·/etc/securetty·file,·make·sure·the·pam_securetty.so·PAM·module·is·properly·enabled·in·relevant·PAM·files.2149 Warning: ·This·rule·only·checks·the·/etc/securetty·file·existence·and·its·content.·If·you·need·to·restrict·user·access·using·the·/etc/securetty·file,·make·sure·the·pam_securetty.so·PAM·module·is·properly·enabled·in·relevant·PAM·files.
2150 Rationale:··Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor·authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate·to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low·and·FISMA·Moderate·systems.2150 Rationale:··Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor·authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate·to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low·and·FISMA·Moderate·systems.
Offset 3274, 19 lines modifiedOffset 3274, 14 lines modified
3274 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.312(a)(2)(ii)3274 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.312(a)(2)(ii)
3275 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.43275 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4
3276 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.93276 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
3277 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.13277 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
3278 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3278 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3279 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-13279 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
3280 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-002273280 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
3281 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3282 [[packages]] 
3283 name·=·"rsyslog" 
Max diff block lines reached; 35896/59084 bytes (60.75%) of diff not shown.
906 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-ism_o.html
    
Offset 17320, 217 lines modifiedOffset 17320, 217 lines modified
00043a70:·7461·7267·6574·3d22·2369·646d·3530·3937··target="#idm509700043a70:·7461·7267·6574·3d22·2369·646d·3530·3937··target="#idm5097
00043a80:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00043a80:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00043a90:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00043a90:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00043aa0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00043aa0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00043ab0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00043ab0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00043ac0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00043ac0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00043ad0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00043ad0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00043ae0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
00043ae0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
00043af0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
00043b00:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00043b10:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
00043b20:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
00043b30:·3d22·6964·6d35·3039·3722·3e3c·7072·653e··="idm5097"><pre> 
00043b40:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
00043b50:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
00043b60:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
00043b70:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
00043b80:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
00043b90:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00043ba0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00043bb0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00043bc0:·3d22·2369·646d·3530·3938·2220·7461·6269··="#idm5098"·tabi 
00043bd0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00043be0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00043bf0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00043c00:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00043c10:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00043c20:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
00043c30:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
00043c40:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00043c50:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00043c60:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00043c70:·646d·3530·3938·223e·3c74·6162·6c65·2063··dm5098"><table·c 
00043c80:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
00043c90:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
00043ca0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
00043cb0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
00043cc0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
00043cd0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00043ce0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
00043cf0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
00043d00:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00043d10:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
00043d20:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
00043d30:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
00043d40:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
00043d50:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
00043d60:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
00043d70:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
00043d80:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
00043d90:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
00043da0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q 
00043db0:·7569·6574·202d·7120·6b65·726e·656c·207c··uiet·-q·kernel·| 
00043dc0:·7c20·7270·6d20·2d2d·7175·6965·7420·2d71··|·rpm·--quiet·-q 
00043dd0:·206b·6572·6e65·6c2d·7565·6b3b·2074·6865···kernel-uek;·the 
00043de0:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
00043df0:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
00043e00:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins 
00043e10:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
00043e20:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
00043e30:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
00043e40:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
00043e50:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
00043e60:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
00043e70:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
00043e80:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
00043e90:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
00043ea0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
00043eb0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
00043ec0:·743d·2223·6964·6d35·3039·3922·2074·6162··t="#idm5099"·tab 
00043ed0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
00043ee0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
00043ef0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
00043f00:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
00043f10:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
00043f20:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
00043f30:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
00043f40:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00043af0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
00043f50:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00043b00:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00043f60:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00043b10:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00043f70:·643d·2269·646d·3530·3939·223e·3c74·6162··d="idm5099"><tab00043b20:·2069·643d·2269·646d·3530·3937·223e·3c74···id="idm5097"><t
00043f80:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00043b30:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
00043f90:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00043b40:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
00043fa0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab00043b50:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
00043fb0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t00043b60:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
00043fc0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00043b70:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
00043fd0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00043b80:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00043b90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00043ba0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00043bb0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00043bc0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00043bd0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
00043fe0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D00043be0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00043ff0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
00044000:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00044010:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
00044020:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
00044030:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
00044040:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00043bf0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00044050:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr00043c00:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
00044060:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c00043c10:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00043c20:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 00043c30:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 00043c40:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 00043c50:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 00043c60:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 00043c70:·726e·656c·207c·7c20·7270·6d20·2d2d·7175··rnel·||·rpm·--qu
 00043c80:·6965·7420·2d71·206b·6572·6e65·6c2d·7565··iet·-q·kernel-ue
 00043c90:·6b3b·2074·6865·6e0a·0a69·6620·2120·7270··k;·then..if·!·rp
 00043ca0:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 00043cb0:·6465·2220·3b20·7468·656e·0a20·2020·2064··de"·;·then.····d
 00043cc0:·6e66·2069·6e73·7461·6c6c·202d·7920·2261··nf·install·-y·"a
 00043cd0:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 00043ce0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 00043cf0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 00043d00:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 00043d10:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 00043d20:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
00044070:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
00044080:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f 
00044090:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f 
000440a0:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage 
000440b0:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:. 
000440c0:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
000440d0:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5 
000440e0:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC 
Max diff block lines reached; 812509/841103 bytes (96.60%) of diff not shown.
84.2 KB
html2text {}
    
Offset 682, 19 lines modifiedOffset 682, 14 lines modified
682 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3682 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
683 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)683 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
684 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3684 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
685 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5685 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
686 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199686 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
687 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79687 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
688 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2688 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
689 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
690 [[packages]] 
691 name·=·"aide" 
692 version·=·"*" 
693 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8689 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
694 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low690 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
695 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low691 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
696 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false692 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
697 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable693 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
698 #·Remediation·is·applicable·only·in·certain·platforms694 #·Remediation·is·applicable·only·in·certain·platforms
699 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then695 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 738, 33 lines modifiedOffset 733, 38 lines modified
738 ··-·PCI-DSSv4-11.5.2733 ··-·PCI-DSSv4-11.5.2
739 ··-·enable_strategy734 ··-·enable_strategy
740 ··-·low_complexity735 ··-·low_complexity
741 ··-·low_disruption736 ··-·low_disruption
742 ··-·medium_severity737 ··-·medium_severity
743 ··-·no_reboot_needed738 ··-·no_reboot_needed
744 ··-·package_aide_installed739 ··-·package_aide_installed
 740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 745 package·--add=aide
 746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 747 [[packages]]
 748 name·=·"aide"
 749 version·=·"*"
745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
746 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low751 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
747 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low752 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
748 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false753 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
749 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable754 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
750 include·install_aide755 include·install_aide
  
751 class·install_aide·{756 class·install_aide·{
752 ··package·{·'aide':757 ··package·{·'aide':
753 ····ensure·=>·'installed',758 ····ensure·=>·'installed',
754 ··}759 ··}
755 }760 }
756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
757 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
761 package·--add=aide 
762 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules761 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
763 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.762 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
764 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.763 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.
  
765 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.764 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
766 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*765 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 783, 31 lines modifiedOffset 783, 31 lines modified
783 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode783 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
784 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877784 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
785 ············_\x8i_\x8s_\x8m······1446785 ············_\x8i_\x8s_\x8m······1446
786 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1786 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
787 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12787 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
788 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1788 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
789 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176789 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
791 [customizations] 
792 fips·=·true 
793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
794 #·Remediation·is·applicable·only·in·certain·platforms791 #·Remediation·is·applicable·only·in·certain·platforms
795 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then792 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
796 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then793 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
797 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF794 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
798 kargs·=·["fips=1"]795 kargs·=·["fips=1"]
799 EOF796 EOF
800 fi797 fi
  
801 else798 else
802 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'799 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
803 fi800 fi
 801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 802 [customizations]
 803 fips·=·true
804 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*804 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
805 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:805 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
806 #·cat·/proc/sys/crypto/fips_enabled806 #·cat·/proc/sys/crypto/fips_enabled
807 1807 1
808 Warning: ·To·configure·Oracle·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Oracle·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.808 Warning: ·To·configure·Oracle·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Oracle·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
809 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.809 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
810 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.810 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 1008, 19 lines modifiedOffset 1008, 14 lines modified
1008 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351008 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1009 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861009 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1010 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1010 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1011 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11011 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1012 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251012 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1013 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331013 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1014 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21014 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1016 [[packages]] 
1017 name·=·"sudo" 
1018 version·=·"*" 
1019 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1020 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1016 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1021 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1017 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1022 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1018 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1023 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1019 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1024 #·Remediation·is·applicable·only·in·certain·platforms1020 #·Remediation·is·applicable·only·in·certain·platforms
1025 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1021 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1062, 33 lines modifiedOffset 1057, 38 lines modified
1062 ··-·PCI-DSSv4-2.2.61057 ··-·PCI-DSSv4-2.2.6
1063 ··-·enable_strategy1058 ··-·enable_strategy
1064 ··-·low_complexity1059 ··-·low_complexity
1065 ··-·low_disruption1060 ··-·low_disruption
1066 ··-·medium_severity1061 ··-·medium_severity
Max diff block lines reached; 77962/86161 bytes (90.48%) of diff not shown.
906 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-ism_o_secret.html
    
Offset 17320, 218 lines modifiedOffset 17320, 218 lines modified
00043a70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00043a70:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
00043a80:·743d·2223·6964·6d35·3039·3722·2074·6162··t="#idm5097"·tab00043a80:·743d·2223·6964·6d35·3039·3722·2074·6162··t="#idm5097"·tab
00043a90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00043a90:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00043aa0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00043aa0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00043ab0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00043ab0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00043ac0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00043ac0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00043ad0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00043ad0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00043ae0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O00043ae0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
 00043af0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
00043af0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
00043b00:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
00043b10:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
00043b20:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
00043b30:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
00043b40:·3530·3937·223e·3c70·7265·3e3c·636f·6465··5097"><pre><code 
00043b50:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
00043b60:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
00043b70:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
00043b80:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
00043b90:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
00043ba0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
00043bb0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
00043bc0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
00043bd0:·6d35·3039·3822·2074·6162·696e·6465·783d··m5098"·tabindex= 
00043be0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
00043bf0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
00043c00:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
00043c10:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
00043c20:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
00043c30:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
00043c40:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br 
00043c50:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00043c60:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00043c70:·6170·7365·2220·6964·3d22·6964·6d35·3039··apse"·id="idm509 
00043c80:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class= 
00043c90:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
00043ca0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
00043cb0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
00043cc0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
00043cd0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
00043ce0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00043cf0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00043d00:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00043d10:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
00043d20:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
00043d30:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
00043d40:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
00043d50:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
00043d60:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
00043d70:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem 
00043d80:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
00043d90:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
00043da0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
00043db0:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet· 
00043dc0:·2d71·206b·6572·6e65·6c20·7c7c·2072·706d··-q·kernel·||·rpm 
00043dd0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern 
00043de0:·656c·2d75·656b·3b20·7468·656e·0a0a·6966··el-uek;·then..if 
00043df0:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
00043e00:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then. 
00043e10:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install· 
00043e20:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el 
00043e30:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
00043e40:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
00043e50:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
00043e60:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
00043e70:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
00043e80:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
00043e90:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
00043ea0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
00043eb0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
00043ec0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
00043ed0:·646d·3530·3939·2220·7461·6269·6e64·6578··dm5099"·tabindex 
00043ee0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00043ef0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00043f00:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00043f10:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
00043f20:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
00043f30:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl 
00043f40:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a 
00043f50:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=00043b00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00043f60:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·00043b10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00043f70:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id00043b20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00043f80:·6d35·3039·3922·3e3c·7461·626c·6520·636c··m5099"><table·cl00043b30:·6964·6d35·3039·3722·3e3c·7461·626c·6520··idm5097"><table·
00043f90:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table00043b40:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
00043fa0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b00043b50:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
00043fb0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co00043b60:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
00043fc0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th00043b70:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
00043fd0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th00043b80:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00043fe0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t00043b90:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00043ff0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup00043ba0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
00044000:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo00043bb0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00044010:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00043bc0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00044020:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><00043bd0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
00044030:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t00043be0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
00044040:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate00043bf0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
00044050:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab00043c00:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
00044060:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta00043c10:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
00044070:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-00043c20:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
00044080:·206e·616d·653a·2047·6174·6865·7220·7468···name:·Gather·th 
00044090:·6520·7061·636b·6167·6520·6661·6374·730a··e·package·facts. 
000440a0:·2020·7061·636b·6167·655f·6661·6374·733a····package_facts: 
000440b0:·0a20·2020·206d·616e·6167·6572·3a20·6175··.····manager:·au 
000440c0:·746f·0a20·2074·6167·733a·0a20·202d·2043··to.··tags:.··-·C 
000440d0:·4a49·532d·352e·3130·2e31·2e33·0a20·202d··JIS-5.10.1.3.··- 
000440e0:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM- 
000440f0:·3628·6129·0a20·202d·2050·4349·2d44·5353··6(a).··-·PCI-DSS 
00044100:·2d52·6571·2d31·312e·350a·2020·2d20·5043··-Req-11.5.··-·PC 
00044110:·492d·4453·5376·342d·3131·2e35·2e32·0a20··I-DSSv4-11.5.2.· 
00044120:·202d·2065·6e61·626c·655f·7374·7261·7465···-·enable_strate 
00044130:·6779·0a20·202d·206c·6f77·5f63·6f6d·706c··gy.··-·low_compl 
00044140:·6578·6974·790a·2020·2d20·6c6f·775f·6469··exity.··-·low_di 
00044150:·7372·7570·7469·6f6e·0a20·202d·206d·6564··sruption.··-·med 
00044160:·6975·6d5f·7365·7665·7269·7479·0a20·202d··ium_severity.··- 
00044170:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede 
00044180:·640a·2020·2d20·7061·636b·6167·655f·6169··d.··-·package_ai 
00044190:·6465·5f69·6e73·7461·6c6c·6564·0a0a·2d20··de_installed..-· 
000441a0:·6e61·6d65·3a20·456e·7375·7265·2061·6964··name:·Ensure·aid 
000441b0:·6520·6973·2069·6e73·7461·6c6c·6564·0a20··e·is·installed.· 
000441c0:·2070·6163·6b61·6765·3a0a·2020·2020·6e61···package:.····na 
000441d0:·6d65·3a20·6169·6465·0a20·2020·2073·7461··me:·aide.····sta 
000441e0:·7465·3a20·7072·6573·656e·740a·2020·7768··te:·present.··wh00043c30:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 00043c40:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 00043c50:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 00043c60:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
 00043c70:·7175·6965·7420·2d71·206b·6572·6e65·6c20··quiet·-q·kernel·
 00043c80:·7c7c·2072·706d·202d·2d71·7569·6574·202d··||·rpm·--quiet·-
 00043c90:·7120·6b65·726e·656c·2d75·656b·3b20·7468··q·kernel-uek;·th
Max diff block lines reached; 812785/841517 bytes (96.59%) of diff not shown.
84.2 KB
html2text {}
    
Offset 682, 19 lines modifiedOffset 682, 14 lines modified
682 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3682 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
683 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)683 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
684 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3684 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
685 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5685 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
686 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199686 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
687 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79687 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
688 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2688 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
689 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
690 [[packages]] 
691 name·=·"aide" 
692 version·=·"*" 
693 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8689 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
694 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low690 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
695 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low691 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
696 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false692 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
697 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable693 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
698 #·Remediation·is·applicable·only·in·certain·platforms694 #·Remediation·is·applicable·only·in·certain·platforms
699 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then695 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 738, 33 lines modifiedOffset 733, 38 lines modified
738 ··-·PCI-DSSv4-11.5.2733 ··-·PCI-DSSv4-11.5.2
739 ··-·enable_strategy734 ··-·enable_strategy
740 ··-·low_complexity735 ··-·low_complexity
741 ··-·low_disruption736 ··-·low_disruption
742 ··-·medium_severity737 ··-·medium_severity
743 ··-·no_reboot_needed738 ··-·no_reboot_needed
744 ··-·package_aide_installed739 ··-·package_aide_installed
 740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 745 package·--add=aide
 746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 747 [[packages]]
 748 name·=·"aide"
 749 version·=·"*"
745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
746 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low751 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
747 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low752 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
748 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false753 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
749 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable754 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
750 include·install_aide755 include·install_aide
  
751 class·install_aide·{756 class·install_aide·{
752 ··package·{·'aide':757 ··package·{·'aide':
753 ····ensure·=>·'installed',758 ····ensure·=>·'installed',
754 ··}759 ··}
755 }760 }
756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
757 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
761 package·--add=aide 
762 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules761 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
763 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.762 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
764 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.763 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.
  
765 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.764 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
766 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*765 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 783, 31 lines modifiedOffset 783, 31 lines modified
783 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode783 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
784 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877784 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
785 ············_\x8i_\x8s_\x8m······1446785 ············_\x8i_\x8s_\x8m······1446
786 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1786 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
787 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12787 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
788 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1788 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
789 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176789 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
791 [customizations] 
792 fips·=·true 
793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
794 #·Remediation·is·applicable·only·in·certain·platforms791 #·Remediation·is·applicable·only·in·certain·platforms
795 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then792 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
796 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then793 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
797 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF794 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
798 kargs·=·["fips=1"]795 kargs·=·["fips=1"]
799 EOF796 EOF
800 fi797 fi
  
801 else798 else
802 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'799 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
803 fi800 fi
 801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 802 [customizations]
 803 fips·=·true
804 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*804 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
805 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:805 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
806 #·cat·/proc/sys/crypto/fips_enabled806 #·cat·/proc/sys/crypto/fips_enabled
807 1807 1
808 Warning: ·To·configure·Oracle·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Oracle·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.808 Warning: ·To·configure·Oracle·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Oracle·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
809 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.809 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
810 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.810 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 1008, 19 lines modifiedOffset 1008, 14 lines modified
1008 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351008 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1009 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861009 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1010 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1010 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1011 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11011 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1012 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251012 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1013 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331013 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1014 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21014 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1016 [[packages]] 
1017 name·=·"sudo" 
1018 version·=·"*" 
1019 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1020 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1016 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1021 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1017 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1022 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1018 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1023 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1019 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1024 #·Remediation·is·applicable·only·in·certain·platforms1020 #·Remediation·is·applicable·only·in·certain·platforms
1025 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1021 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1062, 33 lines modifiedOffset 1057, 38 lines modified
1062 ··-·PCI-DSSv4-2.2.61057 ··-·PCI-DSSv4-2.2.6
1063 ··-·enable_strategy1058 ··-·enable_strategy
1064 ··-·low_complexity1059 ··-·low_complexity
1065 ··-·low_disruption1060 ··-·low_disruption
1066 ··-·medium_severity1061 ··-·medium_severity
Max diff block lines reached; 77962/86161 bytes (90.48%) of diff not shown.
905 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-ism_o_top_secret.html
    
Offset 17321, 218 lines modifiedOffset 17321, 218 lines modified
00043a80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00043a80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
00043a90:·6964·6d35·3039·3722·2074·6162·696e·6465··idm5097"·tabinde00043a90:·6964·6d35·3039·3722·2074·6162·696e·6465··idm5097"·tabinde
00043aa0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt00043aa0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
00043ab0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande00043ab0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
00043ac0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=00043ac0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
00043ad0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev00043ad0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
00043ae0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R00043ae0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
00043af0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui00043af0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
00043b00:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
00043b10:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
00043b20:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00043b30:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00043b40:·7073·6522·2069·643d·2269·646d·3530·3937··pse"·id="idm5097 
00043b50:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
00043b60:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
00043b70:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
00043b80:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
00043b90:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00043ba0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00043bb0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00043bc0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00043bd0:·2d74·6172·6765·743d·2223·6964·6d35·3039··-target="#idm509 
00043be0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"· 
00043bf0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00043c00:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00043c10:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00043c20:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
00043c30:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
00043c40:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
00043c50:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00043c60:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00043c70:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00043c80:·2220·6964·3d22·6964·6d35·3039·3822·3e3c··"·id="idm5098">< 
00043c90:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
00043ca0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
00043cb0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
00043cc0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
00043cd0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
00043ce0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
00043cf0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00043d00:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
00043d10:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00043d20:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
00043d30:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
00043d40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00043d50:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
00043d60:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
00043d70:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
00043d80:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
00043d90:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
00043da0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
00043db0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
00043dc0:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
00043dd0:·6572·6e65·6c20·7c7c·2072·706d·202d·2d71··ernel·||·rpm·--q 
00043de0:·7569·6574·202d·7120·6b65·726e·656c·2d75··uiet·-q·kernel-u 
00043df0:·656b·3b20·7468·656e·0a0a·6966·2021·2072··ek;·then..if·!·r 
00043e00:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
00043e10:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
00043e20:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·" 
00043e30:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
00043e40:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
00043e50:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
00043e60:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
00043e70:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
00043e80:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
00043e90:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
00043ea0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00043eb0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00043ec0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
00043ed0:·612d·7461·7267·6574·3d22·2369·646d·3530··a-target="#idm50 
00043ee0:·3939·2220·7461·6269·6e64·6578·3d22·3022··99"·tabindex="0" 
00043ef0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00043f00:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00043f10:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00043f20:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
00043f30:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
00043f40:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
00043f50:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br00043b00:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
00043f60:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan00043b10:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
00043f70:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll00043b20:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
00043f80:·6170·7365·2220·6964·3d22·6964·6d35·3039··apse"·id="idm50900043b30:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
00043f90:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=00043b40:·3039·3722·3e3c·7461·626c·6520·636c·6173··097"><table·clas
00043fa0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str00043b50:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
00043fb0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde00043b60:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
00043fc0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden00043b70:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
00043fd0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com00043b80:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
00043fe0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td00043b90:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
00043ff0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t00043ba0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00044000:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption00043bb0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
00044010:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00044020:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
00044030:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
00044040:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
00044050:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
00044060:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
00044070:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
00044080:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam 
00044090:·653a·2047·6174·6865·7220·7468·6520·7061··e:·Gather·the·pa 
000440a0:·636b·6167·6520·6661·6374·730a·2020·7061··ckage·facts.··pa 
000440b0:·636b·6167·655f·6661·6374·733a·0a20·2020··ckage_facts:.··· 
000440c0:·206d·616e·6167·6572·3a20·6175·746f·0a20···manager:·auto.· 
000440d0:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS- 
000440e0:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS 
000440f0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
00044100:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
00044110:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
00044120:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
00044130:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
00044140:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
00044150:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
00044160:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
00044170:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
00044180:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
00044190:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
000441a0:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name 
000441b0:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is 
000441c0:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac 
000441d0:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:· 
000441e0:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:· 
000441f0:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:· 
00044200:·2822·6b65·726e·656c·2220·696e·2061·6e73··("kernel"·in·ans 
00044210:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
00044220:·6765·7320·6f72·2022·6b65·726e·656c·2d75··ges·or·"kernel-u 
00044230:·656b·2220·696e·2061·6e73·6962·6c65·5f66··ek"·in·ansible_f 
00044240:·6163·7473·2e70·6163·6b61·6765·7329·0a20··acts.packages).· 
00044250:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS- 
00044260:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS 
Max diff block lines reached; 812095/840827 bytes (96.58%) of diff not shown.
84.2 KB
html2text {}
    
Offset 682, 19 lines modifiedOffset 682, 14 lines modified
682 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3682 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
683 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)683 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
684 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3684 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
685 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5685 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
686 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199686 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
687 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79687 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
688 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2688 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
689 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
690 [[packages]] 
691 name·=·"aide" 
692 version·=·"*" 
693 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8689 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
694 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low690 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
695 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low691 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
696 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false692 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
697 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable693 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
698 #·Remediation·is·applicable·only·in·certain·platforms694 #·Remediation·is·applicable·only·in·certain·platforms
699 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then695 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 738, 33 lines modifiedOffset 733, 38 lines modified
738 ··-·PCI-DSSv4-11.5.2733 ··-·PCI-DSSv4-11.5.2
739 ··-·enable_strategy734 ··-·enable_strategy
740 ··-·low_complexity735 ··-·low_complexity
741 ··-·low_disruption736 ··-·low_disruption
742 ··-·medium_severity737 ··-·medium_severity
743 ··-·no_reboot_needed738 ··-·no_reboot_needed
744 ··-·package_aide_installed739 ··-·package_aide_installed
 740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 745 package·--add=aide
 746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 747 [[packages]]
 748 name·=·"aide"
 749 version·=·"*"
745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
746 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low751 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
747 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low752 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
748 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false753 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
749 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable754 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
750 include·install_aide755 include·install_aide
  
751 class·install_aide·{756 class·install_aide·{
752 ··package·{·'aide':757 ··package·{·'aide':
753 ····ensure·=>·'installed',758 ····ensure·=>·'installed',
754 ··}759 ··}
755 }760 }
756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
757 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
761 package·--add=aide 
762 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules761 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
763 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.762 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
764 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.763 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·10.
  
765 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.764 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
766 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*765 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 783, 31 lines modifiedOffset 783, 31 lines modified
783 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode783 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
784 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877784 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
785 ············_\x8i_\x8s_\x8m······1446785 ············_\x8i_\x8s_\x8m······1446
786 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1786 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
787 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12787 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
788 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1788 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
789 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176789 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
791 [customizations] 
792 fips·=·true 
793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8790 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
794 #·Remediation·is·applicable·only·in·certain·platforms791 #·Remediation·is·applicable·only·in·certain·platforms
795 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then792 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
796 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then793 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
797 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF794 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
798 kargs·=·["fips=1"]795 kargs·=·["fips=1"]
799 EOF796 EOF
800 fi797 fi
  
801 else798 else
802 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'799 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
803 fi800 fi
 801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 802 [customizations]
 803 fips·=·true
804 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*804 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
805 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:805 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
806 #·cat·/proc/sys/crypto/fips_enabled806 #·cat·/proc/sys/crypto/fips_enabled
807 1807 1
808 Warning: ·To·configure·Oracle·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Oracle·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.808 Warning: ·To·configure·Oracle·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Oracle·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
809 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.809 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
810 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.810 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 1008, 19 lines modifiedOffset 1008, 14 lines modified
1008 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351008 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1009 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861009 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1010 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1010 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1011 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11011 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1012 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251012 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1013 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331013 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1014 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21014 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1016 [[packages]] 
1017 name·=·"sudo" 
1018 version·=·"*" 
1019 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81015 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1020 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1016 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1021 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1017 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1022 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1018 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1023 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1019 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1024 #·Remediation·is·applicable·only·in·certain·platforms1020 #·Remediation·is·applicable·only·in·certain·platforms
1025 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1021 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1062, 33 lines modifiedOffset 1057, 38 lines modified
1062 ··-·PCI-DSSv4-2.2.61057 ··-·PCI-DSSv4-2.2.6
1063 ··-·enable_strategy1058 ··-·enable_strategy
1064 ··-·low_complexity1059 ··-·low_complexity
1065 ··-·low_disruption1060 ··-·low_disruption
1066 ··-·medium_severity1061 ··-·medium_severity
Max diff block lines reached; 77962/86161 bytes (90.48%) of diff not shown.
834 KB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-pci-dss.html
    
Offset 17309, 217 lines modifiedOffset 17309, 217 lines modified
000439c0:·7267·6574·3d22·2369·646d·3530·3937·2220··rget="#idm5097"·000439c0:·7267·6574·3d22·2369·646d·3530·3937·2220··rget="#idm5097"·
000439d0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol000439d0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
000439e0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-000439e0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
000439f0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"000439f0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
00043a00:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00043a00:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
00043a10:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00043a10:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
00043a20:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00043a20:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
00043a30:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
00043a40:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
00043a50:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
00043a60:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00043a70:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00043a80:·6964·6d35·3039·3722·3e3c·7072·653e·3c63··idm5097"><pre><c 
00043a90:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
00043aa0:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide". 
00043ab0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</00043a30:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 00043a40:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 00043a50:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 00043a60:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 00043a70:·643d·2269·646d·3530·3937·223e·3c74·6162··d="idm5097"><tab
 00043a80:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 00043a90:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00043aa0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00043ab0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00043ac0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00043ad0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00043ae0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00043af0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00043b00:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00043b10:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00043b20:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 00043b30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00043b40:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00043b50:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00043b60:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00043b70:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 00043b80:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 00043b90:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 00043ba0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 00043bb0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 00043bc0:·656c·207c·7c20·7270·6d20·2d2d·7175·6965··el·||·rpm·--quie
 00043bd0:·7420·2d71·206b·6572·6e65·6c2d·7565·6b3b··t·-q·kernel-uek;
 00043be0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 00043bf0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide
 00043c00:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf
 00043c10:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 00043c20:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.····
 00043c30:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 00043c40:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 00043c50:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 00043c60:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 00043c70:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
 00043c80:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00043c90:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 00043ca0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
 00043cb0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
 00043cc0:·6172·6765·743d·2223·6964·6d35·3039·3822··arget="#idm5098"
 00043cd0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
 00043ce0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
 00043cf0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
 00043d00:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
 00043d10:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
 00043d20:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00043d30:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 00043d40:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 00043d50:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00043d60:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00043d70:·6522·2069·643d·2269·646d·3530·3938·223e··e"·id="idm5098">
 00043d80:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 00043d90:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 00043da0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 00043db0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 00043dc0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 00043dd0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 00043de0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00043df0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 00043e00:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00043e10:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 00043e20:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 00043e30:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 00043e40:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 00043e50:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 00043e60:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 00043e70:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
 00043e80:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa
 00043e90:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa
 00043ea0:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma
 00043eb0:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta
 00043ec0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1
 00043ed0:·302e·312e·330a·2020·2d20·4e49·5354·2d38··0.1.3.··-·NIST-8
 00043ee0:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
 00043ef0:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11
 00043f00:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4
 00043f10:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab
 00043f20:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-·
 00043f30:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
 00043f40:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio
 00043f50:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev
 00043f60:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb
 00043f70:·6f6f·745f·6e65·6564·6564·0a20·202d·2070··oot_needed.··-·p
 00043f80:·6163·6b61·6765·5f61·6964·655f·696e·7374··ackage_aide_inst
 00043f90:·616c·6c65·640a·0a2d·206e·616d·653a·2045··alled..-·name:·E
 00043fa0:·6e73·7572·6520·6169·6465·2069·7320·696e··nsure·aide·is·in
 00043fb0:·7374·616c·6c65·640a·2020·7061·636b·6167··stalled.··packag
 00043fc0:·653a·0a20·2020·206e·616d·653a·2061·6964··e:.····name:·aid
 00043fd0:·650a·2020·2020·7374·6174·653a·2070·7265··e.····state:·pre
 00043fe0:·7365·6e74·0a20·2077·6865·6e3a·2028·226b··sent.··when:·("k
 00043ff0:·6572·6e65·6c22·2069·6e20·616e·7369·626c··ernel"·in·ansibl
 00044000:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
 00044010:·206f·7220·226b·6572·6e65·6c2d·7565·6b22···or·"kernel-uek"
 00044020:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 00044030:·732e·7061·636b·6167·6573·290a·2020·7461··s.packages).··ta
 00044040:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1
 00044050:·302e·312e·330a·2020·2d20·4e49·5354·2d38··0.1.3.··-·NIST-8
 00044060:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
 00044070:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11
 00044080:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4
 00044090:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab
 000440a0:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-·
 000440b0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
 000440c0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio
 000440d0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev
 000440e0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb
 000440f0:·6f6f·745f·6e65·6564·6564·0a20·202d·2070··oot_needed.··-·p
 00044100:·6163·6b61·6765·5f61·6964·655f·696e·7374··ackage_aide_inst
 00044110:·616c·6c65·640a·3c2f·636f·6465·3e3c·2f70··alled.</code></p
 00044120:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
Max diff block lines reached; 741573/770167 bytes (96.29%) of diff not shown.
81.8 KB
html2text {}
    
Offset 679, 19 lines modifiedOffset 679, 14 lines modified
679 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3679 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
680 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)680 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
681 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3681 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
682 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5682 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
683 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199683 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
684 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79684 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
685 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2685 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
686 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
687 [[packages]] 
688 name·=·"aide" 
689 version·=·"*" 
690 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8686 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
691 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low687 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
692 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low688 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
693 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false689 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
694 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable690 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
695 #·Remediation·is·applicable·only·in·certain·platforms691 #·Remediation·is·applicable·only·in·certain·platforms
696 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then692 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 735, 33 lines modifiedOffset 730, 38 lines modified
735 ··-·PCI-DSSv4-11.5.2730 ··-·PCI-DSSv4-11.5.2
736 ··-·enable_strategy731 ··-·enable_strategy
737 ··-·low_complexity732 ··-·low_complexity
738 ··-·low_disruption733 ··-·low_disruption
739 ··-·medium_severity734 ··-·medium_severity
740 ··-·no_reboot_needed735 ··-·no_reboot_needed
741 ··-·package_aide_installed736 ··-·package_aide_installed
 737 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 738 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 739 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 740 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 741 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 742 package·--add=aide
 743 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 744 [[packages]]
 745 name·=·"aide"
 746 version·=·"*"
742 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8747 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
743 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low748 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
744 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low749 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
745 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false750 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
746 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable751 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
747 include·install_aide752 include·install_aide
  
748 class·install_aide·{753 class·install_aide·{
749 ··package·{·'aide':754 ··package·{·'aide':
750 ····ensure·=>·'installed',755 ····ensure·=>·'installed',
751 ··}756 ··}
752 }757 }
753 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
754 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
755 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
756 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
757 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
758 package·--add=aide 
759 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*758 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
760 Run·the·following·command·to·generate·a·new·database:759 Run·the·following·command·to·generate·a·new·database:
761 $·sudo·/usr/sbin/aide·--init760 $·sudo·/usr/sbin/aide·--init
762 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:761 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
763 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz762 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
764 To·initiate·a·manual·check,·run·the·following·command:763 To·initiate·a·manual·check,·run·the·following·command:
765 $·sudo·/usr/sbin/aide·--check764 $·sudo·/usr/sbin/aide·--check
Offset 2814, 19 lines modifiedOffset 2814, 14 lines modified
2814 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022352814 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
2815 ············_\x8i_\x8s_\x8m·····1382,·1384,·13862815 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
2816 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)2816 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
2817 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.12817 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
2818 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001252818 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
2819 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R332819 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
2820 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.22820 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
2821 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2822 [[packages]] 
2823 name·=·"sudo" 
2824 version·=·"*" 
2825 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82821 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2826 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2822 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2827 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2823 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2828 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2824 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2829 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2825 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2830 #·Remediation·is·applicable·only·in·certain·platforms2826 #·Remediation·is·applicable·only·in·certain·platforms
2831 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then2827 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 2868, 33 lines modifiedOffset 2863, 38 lines modified
2868 ··-·PCI-DSSv4-2.2.62863 ··-·PCI-DSSv4-2.2.6
2869 ··-·enable_strategy2864 ··-·enable_strategy
2870 ··-·low_complexity2865 ··-·low_complexity
2871 ··-·low_disruption2866 ··-·low_disruption
2872 ··-·medium_severity2867 ··-·medium_severity
2873 ··-·no_reboot_needed2868 ··-·no_reboot_needed
2874 ··-·package_sudo_installed2869 ··-·package_sudo_installed
 2870 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2871 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2872 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2873 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2874 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2875 package·--add=sudo
 2876 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2877 [[packages]]
 2878 name·=·"sudo"
 2879 version·=·"*"
2875 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82880 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2876 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2881 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2877 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2882 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2878 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2883 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2879 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2884 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2880 include·install_sudo2885 include·install_sudo
  
2881 class·install_sudo·{2886 class·install_sudo·{
2882 ··package·{·'sudo':2887 ··package·{·'sudo':
2883 ····ensure·=>·'installed',2888 ····ensure·=>·'installed',
2884 ··}2889 ··}
2885 }2890 }
2886 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2887 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2888 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2889 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2890 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2891 package·--add=sudo 
2892 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2891 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2893 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.2892 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
2894 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.2893 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.
Max diff block lines reached; 77928/83739 bytes (93.06%) of diff not shown.
1.64 MB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-stig.html
    
Offset 15070, 218 lines modifiedOffset 15070, 218 lines modified
0003add0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003add0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003ade0:·2223·6964·6d35·3039·3722·2074·6162·696e··"#idm5097"·tabin0003ade0:·2223·6964·6d35·3039·3722·2074·6162·696e··"#idm5097"·tabin
0003adf0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003adf0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003ae00:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003ae00:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003ae10:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003ae10:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003ae20:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003ae20:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003ae30:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003ae30:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003ae40:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003ae40:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003ae50:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
0003ae50:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003ae60:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003ae70:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003ae80:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003ae90:·6c61·7073·6522·2069·643d·2269·646d·3530··lapse"·id="idm50 
0003aea0:·3937·223e·3c70·7265·3e3c·636f·6465·3e0a··97"><pre><code>. 
0003aeb0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003aec0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003aed0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003aee0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003aef0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003af00:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003af10:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003af20:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5 
0003af30:·3039·3822·2074·6162·696e·6465·783d·2230··098"·tabindex="0 
0003af40:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003af50:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003af60:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003af70:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003af80:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003af90:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003afa0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003afb0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003afc0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003afd0:·7365·2220·6964·3d22·6964·6d35·3039·3822··se"·id="idm5098" 
0003afe0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003aff0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b000:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b010:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b020:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b030:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b040:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b050:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b060:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b070:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b080:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b090:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b0a0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b0b0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b0c0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b0d0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003b0e0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003b0f0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003b100:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003b110:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
0003b120:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·- 
0003b130:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel 
0003b140:·2d75·656b·3b20·7468·656e·0a0a·6966·2021··-uek;·then..if·! 
0003b150:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003b160:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003b170:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y 
0003b180:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003b190:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b1a0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b1b0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b1c0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b1d0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b1e0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b1f0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b200:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b210:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b220:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b230:·3530·3939·2220·7461·6269·6e64·6578·3d22··5099"·tabindex=" 
0003b240:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b250:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b260:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b270:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b280:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b290:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003b2a0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b2b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003ae60:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b2c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b2d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003b2e0:·3039·3922·3e3c·7461·626c·6520·636c·6173··099"><table·clas 
0003b2f0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b300:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b310:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b320:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b330:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b340:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b350:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b360:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b370:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b380:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b390:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b3a0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b3b0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b3c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b3d0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n 
0003b3e0:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
0003b3f0:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
0003b400:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
0003b410:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto 
0003b420:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI 
0003b430:·532d·352e·3130·2e31·2e33·0a20·202d·204e··S-5.10.1.3.··-·N 
0003b440:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003b450:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003b460:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003b470:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003b480:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003b490:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003b4a0:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003b4b0:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
0003b4c0:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n 
0003b4d0:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed. 
0003b4e0:·2020·2d20·7061·636b·6167·655f·6169·6465····-·package_aide 
0003b4f0:·5f69·6e73·7461·6c6c·6564·0a0a·2d20·6e61··_installed..-·na 
0003b500:·6d65·3a20·456e·7375·7265·2061·6964·6520··me:·Ensure·aide· 
0003b510:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p 
0003b520:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name 
0003b530:·3a20·6169·6465·0a20·2020·2073·7461·7465··:·aide.····state 
0003b540:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when 
0003b550:·3a20·2822·6b65·726e·656c·2220·696e·2061··:·("kernel"·in·a 
0003b560:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
0003b570:·6b61·6765·7320·6f72·2022·6b65·726e·656c··kages·or·"kernel 
0003b580:·2d75·656b·2220·696e·2061·6e73·6962·6c65··-uek"·in·ansible 
0003b590:·5f66·6163·7473·2e70·6163·6b61·6765·7329··_facts.packages) 
0003b5a0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI 
Max diff block lines reached; 1513358/1542090 bytes (98.14%) of diff not shown.
176 KB
html2text {}
    
Offset 100, 19 lines modifiedOffset 100, 14 lines modified
100 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3100 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
101 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)101 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
102 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3102 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
103 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5103 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
104 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199104 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
105 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79105 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
107 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
108 [[packages]] 
109 name·=·"aide" 
110 version·=·"*" 
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8107 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low108 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low109 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false110 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable111 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
116 #·Remediation·is·applicable·only·in·certain·platforms112 #·Remediation·is·applicable·only·in·certain·platforms
117 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then113 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 156, 33 lines modifiedOffset 151, 38 lines modified
156 ··-·PCI-DSSv4-11.5.2151 ··-·PCI-DSSv4-11.5.2
157 ··-·enable_strategy152 ··-·enable_strategy
158 ··-·low_complexity153 ··-·low_complexity
159 ··-·low_disruption154 ··-·low_disruption
160 ··-·medium_severity155 ··-·medium_severity
161 ··-·no_reboot_needed156 ··-·no_reboot_needed
162 ··-·package_aide_installed157 ··-·package_aide_installed
 158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 163 package·--add=aide
 164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 165 [[packages]]
 166 name·=·"aide"
 167 version·=·"*"
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
168 include·install_aide173 include·install_aide
  
169 class·install_aide·{174 class·install_aide·{
170 ··package·{·'aide':175 ··package·{·'aide':
171 ····ensure·=>·'installed',176 ····ensure·=>·'installed',
172 ··}177 ··}
173 }178 }
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
179 package·--add=aide 
180 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
181 Run·the·following·command·to·generate·a·new·database:180 Run·the·following·command·to·generate·a·new·database:
182 $·sudo·/usr/sbin/aide·--init181 $·sudo·/usr/sbin/aide·--init
183 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
184 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz183 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
185 To·initiate·a·manual·check,·run·the·following·command:184 To·initiate·a·manual·check,·run·the·following·command:
186 $·sudo·/usr/sbin/aide·--check185 $·sudo·/usr/sbin/aide·--check
Offset 1920, 31 lines modifiedOffset 1920, 31 lines modified
1920 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode1920 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
1921 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008771921 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
1922 ············_\x8i_\x8s_\x8m······14461922 ············_\x8i_\x8s_\x8m······1446
1923 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11923 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1924 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121924 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1925 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11925 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1926 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761926 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1927 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1928 [customizations] 
1929 fips·=·true 
1930 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81927 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1931 #·Remediation·is·applicable·only·in·certain·platforms1928 #·Remediation·is·applicable·only·in·certain·platforms
1932 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then1929 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
1933 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1930 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1934 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1931 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1935 kargs·=·["fips=1"]1932 kargs·=·["fips=1"]
1936 EOF1933 EOF
1937 fi1934 fi
  
1938 else1935 else
1939 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1936 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1940 fi1937 fi
 1938 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1939 [customizations]
 1940 fips·=·true
1941 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1941 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1942 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:1942 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:
1943 fips-mode-setup·--enable1943 fips-mode-setup·--enable
1944 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1944 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1945 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1945 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1946 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1946 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1947 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1947 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 1981, 19 lines modifiedOffset 1981, 14 lines modified
1981 $·sudo·dnf·install·crypto-policies1981 $·sudo·dnf·install·crypto-policies
1982 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.1982 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
1983 Severity: ··medium1983 Severity: ··medium
1984 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed1984 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
1985 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-0031231985 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
1986 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.11986 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
1987 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001741987 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
1988 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1989 [[packages]] 
1990 name·=·"crypto-policies" 
1991 version·=·"*" 
1992 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81988 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1993 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1989 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1994 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1990 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1995 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1991 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1996 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1992 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1997 if·!·rpm·-q·--quiet·"crypto-policies"·;·then1993 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 2011, 33 lines modifiedOffset 2006, 38 lines modified
2011 ··tags:2006 ··tags:
2012 ··-·enable_strategy2007 ··-·enable_strategy
2013 ··-·low_complexity2008 ··-·low_complexity
2014 ··-·low_disruption2009 ··-·low_disruption
2015 ··-·medium_severity2010 ··-·medium_severity
Max diff block lines reached; 171935/179902 bytes (95.57%) of diff not shown.
1.63 MB
./usr/share/doc/ssg-nondebian/ssg-ol10-guide-stig_gui.html
    
Offset 15065, 218 lines modifiedOffset 15065, 218 lines modified
0003ad80:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003ad80:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003ad90:·3d22·2369·646d·3530·3937·2220·7461·6269··="#idm5097"·tabi0003ad90:·3d22·2369·646d·3530·3937·2220·7461·6269··="#idm5097"·tabi
0003ada0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003ada0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003adb0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003adb0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003adc0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003adc0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003add0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003add0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003ade0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003ade0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003adf0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003adf0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003ae00:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
0003ae00:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003ae10:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003ae20:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003ae30:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003ae40:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003ae50:·3039·3722·3e3c·7072·653e·3c63·6f64·653e··097"><pre><code> 
0003ae60:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003ae70:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003ae80:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003ae90:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003aea0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003aeb0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003aec0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003aed0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003aee0:·3530·3938·2220·7461·6269·6e64·6578·3d22··5098"·tabindex=" 
0003aef0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003af00:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003af10:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003af20:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003af30:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003af40:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003af50:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003af60:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003af70:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003af80:·7073·6522·2069·643d·2269·646d·3530·3938··pse"·id="idm5098 
0003af90:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003afa0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003afb0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003afc0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003afd0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003afe0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003aff0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b000:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b010:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b020:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b030:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003b040:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003b050:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003b060:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003b070:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b080:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003b090:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b0a0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b0b0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b0c0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003b0d0:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm· 
0003b0e0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003b0f0:·6c2d·7565·6b3b·2074·6865·6e0a·0a69·6620··l-uek;·then..if· 
0003b100:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003b110:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003b120:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
0003b130:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003b140:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b150:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b160:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b170:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b180:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b190:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b1a0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b1b0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b1c0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b1d0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b1e0:·6d35·3039·3922·2074·6162·696e·6465·783d··m5099"·tabindex= 
0003b1f0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b200:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b210:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b220:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b230:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b240:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b250:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b260:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003ae10:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b270:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003ae20:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b280:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003ae30:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b290:·3530·3939·223e·3c74·6162·6c65·2063·6c61··5099"><table·cla0003ae40:·646d·3530·3937·223e·3c74·6162·6c65·2063··dm5097"><table·c
0003b2a0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003ae50:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b2b0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003ae60:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b2c0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b2d0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b2e0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b2f0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b300:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b310:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b320:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b330:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b340:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b350:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b360:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b370:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b380:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
0003b390:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
0003b3a0:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
0003b3b0:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
0003b3c0:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
0003b3d0:·6f0a·2020·7461·6773·3a0a·2020·2d20·434a··o.··tags:.··-·CJ 
0003b3e0:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003b3f0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003b400:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003b410:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003b420:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003b430:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003b440:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003b450:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003b460:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003b470:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003b480:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003b490:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003b4a0:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
0003b4b0:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
0003b4c0:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
0003b4d0:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
0003b4e0:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
0003b4f0:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe 
0003b500:·6e3a·2028·226b·6572·6e65·6c22·2069·6e20··n:·("kernel"·in· 
0003b510:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
0003b520:·636b·6167·6573·206f·7220·226b·6572·6e65··ckages·or·"kerne 
0003b530:·6c2d·7565·6b22·2069·6e20·616e·7369·626c··l-uek"·in·ansibl 
0003b540:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages 
0003b550:·290a·2020·7461·6773·3a0a·2020·2d20·434a··).··tags:.··-·CJ 
Max diff block lines reached; 1503877/1532609 bytes (98.13%) of diff not shown.
174 KB
html2text {}
    
Offset 99, 19 lines modifiedOffset 99, 14 lines modified
99 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.399 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
100 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)100 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
104 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79104 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
105 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2105 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
107 [[packages]] 
108 name·=·"aide" 
109 version·=·"*" 
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
115 #·Remediation·is·applicable·only·in·certain·platforms111 #·Remediation·is·applicable·only·in·certain·platforms
116 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then112 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 155, 33 lines modifiedOffset 150, 38 lines modified
155 ··-·PCI-DSSv4-11.5.2150 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy151 ··-·enable_strategy
157 ··-·low_complexity152 ··-·low_complexity
158 ··-·low_disruption153 ··-·low_disruption
159 ··-·medium_severity154 ··-·medium_severity
160 ··-·no_reboot_needed155 ··-·no_reboot_needed
161 ··-·package_aide_installed156 ··-·package_aide_installed
 157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 162 package·--add=aide
 163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 164 [[packages]]
 165 name·=·"aide"
 166 version·=·"*"
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
167 include·install_aide172 include·install_aide
  
168 class·install_aide·{173 class·install_aide·{
169 ··package·{·'aide':174 ··package·{·'aide':
170 ····ensure·=>·'installed',175 ····ensure·=>·'installed',
171 ··}176 ··}
172 }177 }
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
178 package·--add=aide 
179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
180 Run·the·following·command·to·generate·a·new·database:179 Run·the·following·command·to·generate·a·new·database:
181 $·sudo·/usr/sbin/aide·--init180 $·sudo·/usr/sbin/aide·--init
182 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:181 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
183 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz182 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
184 To·initiate·a·manual·check,·run·the·following·command:183 To·initiate·a·manual·check,·run·the·following·command:
185 $·sudo·/usr/sbin/aide·--check184 $·sudo·/usr/sbin/aide·--check
Offset 1919, 31 lines modifiedOffset 1919, 31 lines modified
1919 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode1919 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
1920 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008771920 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
1921 ············_\x8i_\x8s_\x8m······14461921 ············_\x8i_\x8s_\x8m······1446
1922 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11922 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1923 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121923 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1924 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11924 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1925 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761925 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1926 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1927 [customizations] 
1928 fips·=·true 
1929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81926 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1930 #·Remediation·is·applicable·only·in·certain·platforms1927 #·Remediation·is·applicable·only·in·certain·platforms
1931 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then1928 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
1932 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1929 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1933 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1930 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1934 kargs·=·["fips=1"]1931 kargs·=·["fips=1"]
1935 EOF1932 EOF
1936 fi1933 fi
  
1937 else1934 else
1938 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1935 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1939 fi1936 fi
 1937 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1938 [customizations]
 1939 fips·=·true
1940 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1940 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1941 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:1941 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:
1942 fips-mode-setup·--enable1942 fips-mode-setup·--enable
1943 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1943 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1944 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1944 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1945 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1945 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1946 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1946 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 1980, 19 lines modifiedOffset 1980, 14 lines modified
1980 $·sudo·dnf·install·crypto-policies1980 $·sudo·dnf·install·crypto-policies
1981 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.1981 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
1982 Severity: ··medium1982 Severity: ··medium
1983 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed1983 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
1984 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-0031231984 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
1985 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.11985 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
1986 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001741986 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
1987 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1988 [[packages]] 
1989 name·=·"crypto-policies" 
1990 version·=·"*" 
1991 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81987 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1992 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1988 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1993 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1989 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1994 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1990 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1995 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1991 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1996 if·!·rpm·-q·--quiet·"crypto-policies"·;·then1992 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 2010, 33 lines modifiedOffset 2005, 38 lines modified
2010 ··tags:2005 ··tags:
2011 ··-·enable_strategy2006 ··-·enable_strategy
2012 ··-·low_complexity2007 ··-·low_complexity
2013 ··-·low_disruption2008 ··-·low_disruption
2014 ··-·medium_severity2009 ··-·medium_severity
Max diff block lines reached; 169706/177671 bytes (95.52%) of diff not shown.
935 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_enhanced.html
    
Offset 15059, 221 lines modifiedOffset 15059, 221 lines modified
0003ad20:·6765·743d·2223·6964·6d35·3635·3122·2074··get="#idm5651"·t0003ad20:·6765·743d·2223·6964·6d35·3635·3122·2074··get="#idm5651"·t
0003ad30:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003ad30:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003ad40:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003ad40:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003ad50:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003ad50:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003ad60:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003ad60:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003ad70:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003ad70:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003ad80:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003ad80:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003ad90:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
0003ad90:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003ada0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003adb0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003adc0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003add0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003ade0:·646d·3536·3531·223e·3c70·7265·3e3c·636f··dm5651"><pre><co 
0003adf0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003ae00:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003ae10:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003ae20:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003ae30:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003ae40:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003ae50:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003ae60:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003ae70:·6964·6d35·3635·3222·2074·6162·696e·6465··idm5652"·tabinde 
0003ae80:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003ae90:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003aea0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003aeb0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003aec0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003aed0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003aee0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003aef0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003af00:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003af10:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003af20:·3635·3222·3e3c·7461·626c·6520·636c·6173··652"><table·clas 
0003af30:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003af40:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003af50:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003af60:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003af70:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003af80:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003af90:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003afa0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003afb0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003afc0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003afd0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003afe0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003aff0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b000:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b010:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b020:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b030:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b040:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b050:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003b060:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r 
0003b070:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003b080:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then.. 
0003b090:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b0a0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b0b0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal 
0003b0c0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b0d0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b0e0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b0f0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b100:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b110:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b120:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b130:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b140:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b150:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b160:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b170:·2369·646d·3536·3533·2220·7461·6269·6e64··#idm5653"·tabind 
0003b180:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b190:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b1a0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b1b0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b1c0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b1d0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
0003b1e0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b1f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003ada0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b200:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003adb0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b210:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003adc0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b220:·6964·6d35·3635·3322·3e3c·7461·626c·6520··idm5653"><table·0003add0:·3d22·6964·6d35·3635·3122·3e3c·7461·626c··="idm5651"><tabl
0003b230:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003ade0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003b240:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003adf0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003b250:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003ae00:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003b260:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003ae10:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003b270:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003ae20:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003b280:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003ae30:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b290:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003ae40:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b2a0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003ae50:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b2b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003ae60:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b2c0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003ae70:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003b2d0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003ae80:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003b2e0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003ae90:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003b2f0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003aea0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003b300:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003aeb0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003b310:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003aec0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003b320:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather· 
0003b330:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact 
0003b340:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact 
0003b350:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:· 
0003b360:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··- 
0003b370:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003b380:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL0 
0003b390:·372d·3030·2d30·3230·3032·390a·2020·2d20··7-00-020029.··-· 
0003b3a0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003b3b0:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003b3c0:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003b3d0:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003b3e0:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003b3f0:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003b400:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003b410:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003b420:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003b430:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003b440:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003b450:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
0003b460:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
0003b470:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
0003b480:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
0003b490:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
0003b4a0:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe0003aed0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003aee0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003aef0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003af00:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm·
 0003af10:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 0003af20:·6c20·7c7c·2072·706d·202d·2d71·7569·6574··l·||·rpm·--quiet
Max diff block lines reached; 861795/890941 bytes (96.73%) of diff not shown.
64.4 KB
html2text {}
    
Offset 116, 19 lines modifiedOffset 116, 14 lines modified
116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029119 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
120 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79120 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule122 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
124 [[packages]] 
125 name·=·"aide" 
126 version·=·"*" 
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
132 #·Remediation·is·applicable·only·in·certain·platforms128 #·Remediation·is·applicable·only·in·certain·platforms
133 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then129 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 174, 33 lines modifiedOffset 169, 38 lines modified
174 ··-·PCI-DSSv4-11.5.2169 ··-·PCI-DSSv4-11.5.2
175 ··-·enable_strategy170 ··-·enable_strategy
176 ··-·low_complexity171 ··-·low_complexity
177 ··-·low_disruption172 ··-·low_disruption
178 ··-·medium_severity173 ··-·medium_severity
179 ··-·no_reboot_needed174 ··-·no_reboot_needed
180 ··-·package_aide_installed175 ··-·package_aide_installed
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 181 package·--add=aide
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
186 include·install_aide191 include·install_aide
  
187 class·install_aide·{192 class·install_aide·{
188 ··package·{·'aide':193 ··package·{·'aide':
189 ····ensure·=>·'installed',194 ····ensure·=>·'installed',
190 ··}195 ··}
191 }196 }
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·--add=aide 
198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
199 Run·the·following·command·to·generate·a·new·database:198 Run·the·following·command·to·generate·a·new·database:
200 $·sudo·/usr/sbin/aide·--init199 $·sudo·/usr/sbin/aide·--init
201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
202 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these201 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
203 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their202 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
204 integrity.·The·newly-generated·database·can·be·installed·as·follows:203 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 787, 19 lines modifiedOffset 787, 14 lines modified
787 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235787 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
788 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386788 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
789 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)789 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
790 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1790 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
791 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125791 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
792 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33792 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
793 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2793 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
794 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
795 [[packages]] 
796 name·=·"sudo" 
797 version·=·"*" 
798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8794 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
799 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low795 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
800 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low796 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
801 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false797 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
802 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable798 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
803 #·Remediation·is·applicable·only·in·certain·platforms799 #·Remediation·is·applicable·only·in·certain·platforms
804 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then800 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 841, 33 lines modifiedOffset 836, 38 lines modified
841 ··-·PCI-DSSv4-2.2.6836 ··-·PCI-DSSv4-2.2.6
842 ··-·enable_strategy837 ··-·enable_strategy
843 ··-·low_complexity838 ··-·low_complexity
844 ··-·low_disruption839 ··-·low_disruption
845 ··-·medium_severity840 ··-·medium_severity
846 ··-·no_reboot_needed841 ··-·no_reboot_needed
847 ··-·package_sudo_installed842 ··-·package_sudo_installed
 843 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 844 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 845 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 846 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 847 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 848 package·--add=sudo
 849 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 850 [[packages]]
 851 name·=·"sudo"
 852 version·=·"*"
848 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8853 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
849 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low854 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
850 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low855 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
851 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false856 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
852 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable857 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
853 include·install_sudo858 include·install_sudo
  
854 class·install_sudo·{859 class·install_sudo·{
855 ··package·{·'sudo':860 ··package·{·'sudo':
856 ····ensure·=>·'installed',861 ····ensure·=>·'installed',
857 ··}862 ··}
858 }863 }
859 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
860 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
861 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
862 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
863 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
864 package·--add=sudo 
865 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*864 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
866 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:865 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
867 $·sudo·chgrp·root·/etc/sudoers.d866 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 60713/65932 bytes (92.08%) of diff not shown.
969 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_high.html
    
Offset 15065, 221 lines modifiedOffset 15065, 221 lines modified
0003ad80:·7461·7267·6574·3d22·2369·646d·3536·3531··target="#idm56510003ad80:·7461·7267·6574·3d22·2369·646d·3536·3531··target="#idm5651
0003ad90:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003ad90:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003ada0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003ada0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003adb0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003adb0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003adc0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003adc0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003add0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003add0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003ade0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003ade0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003adf0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
0003adf0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003ae00:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003ae10:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003ae20:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003ae30:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003ae40:·3d22·6964·6d35·3635·3122·3e3c·7072·653e··="idm5651"><pre> 
0003ae50:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003ae60:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003ae70:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003ae80:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003ae90:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003aea0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003aeb0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003aec0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003aed0:·3d22·2369·646d·3536·3532·2220·7461·6269··="#idm5652"·tabi 
0003aee0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003aef0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003af00:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003af10:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003af20:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003af30:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003af40:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003af50:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003af60:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003af70:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003af80:·646d·3536·3532·223e·3c74·6162·6c65·2063··dm5652"><table·c 
0003af90:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003afa0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003afb0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003afc0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003afd0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003afe0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003aff0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b000:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b010:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b020:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b030:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b040:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b050:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b060:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b070:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b080:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003b090:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003b0a0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003b0b0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q 
0003b0c0:·7569·6574·202d·7120·6b65·726e·656c·207c··uiet·-q·kernel·| 
0003b0d0:·7c20·7270·6d20·2d2d·7175·6965·7420·2d71··|·rpm·--quiet·-q 
0003b0e0:·206b·6572·6e65·6c2d·7565·6b3b·2074·6865···kernel-uek;·the 
0003b0f0:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003b100:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003b110:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins 
0003b120:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003b130:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003b140:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b150:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b160:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b170:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b180:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b190:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b1a0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b1b0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b1c0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b1d0:·743d·2223·6964·6d35·3635·3322·2074·6162··t="#idm5653"·tab 
0003b1e0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b1f0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b200:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b210:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b220:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b230:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b240:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b250:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003ae00:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b260:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003ae10:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b270:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003ae20:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b280:·643d·2269·646d·3536·3533·223e·3c74·6162··d="idm5653"><tab0003ae30:·2069·643d·2269·646d·3536·3531·223e·3c74···id="idm5651"><t
0003b290:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003ae40:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b2a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003ae50:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b2b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003ae60:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b2c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003ae70:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b2d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003ae80:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b2e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003ae90:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003b2f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003aea0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b300:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003aeb0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b310:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003aec0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b320:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003aed0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b330:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003aee0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b340:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003aef0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b350:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003af00:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b360:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003af10:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003b370:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003af20:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003b380:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003b390:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f0003af30:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 0003af40:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 0003af50:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 0003af60:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 0003af70:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 0003af80:·726e·656c·207c·7c20·7270·6d20·2d2d·7175··rnel·||·rpm·--qu
 0003af90:·6965·7420·2d71·206b·6572·6e65·6c2d·7565··iet·-q·kernel-ue
 0003afa0:·6b3b·2074·6865·6e0a·0a69·6620·2120·7270··k;·then..if·!·rp
 0003afb0:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 0003afc0:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y
 0003afd0:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a
 0003afe0:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 0003aff0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003b000:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003b010:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003b020:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 0003b030:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 0003b040:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003b050:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003b060:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003b070:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003b080:·2d74·6172·6765·743d·2223·6964·6d35·3635··-target="#idm565
 0003b090:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
 0003b0a0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0003b0b0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0003b0c0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0003b0d0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0003b0e0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b0f0:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
Max diff block lines reached; 891480/920626 bytes (96.83%) of diff not shown.
69.8 KB
html2text {}
    
Offset 117, 19 lines modifiedOffset 117, 14 lines modified
117 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3117 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
119 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199119 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
120 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029120 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
121 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79121 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
123 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule123 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
125 [[packages]] 
126 name·=·"aide" 
127 version·=·"*" 
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
133 #·Remediation·is·applicable·only·in·certain·platforms129 #·Remediation·is·applicable·only·in·certain·platforms
134 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then130 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 175, 33 lines modifiedOffset 170, 38 lines modified
175 ··-·PCI-DSSv4-11.5.2170 ··-·PCI-DSSv4-11.5.2
176 ··-·enable_strategy171 ··-·enable_strategy
177 ··-·low_complexity172 ··-·low_complexity
178 ··-·low_disruption173 ··-·low_disruption
179 ··-·medium_severity174 ··-·medium_severity
180 ··-·no_reboot_needed175 ··-·no_reboot_needed
181 ··-·package_aide_installed176 ··-·package_aide_installed
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·--add=aide
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 184 [[packages]]
 185 name·=·"aide"
 186 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
187 include·install_aide192 include·install_aide
  
188 class·install_aide·{193 class·install_aide·{
189 ··package·{·'aide':194 ··package·{·'aide':
190 ····ensure·=>·'installed',195 ····ensure·=>·'installed',
191 ··}196 ··}
192 }197 }
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
198 package·--add=aide 
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
200 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
201 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
203 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these202 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
204 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their203 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
205 integrity.·The·newly-generated·database·can·be·installed·as·follows:204 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 1348, 19 lines modifiedOffset 1348, 14 lines modified
1348 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351348 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1349 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861349 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1350 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1350 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1351 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11351 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1352 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251352 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1353 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331353 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1354 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21354 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1355 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1356 [[packages]] 
1357 name·=·"sudo" 
1358 version·=·"*" 
1359 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81355 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1360 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1356 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1361 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1357 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1362 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1358 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1363 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1359 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1364 #·Remediation·is·applicable·only·in·certain·platforms1360 #·Remediation·is·applicable·only·in·certain·platforms
1365 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1361 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1402, 33 lines modifiedOffset 1397, 38 lines modified
1402 ··-·PCI-DSSv4-2.2.61397 ··-·PCI-DSSv4-2.2.6
1403 ··-·enable_strategy1398 ··-·enable_strategy
1404 ··-·low_complexity1399 ··-·low_complexity
1405 ··-·low_disruption1400 ··-·low_disruption
1406 ··-·medium_severity1401 ··-·medium_severity
1407 ··-·no_reboot_needed1402 ··-·no_reboot_needed
1408 ··-·package_sudo_installed1403 ··-·package_sudo_installed
 1404 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1405 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1406 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1407 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1408 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1409 package·--add=sudo
 1410 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1411 [[packages]]
 1412 name·=·"sudo"
 1413 version·=·"*"
1409 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81414 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1410 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1415 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1411 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1416 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1412 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1417 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1413 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1418 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1414 include·install_sudo1419 include·install_sudo
  
1415 class·install_sudo·{1420 class·install_sudo·{
1416 ··package·{·'sudo':1421 ··package·{·'sudo':
1417 ····ensure·=>·'installed',1422 ····ensure·=>·'installed',
1418 ··}1423 ··}
1419 }1424 }
1420 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1421 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1422 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1423 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1424 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1425 package·--add=sudo 
1426 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1425 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1427 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:1426 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
1428 $·sudo·chgrp·root·/etc/sudoers.d1427 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 66184/71407 bytes (92.69%) of diff not shown.
764 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_intermediary.html
    
Offset 15050, 221 lines modifiedOffset 15050, 221 lines modified
0003ac90:·7267·6574·3d22·2369·646d·3536·3531·2220··rget="#idm5651"·0003ac90:·7267·6574·3d22·2369·646d·3536·3531·2220··rget="#idm5651"·
0003aca0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003aca0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003acb0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003acb0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003acc0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003acc0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003acd0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003acd0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003ace0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003ace0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003acf0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003acf0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003ad00:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
0003ad00:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0003ad10:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
0003ad20:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003ad30:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003ad40:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003ad50:·6964·6d35·3635·3122·3e3c·7072·653e·3c63··idm5651"><pre><c 
0003ad60:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
0003ad70:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide". 
0003ad80:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
0003ad90:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003ada0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003adb0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003adc0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003add0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003ade0:·2369·646d·3536·3532·2220·7461·6269·6e64··#idm5652"·tabind 
0003adf0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003ae00:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003ae10:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003ae20:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003ae30:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003ae40:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003ae50:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003ae60:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003ae70:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003ae80:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003ae90:·3536·3532·223e·3c74·6162·6c65·2063·6c61··5652"><table·cla 
0003aea0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003aeb0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003aec0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003aed0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003aee0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003aef0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003af00:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003af10:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003af20:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003af30:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003af40:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003af50:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003af60:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003af70:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003af80:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003af90:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003afa0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003afb0:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003afc0:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui 
0003afd0:·6574·202d·7120·6b65·726e·656c·207c·7c20··et·-q·kernel·||· 
0003afe0:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003aff0:·6572·6e65·6c2d·7565·6b3b·2074·6865·6e0a··ernel-uek;·then. 
0003b000:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q 
0003b010:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th 
0003b020:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta 
0003b030:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi. 
0003b040:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b050:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b060:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b070:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b080:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b090:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b0a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b0b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b0c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b0d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b0e0:·2223·6964·6d35·3635·3322·2074·6162·696e··"#idm5653"·tabin 
0003b0f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b100:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b110:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b120:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b130:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b140:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003b150:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003b160:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003ad10:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b170:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003ad20:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b180:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003ad30:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b190:·2269·646d·3536·3533·223e·3c74·6162·6c65··"idm5653"><table0003ad40:·643d·2269·646d·3536·3531·223e·3c74·6162··d="idm5651"><tab
0003b1a0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003ad50:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b1b0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003ad60:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b1c0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003ad70:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003b1d0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003ad80:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003b1e0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003ad90:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003b1f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003ada0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b200:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003adb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003b210:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003adc0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003b220:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003add0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b230:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003ade0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b240:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003adf0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b250:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003ae00:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b260:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003ae10:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b270:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003ae20:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003b280:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003ae30:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003b290:·653e·2d20·6e61·6d65·3a20·4761·7468·6572··e>-·name:·Gather 
0003b2a0:·2074·6865·2070·6163·6b61·6765·2066·6163···the·package·fac 
0003b2b0:·7473·0a20·2070·6163·6b61·6765·5f66·6163··ts.··package_fac 
0003b2c0:·7473·3a0a·2020·2020·6d61·6e61·6765·723a··ts:.····manager: 
0003b2d0:·2061·7574·6f0a·2020·7461·6773·3a0a·2020···auto.··tags:.·· 
0003b2e0:·2d20·434a·4953·2d35·2e31·302e·312e·330a··-·CJIS-5.10.1.3. 
0003b2f0:·2020·2d20·4449·5341·2d53·5449·472d·4f4c····-·DISA-STIG-OL 
0003b300:·3037·2d30·302d·3032·3030·3239·0a20·202d··07-00-020029.··- 
0003b310:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM- 
0003b320:·3628·6129·0a20·202d·2050·4349·2d44·5353··6(a).··-·PCI-DSS 
0003b330:·2d52·6571·2d31·312e·350a·2020·2d20·5043··-Req-11.5.··-·PC 
0003b340:·492d·4453·5376·342d·3131·2e35·2e32·0a20··I-DSSv4-11.5.2.· 
0003b350:·202d·2065·6e61·626c·655f·7374·7261·7465···-·enable_strate 
0003b360:·6779·0a20·202d·206c·6f77·5f63·6f6d·706c··gy.··-·low_compl 
0003b370:·6578·6974·790a·2020·2d20·6c6f·775f·6469··exity.··-·low_di 
0003b380:·7372·7570·7469·6f6e·0a20·202d·206d·6564··sruption.··-·med 
0003b390:·6975·6d5f·7365·7665·7269·7479·0a20·202d··ium_severity.··- 
0003b3a0:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede 
0003b3b0:·640a·2020·2d20·7061·636b·6167·655f·6169··d.··-·package_ai 
0003b3c0:·6465·5f69·6e73·7461·6c6c·6564·0a0a·2d20··de_installed..-· 
0003b3d0:·6e61·6d65·3a20·456e·7375·7265·2061·6964··name:·Ensure·aid 
0003b3e0:·6520·6973·2069·6e73·7461·6c6c·6564·0a20··e·is·installed.· 
0003b3f0:·2070·6163·6b61·6765·3a0a·2020·2020·6e61···package:.····na 
0003b400:·6d65·3a20·6169·6465·0a20·2020·2073·7461··me:·aide.····sta 
0003b410:·7465·3a20·7072·6573·656e·740a·2020·7768··te:·present.··wh0003ae40:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 0003ae50:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 0003ae60:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 0003ae70:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 0003ae80:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 0003ae90:·656c·207c·7c20·7270·6d20·2d2d·7175·6965··el·||·rpm·--quie
Max diff block lines reached; 699986/729132 bytes (96.00%) of diff not shown.
52.1 KB
html2text {}
    
Offset 114, 19 lines modifiedOffset 114, 14 lines modified
114 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3114 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
117 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029117 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
120 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule120 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
122 [[packages]] 
123 name·=·"aide" 
124 version·=·"*" 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
130 #·Remediation·is·applicable·only·in·certain·platforms126 #·Remediation·is·applicable·only·in·certain·platforms
131 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then127 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 172, 33 lines modifiedOffset 167, 38 lines modified
172 ··-·PCI-DSSv4-11.5.2167 ··-·PCI-DSSv4-11.5.2
173 ··-·enable_strategy168 ··-·enable_strategy
174 ··-·low_complexity169 ··-·low_complexity
175 ··-·low_disruption170 ··-·low_disruption
176 ··-·medium_severity171 ··-·medium_severity
177 ··-·no_reboot_needed172 ··-·no_reboot_needed
178 ··-·package_aide_installed173 ··-·package_aide_installed
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 179 package·--add=aide
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 181 [[packages]]
 182 name·=·"aide"
 183 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
184 include·install_aide189 include·install_aide
  
185 class·install_aide·{190 class·install_aide·{
186 ··package·{·'aide':191 ··package·{·'aide':
187 ····ensure·=>·'installed',192 ····ensure·=>·'installed',
188 ··}193 ··}
189 }194 }
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
195 package·--add=aide 
196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*195 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
197 Run·the·following·command·to·generate·a·new·database:196 Run·the·following·command·to·generate·a·new·database:
198 $·sudo·/usr/sbin/aide·--init197 $·sudo·/usr/sbin/aide·--init
199 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the198 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
200 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these199 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
201 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their200 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
202 integrity.·The·newly-generated·database·can·be·installed·as·follows:201 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 610, 19 lines modifiedOffset 610, 14 lines modified
610 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235610 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
611 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386611 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
612 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)612 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
613 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1613 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
614 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125614 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
615 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33615 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
616 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2616 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
617 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
618 [[packages]] 
619 name·=·"sudo" 
620 version·=·"*" 
621 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8617 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
622 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low618 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
623 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low619 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
624 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false620 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
625 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable621 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
626 #·Remediation·is·applicable·only·in·certain·platforms622 #·Remediation·is·applicable·only·in·certain·platforms
627 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then623 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 664, 33 lines modifiedOffset 659, 38 lines modified
664 ··-·PCI-DSSv4-2.2.6659 ··-·PCI-DSSv4-2.2.6
665 ··-·enable_strategy660 ··-·enable_strategy
666 ··-·low_complexity661 ··-·low_complexity
667 ··-·low_disruption662 ··-·low_disruption
668 ··-·medium_severity663 ··-·medium_severity
669 ··-·no_reboot_needed664 ··-·no_reboot_needed
670 ··-·package_sudo_installed665 ··-·package_sudo_installed
 666 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 667 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 668 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 669 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 670 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 671 package·--add=sudo
 672 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 673 [[packages]]
 674 name·=·"sudo"
 675 version·=·"*"
671 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8676 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
672 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low677 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
673 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low678 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
674 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false679 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
675 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable680 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
676 include·install_sudo681 include·install_sudo
  
677 class·install_sudo·{682 class·install_sudo·{
678 ··package·{·'sudo':683 ··package·{·'sudo':
679 ····ensure·=>·'installed',684 ····ensure·=>·'installed',
680 ··}685 ··}
681 }686 }
682 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
683 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
684 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
685 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
686 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
687 package·--add=sudo 
688 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*687 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
689 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:688 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
690 $·sudo·chgrp·root·/etc/sudoers.d689 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 48132/53351 bytes (90.22%) of diff not shown.
141 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-anssi_nt28_minimal.html
    
Offset 48339, 75 lines modifiedOffset 48339, 75 lines modified
000bcd20:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm3000bcd20:·7461·2d74·6172·6765·743d·2223·6964·6d33··ta-target="#idm3
000bcd30:·3734·3631·2220·7461·6269·6e64·6578·3d22··7461"·tabindex="000bcd30:·3734·3631·2220·7461·6269·6e64·6578·3d22··7461"·tabindex="
000bcd40:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"000bcd40:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
000bcd50:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="000bcd50:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
000bcd60:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac000bcd60:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
000bcd70:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal000bcd70:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
000bcd80:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme000bcd80:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
000bcd90:·6469·6174·696f·6e20·5075·7070·6574·2073··diation·Puppet·s000bcd90:·6469·6174·696f·6e20·416e·6163·6f6e·6461··diation·Anaconda
000bcda0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b000bcda0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
000bcdb0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa000bcdb0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
000bcdc0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col000bcdc0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
000bcdd0:·6c61·7073·6522·2069·643d·2269·646d·3337··lapse"·id="idm37000bcdd0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
000bcde0:·3436·3122·3e3c·7461·626c·6520·636c·6173··461"><table·clas000bcde0:·3337·3436·3122·3e3c·7461·626c·6520·636c··37461"><table·cl
000bcdf0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s000bcdf0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
000bce00:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor000bce00:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
000bce10:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond000bce10:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
000bce20:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C000bce20:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
000bce30:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><000bce30:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
000bce40:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>000bce40:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
000bce50:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti000bce50:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
000bce60:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<000bce60:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
000bce70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th000bce70:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
000bce80:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td000bce80:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
000bce90:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>000bce90:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
000bcea0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy000bcea0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
000bceb0:·3a3c·2f74·683e·3c74·643e·6469·7361·626c··:</th><td>disabl000bceb0:·6779·3a3c·2f74·683e·3c74·643e·6469·7361··gy:</th><td>disa
000bcec0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab000bcec0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
000bced0:·6c65·3e3c·7072·653e·3c63·6f64·653e·696e··le><pre><code>in000bced0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 000bcee0:·0a70·6163·6b61·6765·202d·2d72·656d·6f76··.package·--remov
 000bcef0:·653d·6468·6370·0a3c·2f63·6f64·653e·3c2f··e=dhcp.</code></
 000bcf00:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 000bcf10:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 000bcf20:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
000bcee0:·636c·7564·6520·7265·6d6f·7665·5f64·6863··clude·remove_dhc 
000bcef0:·700a·0a63·6c61·7373·2072·656d·6f76·655f··p..class·remove_ 
000bcf00:·6468·6370·207b·0a20·2070·6163·6b61·6765··dhcp·{.··package 
000bcf10:·207b·2027·6468·6370·273a·0a20·2020·2065···{·'dhcp':.····e 
000bcf20:·6e73·7572·6520·3d26·6774·3b20·2770·7572··nsure·=&gt;·'pur 
000bcf30:·6765·6427·2c0a·2020·7d0a·7d0a·3c2f·636f··ged',.··}.}.</co 
000bcf40:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
000bcf50:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
000bcf60:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
000bcf70:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
000bcf80:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
000bcf90:·646d·3337·3436·3222·2074·6162·696e·6465··dm37462"·tabinde 
000bcfa0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
000bcfb0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
000bcfc0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
000bcfd0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
000bcfe0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
000bcff0:·656d·6564·6961·7469·6f6e·2041·6e61·636f··emediation·Anaco 
000bd000:·6e64·6120·736e·6970·7065·7420·e287·b23c··nda·snippet·...< 
000bd010:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
000bd020:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
000bd030:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="000bcf30:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
000bd040:·6964·6d33·3734·3632·223e·3c74·6162·6c65··idm37462"><table 
000bd050:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
000bd060:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
000bd070:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
000bd080:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
000bd090:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
000bd0a0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
000bd0b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis000bcf40:·2d74·6172·6765·743d·2223·6964·6d33·3734··-target="#idm374
 000bcf50:·3632·2220·7461·6269·6e64·6578·3d22·3022··62"·tabindex="0"
 000bcf60:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 000bcf70:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 000bcf80:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 000bcf90:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 000bcfa0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 000bcfb0:·6174·696f·6e20·5075·7070·6574·2073·6e69··ation·Puppet·sni
 000bcfc0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 000bcfd0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 000bcfe0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 000bcff0:·7073·6522·2069·643d·2269·646d·3337·3436··pse"·id="idm3746
 000bd000:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 000bd010:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 000bd020:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 000bd030:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 000bd040:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
000bd0c0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td000bd050:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
000bd0d0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t000bd060:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
000bd0e0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
000bd0f0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>000bd070:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 000bd080:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
000bd100:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str000bd090:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
000bd110:·6174·6567·793a·3c2f·7468·3e3c·7464·3e64··ategy:</th><td>d000bd0a0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
000bd120:·6973·6162·6c65·3c2f·7464·3e3c·2f74·723e··isable</td></tr>000bd0b0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
000bd130:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
000bd140:·6465·3e0a·7061·636b·6167·6520·2d2d·7265··de>.package·--re 
000bd150:·6d6f·7665·3d64·6863·700a·3c2f·636f·6465··move=dhcp.</code000bd0c0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 000bd0d0:·2f74·683e·3c74·643e·6469·7361·626c·653c··/th><td>disable<
 000bd0e0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 000bd0f0:·3e3c·7072·653e·3c63·6f64·653e·696e·636c··><pre><code>incl
 000bd100:·7564·6520·7265·6d6f·7665·5f64·6863·700a··ude·remove_dhcp.
 000bd110:·0a63·6c61·7373·2072·656d·6f76·655f·6468··.class·remove_dh
 000bd120:·6370·207b·0a20·2070·6163·6b61·6765·207b··cp·{.··package·{
 000bd130:·2027·6468·6370·273a·0a20·2020·2065·6e73···'dhcp':.····ens
 000bd140:·7572·6520·3d26·6774·3b20·2770·7572·6765··ure·=&gt;·'purge
 000bd150:·6427·2c0a·2020·7d0a·7d0a·3c2f·636f·6465··d',.··}.}.</code
000bd160:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d000bd160:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d
000bd170:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t000bd170:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t
000bd180:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t000bd180:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t
000bd190:·643e·3c2f·7472·3e3c·7472·2064·6174·612d··d></tr><tr·data-000bd190:·643e·3c2f·7472·3e3c·7472·2064·6174·612d··d></tr><tr·data-
000bd1a0:·7474·2d69·643d·2263·6869·6c64·7265·6e2d··tt-id="children-000bd1a0:·7474·2d69·643d·2263·6869·6c64·7265·6e2d··tt-id="children-
000bd1b0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro000bd1b0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
000bd1c0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro000bd1c0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
Offset 48911, 76 lines modifiedOffset 48911, 76 lines modified
000bf0e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id000bf0e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
000bf0f0:·6d33·3831·3132·2220·7461·6269·6e64·6578··m38112"·tabindex000bf0f0:·6d33·3831·3132·2220·7461·6269·6e64·6578··m38112"·tabindex
000bf100:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto000bf100:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
000bf110:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded000bf110:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
000bf120:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="000bf120:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
000bf130:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve000bf130:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
000bf140:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re000bf140:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
000bf150:·6d65·6469·6174·696f·6e20·5075·7070·6574··mediation·Puppet000bf150:·6d65·6469·6174·696f·6e20·416e·6163·6f6e··mediation·Anacon
000bf160:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>000bf160:·6461·2073·6e69·7070·6574·20e2·87b2·3c2f··da·snippet·...</
000bf170:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="000bf170:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
000bf180:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c000bf180:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
000bf190:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm000bf190:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
000bf1a0:·3338·3131·3222·3e3c·7461·626c·6520·636c··38112"><table·cl000bf1a0:·646d·3338·3131·3222·3e3c·7461·626c·6520··dm38112"><table·
000bf1b0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table000bf1b0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
000bf1c0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b000bf1c0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
000bf1d0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co000bf1d0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
000bf1e0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th000bf1e0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
000bf1f0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th000bf1f0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
000bf200:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t000bf200:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
000bf210:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup000bf210:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
Max diff block lines reached; 105028/123572 bytes (84.99%) of diff not shown.
20.3 KB
html2text {}
    
Offset 10678, 33 lines modifiedOffset 10678, 33 lines modified
10678 ··-·PCI-DSSv4-2.2.410678 ··-·PCI-DSSv4-2.2.4
10679 ··-·disable_strategy10679 ··-·disable_strategy
10680 ··-·low_complexity10680 ··-·low_complexity
10681 ··-·low_disruption10681 ··-·low_disruption
10682 ··-·medium_severity10682 ··-·medium_severity
10683 ··-·no_reboot_needed10683 ··-·no_reboot_needed
10684 ··-·package_dhcp_removed10684 ··-·package_dhcp_removed
 10685 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10686 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10687 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10688 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10689 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10690 package·--remove=dhcp
10685 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810691 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10686 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10692 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10687 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10693 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10688 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10694 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10689 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10695 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10690 include·remove_dhcp10696 include·remove_dhcp
  
10691 class·remove_dhcp·{10697 class·remove_dhcp·{
10692 ··package·{·'dhcp':10698 ··package·{·'dhcp':
10693 ····ensure·=>·'purged',10699 ····ensure·=>·'purged',
10694 ··}10700 ··}
10695 }10701 }
10696 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10697 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10698 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10699 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10700 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10701 package·--remove=dhcp 
10702 Group  ·Mail·Server·Software·  Group·contains·1·rule10702 Group  ·Mail·Server·Software·  Group·contains·1·rule
10703 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very10703 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very
10704 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure10704 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure
10705 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as10705 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as
10706 possible.10706 possible.
  
10707 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.10707 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.
Offset 10797, 33 lines modifiedOffset 10797, 33 lines modified
10797 ··-·NIST-800-53-CM-7(b)10797 ··-·NIST-800-53-CM-7(b)
10798 ··-·disable_strategy10798 ··-·disable_strategy
10799 ··-·low_complexity10799 ··-·low_complexity
10800 ··-·low_disruption10800 ··-·low_disruption
10801 ··-·medium_severity10801 ··-·medium_severity
10802 ··-·no_reboot_needed10802 ··-·no_reboot_needed
10803 ··-·package_sendmail_removed10803 ··-·package_sendmail_removed
 10804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10805 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10806 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10807 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10808 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10809 package·--remove=sendmail
10804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810810 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10805 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10811 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10806 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10812 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10807 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10813 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10808 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10814 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10809 include·remove_sendmail10815 include·remove_sendmail
  
10810 class·remove_sendmail·{10816 class·remove_sendmail·{
10811 ··package·{·'sendmail':10817 ··package·{·'sendmail':
10812 ····ensure·=>·'purged',10818 ····ensure·=>·'purged',
10813 ··}10819 ··}
10814 }10820 }
10815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10816 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10817 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10818 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10819 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10820 package·--remove=sendmail 
10821 Group  ·Obsolete·Services·  Group·contains·6·groups·and·11·rules10821 Group  ·Obsolete·Services·  Group·contains·6·groups·and·11·rules
10822 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically10822 _\x8[_\x8r_\x8e_\x8f_\x8]  ·This·section·discusses·a·number·of·network-visible·services·which·have·historically
10823 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service10823 caused·problems·for·system·security,·and·for·which·disabling·or·severely·limiting·the·service
10824 has·been·the·best·available·guidance·for·some·time.·As·a·result·of·this,·many·of·these10824 has·been·the·best·available·guidance·for·some·time.·As·a·result·of·this,·many·of·these
10825 services·are·not·installed·as·part·of·Oracle·Linux·7·by·default.10825 services·are·not·installed·as·part·of·Oracle·Linux·7·by·default.
  
10826 Organizations·which·are·running·these·services·should·switch·to·more·secure·equivalents·as10826 Organizations·which·are·running·these·services·should·switch·to·more·secure·equivalents·as
Offset 10918, 33 lines modifiedOffset 10918, 33 lines modified
10918 ··-·PCI-DSSv4-2.2.410918 ··-·PCI-DSSv4-2.2.4
10919 ··-·disable_strategy10919 ··-·disable_strategy
10920 ··-·low_complexity10920 ··-·low_complexity
10921 ··-·low_disruption10921 ··-·low_disruption
10922 ··-·low_severity10922 ··-·low_severity
10923 ··-·no_reboot_needed10923 ··-·no_reboot_needed
10924 ··-·package_xinetd_removed10924 ··-·package_xinetd_removed
 10925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10926 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10927 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10928 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10929 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10930 package·--remove=xinetd
10925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810931 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10926 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10932 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10927 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10933 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10928 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10934 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10929 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10935 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
10930 include·remove_xinetd10936 include·remove_xinetd
  
10931 class·remove_xinetd·{10937 class·remove_xinetd·{
10932 ··package·{·'xinetd':10938 ··package·{·'xinetd':
10933 ····ensure·=>·'purged',10939 ····ensure·=>·'purged',
10934 ··}10940 ··}
10935 }10941 }
10936 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
10937 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
10938 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
10939 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
10940 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
10941 package·--remove=xinetd 
10942 Group  ·NIS·  Group·contains·2·rules10942 Group  ·NIS·  Group·contains·2·rules
10943 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Network·Information·Service·(NIS),·also·known·as·'Yellow·Pages'·(YP),·and·its10943 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Network·Information·Service·(NIS),·also·known·as·'Yellow·Pages'·(YP),·and·its
10944 successor·NIS+·have·been·made·obsolete·by·Kerberos,·LDAP,·and·other·modern·centralized10944 successor·NIS+·have·been·made·obsolete·by·Kerberos,·LDAP,·and·other·modern·centralized
10945 authentication·services.·NIS·should·not·be·used·because·it·suffers·from·security·problems10945 authentication·services.·NIS·should·not·be·used·because·it·suffers·from·security·problems
10946 inherent·in·its·design,·such·as·inadequate·protection·of·important·authentication10946 inherent·in·its·design,·such·as·inadequate·protection·of·important·authentication
10947 information.10947 information.
10948 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·R\x8Re\x8em\x8mo\x8ov\x8ve\x8e·N\x8NI\x8IS\x8S·C\x8Cl\x8li\x8ie\x8en\x8nt\x8t·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*10948 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·R\x8Re\x8em\x8mo\x8ov\x8ve\x8e·N\x8NI\x8IS\x8S·C\x8Cl\x8li\x8ie\x8en\x8nt\x8t·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 10991, 33 lines modifiedOffset 10991, 33 lines modified
10991 ··-·PCI-DSSv4-2.2.410991 ··-·PCI-DSSv4-2.2.4
10992 ··-·disable_strategy10992 ··-·disable_strategy
10993 ··-·low_complexity10993 ··-·low_complexity
10994 ··-·low_disruption10994 ··-·low_disruption
Max diff block lines reached; 16001/20805 bytes (76.91%) of diff not shown.
296 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-cjis.html
    
Offset 16627, 221 lines modifiedOffset 16627, 221 lines modified
00040f20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00040f20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
00040f30:·2369·646d·3536·3531·2220·7461·6269·6e64··#idm5651"·tabind00040f30:·2369·646d·3536·3531·2220·7461·6269·6e64··#idm5651"·tabind
00040f40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00040f40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
00040f50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00040f50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
00040f60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00040f60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
00040f70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00040f70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
00040f80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">00040f80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00040f90:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu00040f90:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 00040fa0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
00040fa0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
00040fb0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
00040fc0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00040fd0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00040fe0:·6170·7365·2220·6964·3d22·6964·6d35·3635··apse"·id="idm565 
00040ff0:·3122·3e3c·7072·653e·3c63·6f64·653e·0a5b··1"><pre><code>.[ 
00041000:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
00041010:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio 
00041020:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
00041030:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
00041040:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00041050:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00041060:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
00041070:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56 
00041080:·3532·2220·7461·6269·6e64·6578·3d22·3022··52"·tabindex="0" 
00041090:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
000410a0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
000410b0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
000410c0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
000410d0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
000410e0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
000410f0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
00041100:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
00041110:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
00041120:·6522·2069·643d·2269·646d·3536·3532·223e··e"·id="idm5652"> 
00041130:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
00041140:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
00041150:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
00041160:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
00041170:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
00041180:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
00041190:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
000411a0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
000411b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
000411c0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
000411d0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
000411e0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
000411f0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00041200:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00041210:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00041220:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
00041230:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
00041240:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
00041250:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
00041260:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
00041270:·6b65·726e·656c·207c·7c20·7270·6d20·2d2d··kernel·||·rpm·-- 
00041280:·7175·6965·7420·2d71·206b·6572·6e65·6c2d··quiet·-q·kernel- 
00041290:·7565·6b3b·2074·6865·6e0a·0a69·6620·2120··uek;·then..if·!· 
000412a0:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
000412b0:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.··· 
000412c0:·2079·756d·2069·6e73·7461·6c6c·202d·7920···yum·install·-y· 
000412d0:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else. 
000412e0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
000412f0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
00041300:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
00041310:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
00041320:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
00041330:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00041340:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00041350:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00041360:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00041370:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5 
00041380:·3635·3322·2074·6162·696e·6465·783d·2230··653"·tabindex="0 
00041390:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
000413a0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
000413b0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
000413c0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
000413d0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
000413e0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
000413f0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00041400:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00040fb0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
00041410:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00040fc0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
00041420:·6c61·7073·6522·2069·643d·2269·646d·3536··lapse"·id="idm5600040fd0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
00041430:·3533·223e·3c74·6162·6c65·2063·6c61·7373··53"><table·class00040fe0:·3536·3531·223e·3c74·6162·6c65·2063·6c61··5651"><table·cla
00041440:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00040ff0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
00041450:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord00041000:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
00041460:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde00041010:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
00041470:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co00041020:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
00041480:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t00041030:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
00041490:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00041040:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
000414a0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio00041050:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
000414b0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</00041060:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
000414c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00041070:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
000414d0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>00041080:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 00041090:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 000410a0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 000410b0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 000410c0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 000410d0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
 000410e0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 000410f0:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 00041100:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 00041110:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 00041120:·6574·202d·7120·6b65·726e·656c·207c·7c20··et·-q·kernel·||·
 00041130:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k
 00041140:·6572·6e65·6c2d·7565·6b3b·2074·6865·6e0a··ernel-uek;·then.
 00041150:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
 00041160:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th
 00041170:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta
 00041180:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi.
 00041190:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 000411a0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 000411b0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 000411c0:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 000411d0:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
 000411e0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 000411f0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00041200:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00041210:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00041220:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 00041230:·2223·6964·6d35·3635·3222·2074·6162·696e··"#idm5652"·tabin
 00041240:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00041250:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00041260:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00041270:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00041280:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00041290:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
 000412a0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
Max diff block lines reached; 242720/271866 bytes (89.28%) of diff not shown.
30.0 KB
html2text {}
    
Offset 510, 19 lines modifiedOffset 510, 14 lines modified
510 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3510 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
511 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5511 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
512 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199512 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
513 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029513 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
514 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79514 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
515 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2515 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
516 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule516 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule
517 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
518 [[packages]] 
519 name·=·"aide" 
520 version·=·"*" 
521 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8517 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
522 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low518 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
523 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low519 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
524 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false520 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
525 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable521 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
526 #·Remediation·is·applicable·only·in·certain·platforms522 #·Remediation·is·applicable·only·in·certain·platforms
527 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then523 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 568, 33 lines modifiedOffset 563, 38 lines modified
568 ··-·PCI-DSSv4-11.5.2563 ··-·PCI-DSSv4-11.5.2
569 ··-·enable_strategy564 ··-·enable_strategy
570 ··-·low_complexity565 ··-·low_complexity
571 ··-·low_disruption566 ··-·low_disruption
572 ··-·medium_severity567 ··-·medium_severity
573 ··-·no_reboot_needed568 ··-·no_reboot_needed
574 ··-·package_aide_installed569 ··-·package_aide_installed
 570 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 571 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 572 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 573 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 574 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 575 package·--add=aide
 576 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 577 [[packages]]
 578 name·=·"aide"
 579 version·=·"*"
575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8580 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
576 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low581 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
577 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low582 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
578 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false583 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
579 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable584 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
580 include·install_aide585 include·install_aide
  
581 class·install_aide·{586 class·install_aide·{
582 ··package·{·'aide':587 ··package·{·'aide':
583 ····ensure·=>·'installed',588 ····ensure·=>·'installed',
584 ··}589 ··}
585 }590 }
586 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
587 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
588 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
589 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
590 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
591 package·--add=aide 
592 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*591 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
593 Run·the·following·command·to·generate·a·new·database:592 Run·the·following·command·to·generate·a·new·database:
594 $·sudo·/usr/sbin/aide·--init593 $·sudo·/usr/sbin/aide·--init
595 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:594 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
596 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz595 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
597 To·initiate·a·manual·check,·run·the·following·command:596 To·initiate·a·manual·check,·run·the·following·command:
598 $·sudo·/usr/sbin/aide·--check597 $·sudo·/usr/sbin/aide·--check
Offset 5133, 14 lines modifiedOffset 5133, 38 lines modified
5133 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"5133 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
5134 fi5134 fi
5135 fi5135 fi
  
5136 else5136 else
5137 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'5137 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
5138 fi5138 fi
 5139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 5140 ---
 5141 apiVersion:·machineconfiguration.openshift.io/v1
 5142 kind:·MachineConfig
 5143 spec:
 5144 ··config:
 5145 ····ignition:
 5146 ······version:·3.1.0
 5147 ····storage:
 5148 ······files:
 5149 ······-·contents:
 5150 ··········source:
 5151 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 5152 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 5153 ········mode:·0644
 5154 ········path:·/etc/pam.d/password-auth
 5155 ········overwrite:·true
 5156 ······-·contents:
 5157 ··········source:
 5158 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 5159 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 5160 ········mode:·0644
 5161 ········path:·/etc/pam.d/system-auth
 5162 ········overwrite:·true
5139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium5165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
5142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure5167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
5144 -·name:·Gather·the·package·facts5168 -·name:·Gather·the·package·facts
5145 ··package_facts:5169 ··package_facts:
Offset 5283, 38 lines modifiedOffset 5307, 14 lines modified
5283 ··-·PCI-DSSv4-8.3.15307 ··-·PCI-DSSv4-8.3.1
5284 ··-·configure_strategy5308 ··-·configure_strategy
5285 ··-·high_severity5309 ··-·high_severity
5286 ··-·low_complexity5310 ··-·low_complexity
5287 ··-·medium_disruption5311 ··-·medium_disruption
5288 ··-·no_empty_passwords5312 ··-·no_empty_passwords
5289 ··-·no_reboot_needed5313 ··-·no_reboot_needed
5290 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
5291 --- 
5292 apiVersion:·machineconfiguration.openshift.io/v1 
5293 kind:·MachineConfig 
5294 spec: 
5295 ··config: 
5296 ····ignition: 
5297 ······version:·3.1.0 
5298 ····storage: 
5299 ······files: 
5300 ······-·contents: 
5301 ··········source: 
5302 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
5303 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
5304 ········mode:·0644 
Max diff block lines reached; 9713/30698 bytes (31.64%) of diff not shown.
742 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-cui.html
    
Offset 15071, 246 lines modifiedOffset 15071, 246 lines modified
0003ade0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003ade0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003adf0:·6964·6d36·3138·3322·2074·6162·696e·6465··idm6183"·tabinde0003adf0:·6964·6d36·3138·3322·2074·6162·696e·6465··idm6183"·tabinde
0003ae00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003ae00:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003ae10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003ae10:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003ae20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003ae20:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003ae30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003ae30:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003ae40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003ae40:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003ae50:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003ae50:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0003ae60:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003ae70:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003ae80:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003ae90:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003aea0:·7073·6522·2069·643d·2269·646d·3631·3833··pse"·id="idm6183 
0003aeb0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003aec0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003aed0:·3d20·2264·7261·6375·742d·6669·7073·220a··=·"dracut-fips". 
0003aee0:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
0003aef0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003af00:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003af10:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003af20:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003af30:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003af40:·2369·646d·3631·3834·2220·7461·6269·6e64··#idm6184"·tabind 
0003af50:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003af60:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003af70:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003af80:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003af90:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003afa0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003afb0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003afc0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003afd0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003afe0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003aff0:·3631·3834·223e·3c74·6162·6c65·2063·6c61··6184"><table·cla 
0003b000:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b010:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b020:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b030:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b040:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b050:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b060:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b070:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b080:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b090:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b0a0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b0b0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b0c0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b0d0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b0e0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003b0f0:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003b100:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003b110:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003b120:·726d·730a·6966·2028·2021·2028·205b·2022··rms.if·(·!·(·[·" 
0003b130:·247b·636f·6e74·6169·6e65·723a·2d7d·2220··${container:-}"· 
0003b140:·3d3d·2022·6277·7261·702d·6f73·6275·696c··==·"bwrap-osbuil 
0003b150:·6422·205d·2029·2026·616d·703b·2661·6d70··d"·]·)·&amp;&amp 
0003b160:·3b20·7270·6d20·2d2d·7175·6965·7420·2d71··;·rpm·--quiet·-q 
0003b170:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·- 
0003b180:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel 
0003b190:·2d75·656b·2029·3b20·7468·656e·0a0a·6966··-uek·);·then..if 
0003b1a0:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003b1b0:·7420·2264·7261·6375·742d·6669·7073·2220··t·"dracut-fips"· 
0003b1c0:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i 
0003b1d0:·6e73·7461·6c6c·202d·7920·2264·7261·6375··nstall·-y·"dracu 
0003b1e0:·742d·6669·7073·220a·6669·0a0a·656c·7365··t-fips".fi..else 
0003b1f0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b200:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b210:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b220:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b230:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b240:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b250:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b260:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b270:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b280:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b290:·3631·3835·2220·7461·6269·6e64·6578·3d22··6185"·tabindex=" 
0003b2a0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b2b0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b2c0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b2d0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b2e0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b2f0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003b300:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003ae60:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003b310:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003ae70:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b320:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003ae80:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b330:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm60003ae90:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
0003b340:·3138·3522·3e3c·7461·626c·6520·636c·6173··185"><table·clas0003aea0:·3138·3322·3e3c·7461·626c·6520·636c·6173··183"><table·clas
0003b350:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003aeb0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b360:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003aec0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b370:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003aed0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b380:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003aee0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b390:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003aef0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b3a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003af00:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b3b0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003af10:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b3c0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003af20:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b3d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003af30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b3e0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003af40:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b3f0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003af50:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b400:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003af60:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b410:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003af70:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003b420:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003af80:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b430:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0003af90:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
0003b440:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
0003b450:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
0003b460:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
0003b470:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto0003afa0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003afb0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003afc0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003afd0:·6d73·0a69·6620·2820·2120·2820·5b20·2224··ms.if·(·!·(·[·"$
 0003afe0:·7b63·6f6e·7461·696e·6572·3a2d·7d22·203d··{container:-}"·=
 0003aff0:·3d20·2262·7772·6170·2d6f·7362·7569·6c64··=·"bwrap-osbuild
 0003b000:·2220·5d20·2920·2661·6d70·3b26·616d·703b··"·]·)·&amp;&amp;
 0003b010:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 0003b020:·6b65·726e·656c·207c·7c20·7270·6d20·2d2d··kernel·||·rpm·--
 0003b030:·7175·6965·7420·2d71·206b·6572·6e65·6c2d··quiet·-q·kernel-
 0003b040:·7565·6b20·293b·2074·6865·6e0a·0a69·6620··uek·);·then..if·
 0003b050:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003b060:·2022·6472·6163·7574·2d66·6970·7322·203b···"dracut-fips"·;
 0003b070:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003b080:·7374·616c·6c20·2d79·2022·6472·6163·7574··stall·-y·"dracut
 0003b090:·2d66·6970·7322·0a66·690a·0a65·6c73·650a··-fips".fi..else.
 0003b0a0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 0003b0b0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 0003b0c0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 0003b0d0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 0003b0e0:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
 0003b0f0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
Max diff block lines reached; 672795/705391 bytes (95.38%) of diff not shown.
53.2 KB
html2text {}
    
Offset 99, 19 lines modifiedOffset 99, 14 lines modified
99 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.699 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.6
100 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6100 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
101 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2101 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2
102 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1102 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1
103 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12103 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
104 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4104 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4
105 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223105 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223
106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
107 [[packages]] 
108 name·=·"dracut-fips" 
109 version·=·"*" 
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
115 #·Remediation·is·applicable·only·in·certain·platforms111 #·Remediation·is·applicable·only·in·certain·platforms
116 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then112 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
Offset 166, 33 lines modifiedOffset 161, 38 lines modified
166 ··-·NIST-800-53-SC-13161 ··-·NIST-800-53-SC-13
167 ··-·enable_strategy162 ··-·enable_strategy
168 ··-·low_complexity163 ··-·low_complexity
169 ··-·low_disruption164 ··-·low_disruption
170 ··-·medium_severity165 ··-·medium_severity
171 ··-·no_reboot_needed166 ··-·no_reboot_needed
172 ··-·package_dracut-fips_installed167 ··-·package_dracut-fips_installed
 168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 173 package·--add=dracut-fips
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 175 [[packages]]
 176 name·=·"dracut-fips"
 177 version·=·"*"
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
178 include·install_dracut-fips183 include·install_dracut-fips
  
179 class·install_dracut-fips·{184 class·install_dracut-fips·{
180 ··package·{·'dracut-fips':185 ··package·{·'dracut-fips':
181 ····ensure·=>·'installed',186 ····ensure·=>·'installed',
182 ··}187 ··}
183 }188 }
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·--add=dracut-fips 
190 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*189 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
191 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:190 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:
192 $·sudo·yum·install·dracut-fips191 $·sudo·yum·install·dracut-fips
193 dracut·-f192 dracut·-f
194 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:193 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:
195 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"194 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"
196 Finally,·rebuild·the·grub.cfg·file·by·using·the195 Finally,·rebuild·the·grub.cfg·file·by·using·the
Offset 7963, 19 lines modifiedOffset 7963, 14 lines modified
7963 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.37963 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3
7964 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)7964 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
7965 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-77965 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-7
7966 ············_\x8o_\x8s_\x8p_\x8p···········FMT_MOF_EXT.17966 ············_\x8o_\x8s_\x8p_\x8p···········FMT_MOF_EXT.1
7967 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000029-GPOS-000107967 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000029-GPOS-00010
7968 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-0100907968 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010090
7969 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255900r958402_rule7969 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255900r958402_rule
7970 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
7971 [[packages]] 
7972 name·=·"screen" 
7973 version·=·"*" 
7974 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87970 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7975 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7971 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7976 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7972 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7977 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7973 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7978 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7974 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7979 #·Remediation·is·applicable·only·in·certain·platforms7975 #·Remediation·is·applicable·only·in·certain·platforms
7980 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then7976 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 8017, 51 lines modifiedOffset 8012, 52 lines modified
8017 ··-·NIST-800-53-CM-6(a)8012 ··-·NIST-800-53-CM-6(a)
8018 ··-·enable_strategy8013 ··-·enable_strategy
8019 ··-·low_complexity8014 ··-·low_complexity
8020 ··-·low_disruption8015 ··-·low_disruption
8021 ··-·medium_severity8016 ··-·medium_severity
8022 ··-·no_reboot_needed8017 ··-·no_reboot_needed
8023 ··-·package_screen_installed8018 ··-·package_screen_installed
 8019 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 8020 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 8021 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 8022 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 8023 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 8024 package·--add=screen
 8025 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 8026 [[packages]]
 8027 name·=·"screen"
 8028 version·=·"*"
8024 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88029 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8025 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8030 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8026 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8031 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8027 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8032 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8028 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8033 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8029 include·install_screen8034 include·install_screen
  
8030 class·install_screen·{8035 class·install_screen·{
8031 ··package·{·'screen':8036 ··package·{·'screen':
8032 ····ensure·=>·'installed',8037 ····ensure·=>·'installed',
8033 ··}8038 ··}
8034 }8039 }
8035 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
8036 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
8037 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
8038 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
8039 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
8040 package·--add=screen 
8041 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·d\x8de\x8eb\x8bu\x8ug\x8g-\x8-s\x8sh\x8he\x8el\x8ll\x8l·S\x8Sy\x8ys\x8st\x8te\x8em\x8mD\x8D·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*8040 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·d\x8de\x8eb\x8bu\x8ug\x8g-\x8-s\x8sh\x8he\x8el\x8ll\x8l·S\x8Sy\x8ys\x8st\x8te\x8em\x8mD\x8D·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
8042 SystemD's·debug-shell·service·is·intended·to·diagnose·SystemD·related·boot·issues·with·various·systemctl·commands.·Once·enabled·and·following·a·system·reboot,·the·root·shell·will·be·available·on·tty9·which·is·access·by·pressing·CTRL-ALT-F9.·The·debug-shell·service·should·only·be·used·for·SystemD·related·issues·and·should·otherwise·be·disabled.8041 SystemD's·debug-shell·service·is·intended·to·diagnose·SystemD·related·boot·issues·with·various·systemctl·commands.·Once·enabled·and·following·a·system·reboot,·the·root·shell·will·be·available·on·tty9·which·is·access·by·pressing·CTRL-ALT-F9.·The·debug-shell·service·should·only·be·used·for·SystemD·related·issues·and·should·otherwise·be·disabled.
  
Max diff block lines reached; 48464/54475 bytes (88.97%) of diff not shown.
659 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-e8.html
    
Offset 18503, 284 lines modifiedOffset 18503, 284 lines modified
00048460:·6765·743d·2223·6964·6d39·3835·3122·2074··get="#idm9851"·t00048460:·6765·743d·2223·6964·6d39·3835·3122·2074··get="#idm9851"·t
00048470:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00048470:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00048480:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00048480:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00048490:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00048490:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
000484a0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·000484a0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
000484b0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=000484b0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
000484c0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation000484c0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 000484d0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 000484e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 000484f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00048500:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00048510:·3d22·6964·6d39·3835·3122·3e3c·7461·626c··="idm9851"><tabl
 00048520:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00048530:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00048540:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00048550:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00048560:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00048570:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00048580:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00048590:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 000485a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 000485b0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 000485c0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 000485d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 000485e0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
000484d0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
000484e0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
000484f0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00048500:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00048510:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00048520:·646d·3938·3531·223e·3c70·7265·3e3c·636f··dm9851"><pre><co 
00048530:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
00048540:·0a6e·616d·6520·3d20·2272·6561·7222·0a76··.name·=·"rear".v 
00048550:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
00048560:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00048570:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00048580:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00048590:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
000485a0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
000485b0:·6964·6d39·3835·3222·2074·6162·696e·6465··idm9852"·tabinde 
000485c0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
000485d0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
000485e0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
000485f0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
00048600:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
00048610:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
00048620:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
00048630:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
00048640:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
00048650:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9 
00048660:·3835·3222·3e3c·7461·626c·6520·636c·6173··852"><table·clas 
00048670:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00048680:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00048690:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
000486a0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
000486b0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
000486c0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
000486d0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
000486e0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
000486f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00048700:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
00048710:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>000485f0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 00048600:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 00048610:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 00048620:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 00048630:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 00048640:·6c61·7466·6f72·6d73·0a69·6620·2120·2820··latforms.if·!·(·
00048720:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00048730:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
00048740:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00048750:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
00048760:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
00048770:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
00048780:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
00048790:·6d73·0a69·6620·2120·2820·2820·2820·2820··ms.if·!·(·(·(·(· 
000487a0:·6772·6570·202d·7371·4520·225e·2e2a·5c2e··grep·-sqE·"^.*\. 
000487b0:·6161·7263·6836·3424·2220·2f70·726f·632f··aarch64$"·/proc/ 
000487c0:·7379·732f·6b65·726e·656c·2f6f·7372·656c··sys/kernel/osrel 
000487d0:·6561·7365·207c·7c20·6772·6570·202d·7371··ease·||·grep·-sq 
000487e0:·4520·225e·6161·7263·6836·3424·2220·2f70··E·"^aarch64$"·/p 
000487f0:·726f·632f·7379·732f·6b65·726e·656c·2f61··roc/sys/kernel/a 
00048800:·7263·683b·2029·2026·616d·703b·2661·6d70··rch;·)·&amp;&amp 
00048810:·3b20·6772·6570·202d·7150·2022·5e49·443d··;·grep·-qP·"^ID= 
00048820:·5b5c·2227·5d3f·6f6c·5b5c·2227·5d3f·2422··[\"']?ol[\"']?$" 
00048830:·2022·2f65·7463·2f6f·732d·7265·6c65·6173···"/etc/os-releas 
00048840:·6522·2026·616d·703b·2661·6d70·3b20·7b20··e"·&amp;&amp;·{· 
00048850:·7265·616c·3d22·2428·6772·6570·202d·5020··real="$(grep·-P· 
00048860:·225e·5645·5253·494f·4e5f·4944·3d5b·5c22··"^VERSION_ID=[\" 
00048870:·275d·3f5b·5c77·2e5d·2b5b·5c22·275d·3f24··']?[\w.]+[\"']?$ 
00048880:·2220·2f65·7463·2f6f·732d·7265·6c65·6173··"·/etc/os-releas 
00048890:·6520·7c20·7365·6420·2273·2f5e·5645·5253··e·|·sed·"s/^VERS 
000488a0:·494f·4e5f·4944·3d5b·5c22·275d·5c3f·5c28··ION_ID=[\"']\?\( 
000488b0:·5b5e·5c22·275d·5c2b·5c29·5b5c·2227·5d5c··[^\"']\+\)[\"']\ 
000488c0:·3f24·2f5c·312f·2229·223b·2065·7870·6563··?$/\1/")";·expec 
000488d0:·7465·643d·2239·2e30·223b·2070·7269·6e74··ted="9.0";·print 
000488e0:·6620·2225·735c·6e25·7322·2022·2465·7870··f·"%s\n%s"·"$exp 
000488f0:·6563·7465·6422·2022·2472·6561·6c22·207c··ected"·"$real"·| 
00048900:·2073·6f72·7420·2d56·433b·207d·2029·207c···sort·-VC;·}·)·| 
00048910:·7c20·2820·2820·6772·6570·202d·7371·4520··|·(·(·grep·-sqE·00048650:·2820·2820·2820·6772·6570·202d·7371·4520··(·(·(·grep·-sqE·
00048920:·225e·2e2a·5c2e·6161·7263·6836·3424·2220··"^.*\.aarch64$"·00048660:·225e·2e2a·5c2e·6161·7263·6836·3424·2220··"^.*\.aarch64$"·
00048930:·2f70·726f·632f·7379·732f·6b65·726e·656c··/proc/sys/kernel00048670:·2f70·726f·632f·7379·732f·6b65·726e·656c··/proc/sys/kernel
00048940:·2f6f·7372·656c·6561·7365·207c·7c20·6772··/osrelease·||·gr00048680:·2f6f·7372·656c·6561·7365·207c·7c20·6772··/osrelease·||·gr
00048950:·6570·202d·7371·4520·225e·6161·7263·6836··ep·-sqE·"^aarch600048690:·6570·202d·7371·4520·225e·6161·7263·6836··ep·-sqE·"^aarch6
00048960:·3424·2220·2f70·726f·632f·7379·732f·6b65··4$"·/proc/sys/ke000486a0:·3424·2220·2f70·726f·632f·7379·732f·6b65··4$"·/proc/sys/ke
00048970:·726e·656c·2f61·7263·683b·2029·2026·616d··rnel/arch;·)·&am000486b0:·726e·656c·2f61·7263·683b·2029·2026·616d··rnel/arch;·)·&am
00048980:·703b·2661·6d70·3b20·6772·6570·202d·7150··p;&amp;·grep·-qP000486c0:·703b·2661·6d70·3b20·6772·6570·202d·7150··p;&amp;·grep·-qP
00048990:·2022·5e49·443d·5b5c·2227·5d3f·7268·656c···"^ID=[\"']?rhel000486d0:·2022·5e49·443d·5b5c·2227·5d3f·6f6c·5b5c···"^ID=[\"']?ol[\
000489a0:·5b5c·2227·5d3f·2422·2022·2f65·7463·2f6f··[\"']?$"·"/etc/o000486e0:·2227·5d3f·2422·2022·2f65·7463·2f6f·732d··"']?$"·"/etc/os-
000489b0:·732d·7265·6c65·6173·6522·2026·616d·703b··s-release"·&amp;000486f0:·7265·6c65·6173·6522·2026·616d·703b·2661··release"·&amp;&a
000489c0:·2661·6d70·3b20·7b20·7265·616c·3d22·2428··&amp;·{·real="$(00048700:·6d70·3b20·7b20·7265·616c·3d22·2428·6772··mp;·{·real="$(gr
000489d0:·6772·6570·202d·5020·225e·5645·5253·494f··grep·-P·"^VERSIO00048710:·6570·202d·5020·225e·5645·5253·494f·4e5f··ep·-P·"^VERSION_
000489e0:·4e5f·4944·3d5b·5c22·275d·3f5b·5c77·2e5d··N_ID=[\"']?[\w.]00048720:·4944·3d5b·5c22·275d·3f5b·5c77·2e5d·2b5b··ID=[\"']?[\w.]+[
000489f0:·2b5b·5c22·275d·3f24·2220·2f65·7463·2f6f··+[\"']?$"·/etc/o00048730:·5c22·275d·3f24·2220·2f65·7463·2f6f·732d··\"']?$"·/etc/os-
00048a00:·732d·7265·6c65·6173·6520·7c20·7365·6420··s-release·|·sed·00048740:·7265·6c65·6173·6520·7c20·7365·6420·2273··release·|·sed·"s
00048a10:·2273·2f5e·5645·5253·494f·4e5f·4944·3d5b··"s/^VERSION_ID=[00048750:·2f5e·5645·5253·494f·4e5f·4944·3d5b·5c22··/^VERSION_ID=[\"
00048a20:·5c22·275d·5c3f·5c28·5b5e·5c22·275d·5c2b··\"']\?\([^\"']\+00048760:·275d·5c3f·5c28·5b5e·5c22·275d·5c2b·5c29··']\?\([^\"']\+\)
00048a30:·5c29·5b5c·2227·5d5c·3f24·2f5c·312f·2229··\)[\"']\?$/\1/")00048770:·5b5c·2227·5d5c·3f24·2f5c·312f·2229·223b··[\"']\?$/\1/")";
00048a40:·223b·2065·7870·6563·7465·643d·2239·2e30··";·expected="9.000048780:·2065·7870·6563·7465·643d·2239·2e30·223b···expected="9.0";
00048a50:·223b·2070·7269·6e74·6620·2225·735c·6e25··";·printf·"%s\n%00048790:·2070·7269·6e74·6620·2225·735c·6e25·7322···printf·"%s\n%s"
00048a60:·7322·2022·2465·7870·6563·7465·6422·2022··s"·"$expected"·"000487a0:·2022·2465·7870·6563·7465·6422·2022·2472···"$expected"·"$r
00048a70:·2472·6561·6c22·207c·2073·6f72·7420·2d56··$real"·|·sort·-V000487b0:·6561·6c22·207c·2073·6f72·7420·2d56·433b··eal"·|·sort·-VC;
00048a80:·433b·207d·2029·207c·7c20·2820·6772·6570··C;·}·)·||·(·grep000487c0:·207d·2029·207c·7c20·2820·2820·6772·6570···}·)·||·(·(·grep
 000487d0:·202d·7371·4520·225e·2e2a·5c2e·6161·7263···-sqE·"^.*\.aarc
 000487e0:·6836·3424·2220·2f70·726f·632f·7379·732f··h64$"·/proc/sys/
 000487f0:·6b65·726e·656c·2f6f·7372·656c·6561·7365··kernel/osrelease
 00048800:·207c·7c20·6772·6570·202d·7371·4520·225e···||·grep·-sqE·"^
 00048810:·6161·7263·6836·3424·2220·2f70·726f·632f··aarch64$"·/proc/
Max diff block lines reached; 570922/608762 bytes (93.78%) of diff not shown.
64.4 KB
html2text {}
    
Offset 971, 19 lines modifiedOffset 971, 14 lines modified
971 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.971 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.
972 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*972 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
973 The·rear·package·can·be·installed·with·the·following·command:973 The·rear·package·can·be·installed·with·the·following·command:
974 $·sudo·yum·install·rear974 $·sudo·yum·install·rear
975 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.975 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.
976 Severity: ·medium976 Severity: ·medium
977 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed977 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed
978 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
979 [[packages]] 
980 name·=·"rear" 
981 version·=·"*" 
982 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8978 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
983 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low979 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
984 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low980 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
985 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false981 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
986 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable982 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
987 #·Remediation·is·applicable·only·in·certain·platforms983 #·Remediation·is·applicable·only·in·certain·platforms
988 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then984 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1012, 33 lines modifiedOffset 1007, 38 lines modified
1012 ··tags:1007 ··tags:
1013 ··-·enable_strategy1008 ··-·enable_strategy
1014 ··-·low_complexity1009 ··-·low_complexity
1015 ··-·low_disruption1010 ··-·low_disruption
1016 ··-·medium_severity1011 ··-·medium_severity
1017 ··-·no_reboot_needed1012 ··-·no_reboot_needed
1018 ··-·package_rear_installed1013 ··-·package_rear_installed
 1014 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1015 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1016 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1017 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1018 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1019 package·--add=rear
 1020 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1021 [[packages]]
 1022 name·=·"rear"
 1023 version·=·"*"
1019 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81024 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1020 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1025 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1021 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1026 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1022 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1027 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1023 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1028 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1024 include·install_rear1029 include·install_rear
  
1025 class·install_rear·{1030 class·install_rear·{
1026 ··package·{·'rear':1031 ··package·{·'rear':
1027 ····ensure·=>·'installed',1032 ····ensure·=>·'installed',
1028 ··}1033 ··}
1029 }1034 }
1030 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1031 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1032 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1033 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1034 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1035 package·--add=rear 
1036 Group  ·Updating·Software·  Group·contains·5·rules1035 Group  ·Updating·Software·  Group·contains·5·rules
1037 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1036 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1038 Oracle·Linux·7·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1037 Oracle·Linux·7·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1039 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·I\x8In\x8n·M\x8Ma\x8ai\x8in\x8n·y\x8yu\x8um\x8m·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8ra\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1038 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·g\x8gp\x8pg\x8gc\x8ch\x8he\x8ec\x8ck\x8k·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·I\x8In\x8n·M\x8Ma\x8ai\x8in\x8n·y\x8yu\x8um\x8m·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8ra\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1040 The·gpgcheck·option·controls·whether·RPM·packages'·signatures·are·always·checked·prior·to·installation.·To·configure·yum·to·check·package·signatures·before·installing·them,·ensure·the·following·line·appears·in·/etc/yum.conf·in·the·[main]·section:1039 The·gpgcheck·option·controls·whether·RPM·packages'·signatures·are·always·checked·prior·to·installation.·To·configure·yum·to·check·package·signatures·before·installing·them,·ensure·the·following·line·appears·in·/etc/yum.conf·in·the·[main]·section:
Offset 1659, 14 lines modifiedOffset 1659, 38 lines modified
1659 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"1659 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
1660 fi1660 fi
1661 fi1661 fi
  
1662 else1662 else
1663 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1663 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1664 fi1664 fi
 1665 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1666 ---
 1667 apiVersion:·machineconfiguration.openshift.io/v1
 1668 kind:·MachineConfig
 1669 spec:
 1670 ··config:
 1671 ····ignition:
 1672 ······version:·3.1.0
 1673 ····storage:
 1674 ······files:
 1675 ······-·contents:
 1676 ··········source:
 1677 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1678 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1679 ········mode:·0644
 1680 ········path:·/etc/pam.d/password-auth
 1681 ········overwrite:·true
 1682 ······-·contents:
 1683 ··········source:
 1684 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1685 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1686 ········mode:·0644
 1687 ········path:·/etc/pam.d/system-auth
 1688 ········overwrite:·true
1665 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81689 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1666 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1690 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1667 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1691 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1668 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1692 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1669 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure1693 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
1670 -·name:·Gather·the·package·facts1694 -·name:·Gather·the·package·facts
1671 ··package_facts:1695 ··package_facts:
Offset 1809, 38 lines modifiedOffset 1833, 14 lines modified
1809 ··-·PCI-DSSv4-8.3.11833 ··-·PCI-DSSv4-8.3.1
1810 ··-·configure_strategy1834 ··-·configure_strategy
1811 ··-·high_severity1835 ··-·high_severity
1812 ··-·low_complexity1836 ··-·low_complexity
1813 ··-·medium_disruption1837 ··-·medium_disruption
1814 ··-·no_empty_passwords1838 ··-·no_empty_passwords
1815 ··-·no_reboot_needed1839 ··-·no_reboot_needed
1816 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1817 --- 
1818 apiVersion:·machineconfiguration.openshift.io/v1 
1819 kind:·MachineConfig 
1820 spec: 
1821 ··config: 
1822 ····ignition: 
1823 ······version:·3.1.0 
1824 ····storage: 
1825 ······files: 
1826 ······-·contents: 
1827 ··········source: 
1828 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1829 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1830 ········mode:·0644 
Max diff block lines reached; 43411/65917 bytes (65.86%) of diff not shown.
811 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-hipaa.html
    
Offset 20796, 302 lines modifiedOffset 20796, 302 lines modified
000513b0:·2d74·6172·6765·743d·2223·6964·6d31·3331··-target="#idm131000513b0:·2d74·6172·6765·743d·2223·6964·6d31·3331··-target="#idm131
000513c0:·3939·2220·7461·6269·6e64·6578·3d22·3022··99"·tabindex="0"000513c0:·3939·2220·7461·6269·6e64·6578·3d22·3022··99"·tabindex="0"
000513d0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a000513d0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
000513e0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa000513e0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
000513f0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti000513f0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00051400:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00051400:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00051410:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00051410:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 00051420:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
 00051430:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
 00051440:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 00051450:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 00051460:·6522·2069·643d·2269·646d·3133·3139·3922··e"·id="idm13199"
 00051470:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00051480:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 00051490:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 000514a0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 000514b0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 000514c0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 000514d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 000514e0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 000514f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00051500:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 00051510:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 00051520:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 00051530:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 00051540:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t
 00051550:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00051560:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 00051570:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 00051580:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 00051590:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 000515a0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 000515b0:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm·
 000515c0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 000515d0:·6c2d·7565·6b3b·2074·6865·6e0a·0a53·5953··l-uek;·then..SYS
 000515e0:·5445·4d43·544c·5f45·5845·433d·272f·7573··TEMCTL_EXEC='/us
 000515f0:·722f·6269·6e2f·7379·7374·656d·6374·6c27··r/bin/systemctl'
 00051600:·0a69·6620·5b5b·2024·2822·2453·5953·5445··.if·[[·$("$SYSTE
 00051610:·4d43·544c·5f45·5845·4322·2069·732d·7379··MCTL_EXEC"·is-sy
 00051620:·7374·656d·2d72·756e·6e69·6e67·2920·213d··stem-running)·!=
 00051630:·2022·6f66·666c·696e·6522·205d·5d3b·2074···"offline"·]];·t
 00051640:·6865·6e0a·2020·2224·5359·5354·454d·4354··hen.··"$SYSTEMCT
 00051650:·4c5f·4558·4543·2220·7374·6f70·2027·6465··L_EXEC"·stop·'de
 00051660:·6275·672d·7368·656c·6c2e·7365·7276·6963··bug-shell.servic
00051420:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
00051430:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
00051440:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00051450:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00051460:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00051470:·6964·3d22·6964·6d31·3331·3939·223e·3c70··id="idm13199"><p 
00051480:·7265·3e3c·636f·6465·3e0a·5b63·7573·746f··re><code>.[custo 
00051490:·6d69·7a61·7469·6f6e·732e·7365·7276·6963··mizations.servic 
000514a0:·6573·5d0a·6d61·736b·6564·203d·205b·2264··es].masked·=·["d 
000514b0:·6562·7567·2d73·6865·6c6c·225d·0a3c·2f63··ebug-shell"].</c 
000514c0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
000514d0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
000514e0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
000514f0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00051500:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00051510:·6964·6d31·3332·3030·2220·7461·6269·6e64··idm13200"·tabind 
00051520:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00051530:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00051540:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00051550:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00051560:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00051570:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
00051580:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
00051590:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
000515a0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
000515b0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
000515c0:·3133·3230·3022·3e3c·7461·626c·6520·636c··13200"><table·cl 
000515d0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
000515e0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
000515f0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00051600:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00051610:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00051620:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00051630:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00051640:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
00051650:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00051660:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
00051670:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
00051680:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
00051690:·6779·3a3c·2f74·683e·3c74·643e·6469·7361··gy:</th><td>disa 
000516a0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
000516b0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
000516c0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
000516d0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
000516e0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
000516f0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q 
00051700:·7569·6574·202d·7120·6b65·726e·656c·207c··uiet·-q·kernel·| 
00051710:·7c20·7270·6d20·2d2d·7175·6965·7420·2d71··|·rpm·--quiet·-q 
00051720:·206b·6572·6e65·6c2d·7565·6b3b·2074·6865···kernel-uek;·the 
00051730:·6e0a·0a53·5953·5445·4d43·544c·5f45·5845··n..SYSTEMCTL_EXE 
00051740:·433d·272f·7573·722f·6269·6e2f·7379·7374··C='/usr/bin/syst 
00051750:·656d·6374·6c27·0a69·6620·5b5b·2024·2822··emctl'.if·[[·$(" 
00051760:·2453·5953·5445·4d43·544c·5f45·5845·4322··$SYSTEMCTL_EXEC" 
00051770:·2069·732d·7379·7374·656d·2d72·756e·6e69···is-system-runni 
00051780:·6e67·2920·213d·2022·6f66·666c·696e·6522··ng)·!=·"offline" 
00051790:·205d·5d3b·2074·6865·6e0a·2020·2224·5359···]];·then.··"$SY 
000517a0:·5354·454d·4354·4c5f·4558·4543·2220·7374··STEMCTL_EXEC"·st 
000517b0:·6f70·2027·6465·6275·672d·7368·656c·6c2e··op·'debug-shell. 
000517c0:·7365·7276·6963·6527·0a66·690a·2224·5359··service'.fi."$SY 
000517d0:·5354·454d·4354·4c5f·4558·4543·2220·6469··STEMCTL_EXEC"·di 
000517e0:·7361·626c·6520·2764·6562·7567·2d73·6865··sable·'debug-she 
000517f0:·6c6c·2e73·6572·7669·6365·270a·2224·5359··ll.service'."$SY 
00051800:·5354·454d·4354·4c5f·4558·4543·2220·6d61··STEMCTL_EXEC"·ma 
00051810:·736b·2027·6465·6275·672d·7368·656c·6c2e··sk·'debug-shell. 
00051820:·7365·7276·6963·6527·0a23·2044·6973·6162··service'.#·Disab 
00051830:·6c65·2073·6f63·6b65·7420·6163·7469·7661··le·socket·activa 
00051840:·7469·6f6e·2069·6620·7765·2068·6176·6520··tion·if·we·have· 
00051850:·6120·756e·6974·2066·696c·6520·666f·7220··a·unit·file·for· 
00051860:·6974·0a69·6620·2224·5359·5354·454d·4354··it.if·"$SYSTEMCT00051670:·6527·0a66·690a·2224·5359·5354·454d·4354··e'.fi."$SYSTEMCT
00051870:·4c5f·4558·4543·2220·2d71·206c·6973·742d··L_EXEC"·-q·list- 
00051880:·756e·6974·2d66·696c·6573·2064·6562·7567··unit-files·debug 
00051890:·2d73·6865·6c6c·2e73·6f63·6b65·743b·2074··-shell.socket;·t 
000518a0:·6865·6e0a·2020·2020·6966·205b·5b20·2428··hen.····if·[[·$(00051680:·4c5f·4558·4543·2220·6469·7361·626c·6520··L_EXEC"·disable·
 00051690:·2764·6562·7567·2d73·6865·6c6c·2e73·6572··'debug-shell.ser
 000516a0:·7669·6365·270a·2224·5359·5354·454d·4354··vice'."$SYSTEMCT
 000516b0:·4c5f·4558·4543·2220·6d61·736b·2027·6465··L_EXEC"·mask·'de
 000516c0:·6275·672d·7368·656c·6c2e·7365·7276·6963··bug-shell.servic
 000516d0:·6527·0a23·2044·6973·6162·6c65·2073·6f63··e'.#·Disable·soc
 000516e0:·6b65·7420·6163·7469·7661·7469·6f6e·2069··ket·activation·i
 000516f0:·6620·7765·2068·6176·6520·6120·756e·6974··f·we·have·a·unit
 00051700:·2066·696c·6520·666f·7220·6974·0a69·6620···file·for·it.if·
000518b0:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC00051710:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC
 00051720:·2220·2d71·206c·6973·742d·756e·6974·2d66··"·-q·list-unit-f
Max diff block lines reached; 720962/761286 bytes (94.70%) of diff not shown.
67.1 KB
html2text {}
    
Offset 1415, 18 lines modifiedOffset 1415, 14 lines modified
1415 Rule·ID:····xccdf_org.ssgproject.content_rule_service_debug-shell_disabled1415 Rule·ID:····xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
1416 ············_\x8c_\x8u_\x8i····3.4.51416 ············_\x8c_\x8u_\x8i····3.4.5
1417 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-0022351417 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
1418 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1418 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1419 ············_\x8n_\x8i_\x8s_\x8t···CM-61419 ············_\x8n_\x8i_\x8s_\x8t···CM-6
1420 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.11420 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
1421 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271421 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1422 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1423 [customizations.services] 
1424 masked·=·["debug-shell"] 
1425 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81422 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1426 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1423 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1427 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1424 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1428 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1425 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1429 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1426 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1430 #·Remediation·is·applicable·only·in·certain·platforms1427 #·Remediation·is·applicable·only·in·certain·platforms
1431 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1428 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1538, 14 lines modifiedOffset 1534, 18 lines modified
1538 ··-·NIST-800-53-CM-61534 ··-·NIST-800-53-CM-6
1539 ··-·disable_strategy1535 ··-·disable_strategy
1540 ··-·low_complexity1536 ··-·low_complexity
1541 ··-·low_disruption1537 ··-·low_disruption
1542 ··-·medium_severity1538 ··-·medium_severity
1543 ··-·no_reboot_needed1539 ··-·no_reboot_needed
1544 ··-·service_debug-shell_disabled1540 ··-·service_debug-shell_disabled
 1541 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1542 [customizations.services]
 1543 masked·=·["debug-shell"]
1545 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81544 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1546 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1545 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1547 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1546 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1548 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1547 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1549 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1548 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1550 include·disable_debug-shell1549 include·disable_debug-shell
  
Offset 2048, 14 lines modifiedOffset 2048, 38 lines modified
2048 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"2048 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
2049 fi2049 fi
2050 fi2050 fi
  
2051 else2051 else
2052 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2052 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2053 fi2053 fi
 2054 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2055 ---
 2056 apiVersion:·machineconfiguration.openshift.io/v1
 2057 kind:·MachineConfig
 2058 spec:
 2059 ··config:
 2060 ····ignition:
 2061 ······version:·3.1.0
 2062 ····storage:
 2063 ······files:
 2064 ······-·contents:
 2065 ··········source:
 2066 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 2067 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 2068 ········mode:·0644
 2069 ········path:·/etc/pam.d/password-auth
 2070 ········overwrite:·true
 2071 ······-·contents:
 2072 ··········source:
 2073 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 2074 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 2075 ········mode:·0644
 2076 ········path:·/etc/pam.d/system-auth
 2077 ········overwrite:·true
2054 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82078 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2055 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2079 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2056 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2080 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2057 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2081 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2058 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure2082 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
2059 -·name:·Gather·the·package·facts2083 -·name:·Gather·the·package·facts
2060 ··package_facts:2084 ··package_facts:
Offset 2198, 38 lines modifiedOffset 2222, 14 lines modified
2198 ··-·PCI-DSSv4-8.3.12222 ··-·PCI-DSSv4-8.3.1
2199 ··-·configure_strategy2223 ··-·configure_strategy
2200 ··-·high_severity2224 ··-·high_severity
2201 ··-·low_complexity2225 ··-·low_complexity
2202 ··-·medium_disruption2226 ··-·medium_disruption
2203 ··-·no_empty_passwords2227 ··-·no_empty_passwords
2204 ··-·no_reboot_needed2228 ··-·no_reboot_needed
2205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2206 --- 
2207 apiVersion:·machineconfiguration.openshift.io/v1 
2208 kind:·MachineConfig 
2209 spec: 
2210 ··config: 
2211 ····ignition: 
2212 ······version:·3.1.0 
2213 ····storage: 
2214 ······files: 
2215 ······-·contents: 
2216 ··········source: 
2217 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
2218 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
2219 ········mode:·0644 
2220 ········path:·/etc/pam.d/password-auth 
2221 ········overwrite:·true 
2222 ······-·contents: 
2223 ··········source: 
2224 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
2225 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
2226 ········mode:·0644 
2227 ········path:·/etc/pam.d/system-auth 
2228 ········overwrite:·true 
2229 Group  ·Restrict·Root·Logins·  Group·contains·3·rules2229 Group  ·Restrict·Root·Logins·  Group·contains·3·rules
2230 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.2230 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.
2231 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8ir\x8re\x8ec\x8ct\x8t·r\x8ro\x8oo\x8ot\x8t·L\x8Lo\x8og\x8gi\x8in\x8ns\x8s·N\x8No\x8ot\x8t·A\x8Al\x8ll\x8lo\x8ow\x8we\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2231 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8ir\x8re\x8ec\x8ct\x8t·r\x8ro\x8oo\x8ot\x8t·L\x8Lo\x8og\x8gi\x8in\x8ns\x8s·N\x8No\x8ot\x8t·A\x8Al\x8ll\x8lo\x8ow\x8we\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2232 To·further·limit·access·to·the·root·account,·administrators·can·disable·root·logins·at·the·console·by·editing·the·/etc/securetty·file.·This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does·not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the·system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous·as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in·plain·text·over·the·network.·By·default,·Oracle·Linux·7's·/etc/securetty·file·only·allows·the·root·user·to·login·at·the·console·physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the·contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this·file·by·typing·the·following·command:2232 To·further·limit·access·to·the·root·account,·administrators·can·disable·root·logins·at·the·console·by·editing·the·/etc/securetty·file.·This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does·not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the·system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous·as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in·plain·text·over·the·network.·By·default,·Oracle·Linux·7's·/etc/securetty·file·only·allows·the·root·user·to·login·at·the·console·physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the·contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this·file·by·typing·the·following·command:
2233 $·sudo·echo·>·/etc/securetty2233 $·sudo·echo·>·/etc/securetty
2234 Warning: ·This·rule·only·checks·the·/etc/securetty·file·existence·and·its·content.·If·you·need·to·restrict·user·access·using·the·/etc/securetty·file,·make·sure·the·pam_securetty.so·PAM·module·is·properly·enabled·in·relevant·PAM·files.2234 Warning: ·This·rule·only·checks·the·/etc/securetty·file·existence·and·its·content.·If·you·need·to·restrict·user·access·using·the·/etc/securetty·file,·make·sure·the·pam_securetty.so·PAM·module·is·properly·enabled·in·relevant·PAM·files.
2235 Rationale:··Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor·authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate·to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low·and·FISMA·Moderate·systems.2235 Rationale:··Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor·authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate·to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low·and·FISMA·Moderate·systems.
Offset 2934, 18 lines modifiedOffset 2934, 14 lines modified
2934 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62934 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2935 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32935 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2936 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72936 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2937 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72937 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2938 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272938 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2939 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-0201102939 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020110
2940 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221714r958498_rule2940 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-221714r958498_rule
2941 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2942 [customizations.services] 
2943 masked·=·["autofs"] 
Max diff block lines reached; 45361/68692 bytes (66.04%) of diff not shown.
1.34 MB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-ncp.html
    
Offset 16763, 222 lines modifiedOffset 16763, 222 lines modified
000417a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target000417a0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
000417b0:·3d22·2369·646d·3536·3531·2220·7461·6269··="#idm5651"·tabi000417b0:·3d22·2369·646d·3536·3531·2220·7461·6269··="#idm5651"·tabi
000417c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b000417c0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
000417d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa000417d0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
000417e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit000417e0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
000417f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·000417f0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00041800:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00041800:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00041810:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS00041810:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 00041820:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
00041820:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
00041830:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
00041840:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
00041850:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
00041860:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
00041870:·3635·3122·3e3c·7072·653e·3c63·6f64·653e··651"><pre><code> 
00041880:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
00041890:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
000418a0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
000418b0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
000418c0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
000418d0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
000418e0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
000418f0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
00041900:·3536·3532·2220·7461·6269·6e64·6578·3d22··5652"·tabindex=" 
00041910:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
00041920:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
00041930:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
00041940:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
00041950:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
00041960:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
00041970:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
00041980:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00041990:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
000419a0:·7073·6522·2069·643d·2269·646d·3536·3532··pse"·id="idm5652 
000419b0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
000419c0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
000419d0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
000419e0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
000419f0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00041a00:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
00041a10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00041a20:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00041a30:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00041a40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
00041a50:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
00041a60:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
00041a70:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
00041a80:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
00041a90:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
00041aa0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
00041ab0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
00041ac0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
00041ad0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
00041ae0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
00041af0:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm· 
00041b00:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
00041b10:·6c2d·7565·6b3b·2074·6865·6e0a·0a69·6620··l-uek;·then..if· 
00041b20:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
00041b30:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
00041b40:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·- 
00041b50:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
00041b60:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
00041b70:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
00041b80:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
00041b90:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
00041ba0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
00041bb0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
00041bc0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
00041bd0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
00041be0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
00041bf0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
00041c00:·6d35·3635·3322·2074·6162·696e·6465·783d··m5653"·tabindex= 
00041c10:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
00041c20:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
00041c30:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
00041c40:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
00041c50:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
00041c60:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
00041c70:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
00041c80:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00041830:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
00041c90:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c00041840:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
00041ca0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm00041850:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
00041cb0:·3536·3533·223e·3c74·6162·6c65·2063·6c61··5653"><table·cla00041860:·646d·3536·3531·223e·3c74·6162·6c65·2063··dm5651"><table·c
00041cc0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-00041870:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
00041cd0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo00041880:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
00041ce0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con00041890:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
00041cf0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>000418a0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
00041d00:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>000418b0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
00041d10:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr000418c0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
00041d20:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt000418d0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
00041d30:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low000418e0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
00041d40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t000418f0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00041d50:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t00041900:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
00041d60:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr00041910:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
00041d70:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg00041920:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
00041d80:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl00041930:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
00041d90:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab00041940:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
00041da0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·00041950:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
00041db0:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
00041dc0:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
00041dd0:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
00041de0:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
00041df0:·6f0a·2020·7461·6773·3a0a·2020·2d20·434a··o.··tags:.··-·CJ 
00041e00:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
00041e10:·4449·5341·2d53·5449·472d·4f4c·3037·2d30··DISA-STIG-OL07-0 
00041e20:·302d·3032·3030·3239·0a20·202d·204e·4953··0-020029.··-·NIS 
00041e30:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
00041e40:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
00041e50:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
00041e60:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
00041e70:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
00041e80:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
00041e90:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
00041ea0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
00041eb0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
00041ec0:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
00041ed0:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
00041ee0:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name 
00041ef0:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is 
00041f00:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac 
00041f10:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:· 
00041f20:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:· 
00041f30:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:·00041960:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 00041970:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 00041980:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 00041990:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q
 000419a0:·7569·6574·202d·7120·6b65·726e·656c·207c··uiet·-q·kernel·|
Max diff block lines reached; 1268188/1297472 bytes (97.74%) of diff not shown.
102 KB
html2text {}
    
Offset 539, 19 lines modifiedOffset 539, 14 lines modified
539 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3539 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
540 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5540 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
541 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199541 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
542 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029542 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
543 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79543 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
544 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2544 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
545 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule545 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule
546 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
547 [[packages]] 
548 name·=·"aide" 
549 version·=·"*" 
550 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8546 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
551 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low547 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
552 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low548 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
553 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false549 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
554 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable550 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
555 #·Remediation·is·applicable·only·in·certain·platforms551 #·Remediation·is·applicable·only·in·certain·platforms
556 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then552 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 597, 33 lines modifiedOffset 592, 38 lines modified
597 ··-·PCI-DSSv4-11.5.2592 ··-·PCI-DSSv4-11.5.2
598 ··-·enable_strategy593 ··-·enable_strategy
599 ··-·low_complexity594 ··-·low_complexity
600 ··-·low_disruption595 ··-·low_disruption
601 ··-·medium_severity596 ··-·medium_severity
602 ··-·no_reboot_needed597 ··-·no_reboot_needed
603 ··-·package_aide_installed598 ··-·package_aide_installed
 599 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 600 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 601 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 602 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 603 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 604 package·--add=aide
 605 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 606 [[packages]]
 607 name·=·"aide"
 608 version·=·"*"
604 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
605 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
606 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
607 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
608 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
609 include·install_aide614 include·install_aide
  
610 class·install_aide·{615 class·install_aide·{
611 ··package·{·'aide':616 ··package·{·'aide':
612 ····ensure·=>·'installed',617 ····ensure·=>·'installed',
613 ··}618 ··}
614 }619 }
615 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
616 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
617 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
618 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
619 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
620 package·--add=aide 
621 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*620 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
622 Run·the·following·command·to·generate·a·new·database:621 Run·the·following·command·to·generate·a·new·database:
623 $·sudo·/usr/sbin/aide·--init622 $·sudo·/usr/sbin/aide·--init
624 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:623 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
625 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz624 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
626 To·initiate·a·manual·check,·run·the·following·command:625 To·initiate·a·manual·check,·run·the·following·command:
627 $·sudo·/usr/sbin/aide·--check626 $·sudo·/usr/sbin/aide·--check
Offset 1455, 19 lines modifiedOffset 1455, 14 lines modified
1455 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.61455 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.6
1456 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61456 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1457 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.21457 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2
1458 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.11458 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1
1459 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121459 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1460 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-41460 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4
1461 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-002231461 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223
1462 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1463 [[packages]] 
1464 name·=·"dracut-fips" 
1465 version·=·"*" 
1466 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81462 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1467 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1463 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1468 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1464 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1469 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1465 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1470 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1466 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1471 #·Remediation·is·applicable·only·in·certain·platforms1467 #·Remediation·is·applicable·only·in·certain·platforms
1472 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then1468 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
Offset 1522, 33 lines modifiedOffset 1517, 38 lines modified
1522 ··-·NIST-800-53-SC-131517 ··-·NIST-800-53-SC-13
1523 ··-·enable_strategy1518 ··-·enable_strategy
1524 ··-·low_complexity1519 ··-·low_complexity
1525 ··-·low_disruption1520 ··-·low_disruption
1526 ··-·medium_severity1521 ··-·medium_severity
1527 ··-·no_reboot_needed1522 ··-·no_reboot_needed
1528 ··-·package_dracut-fips_installed1523 ··-·package_dracut-fips_installed
 1524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1525 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1526 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1527 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1528 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1529 package·--add=dracut-fips
 1530 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1531 [[packages]]
 1532 name·=·"dracut-fips"
 1533 version·=·"*"
1529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81534 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1535 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1531 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1536 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1532 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1537 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1533 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1538 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1534 include·install_dracut-fips1539 include·install_dracut-fips
  
1535 class·install_dracut-fips·{1540 class·install_dracut-fips·{
1536 ··package·{·'dracut-fips':1541 ··package·{·'dracut-fips':
1537 ····ensure·=>·'installed',1542 ····ensure·=>·'installed',
1538 ··}1543 ··}
1539 }1544 }
1540 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1541 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1542 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1543 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1544 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1545 package·--add=dracut-fips 
1546 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1545 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1547 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:1546 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:
1548 $·sudo·yum·install·dracut-fips1547 $·sudo·yum·install·dracut-fips
Max diff block lines reached; 98672/104413 bytes (94.50%) of diff not shown.
742 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-ospp.html
    
Offset 15046, 246 lines modifiedOffset 15046, 246 lines modified
0003ac50:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003ac50:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003ac60:·6964·6d36·3138·3322·2074·6162·696e·6465··idm6183"·tabinde0003ac60:·6964·6d36·3138·3322·2074·6162·696e·6465··idm6183"·tabinde
0003ac70:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003ac70:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003ac80:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003ac80:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003ac90:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003ac90:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003aca0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003aca0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003acb0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003acb0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003acc0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003acc0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0003acd0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003ace0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003acf0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003ad00:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003ad10:·7073·6522·2069·643d·2269·646d·3631·3833··pse"·id="idm6183 
0003ad20:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003ad30:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003ad40:·3d20·2264·7261·6375·742d·6669·7073·220a··=·"dracut-fips". 
0003ad50:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
0003ad60:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003ad70:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003ad80:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003ad90:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003ada0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003adb0:·2369·646d·3631·3834·2220·7461·6269·6e64··#idm6184"·tabind 
0003adc0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003add0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003ade0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003adf0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003ae00:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003ae10:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003ae20:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
0003ae30:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003ae40:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003ae50:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003ae60:·3631·3834·223e·3c74·6162·6c65·2063·6c61··6184"><table·cla 
0003ae70:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003ae80:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003ae90:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003aea0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003aeb0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003aec0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003aed0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003aee0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003aef0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003af00:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003af10:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003af20:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003af30:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003af40:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003af50:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003af60:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003af70:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003af80:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003af90:·726d·730a·6966·2028·2021·2028·205b·2022··rms.if·(·!·(·[·" 
0003afa0:·247b·636f·6e74·6169·6e65·723a·2d7d·2220··${container:-}"· 
0003afb0:·3d3d·2022·6277·7261·702d·6f73·6275·696c··==·"bwrap-osbuil 
0003afc0:·6422·205d·2029·2026·616d·703b·2661·6d70··d"·]·)·&amp;&amp 
0003afd0:·3b20·7270·6d20·2d2d·7175·6965·7420·2d71··;·rpm·--quiet·-q 
0003afe0:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·- 
0003aff0:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel 
0003b000:·2d75·656b·2029·3b20·7468·656e·0a0a·6966··-uek·);·then..if 
0003b010:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003b020:·7420·2264·7261·6375·742d·6669·7073·2220··t·"dracut-fips"· 
0003b030:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i 
0003b040:·6e73·7461·6c6c·202d·7920·2264·7261·6375··nstall·-y·"dracu 
0003b050:·742d·6669·7073·220a·6669·0a0a·656c·7365··t-fips".fi..else 
0003b060:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b070:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b080:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b090:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b0a0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b0b0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b0c0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b0d0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b0e0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b0f0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b100:·3631·3835·2220·7461·6269·6e64·6578·3d22··6185"·tabindex=" 
0003b110:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b120:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b130:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b140:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b150:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b160:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003b170:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003acd0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003b180:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003ace0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b190:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003acf0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b1a0:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm60003ad00:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
0003b1b0:·3138·3522·3e3c·7461·626c·6520·636c·6173··185"><table·clas0003ad10:·3138·3322·3e3c·7461·626c·6520·636c·6173··183"><table·clas
0003b1c0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003ad20:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b1d0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003ad30:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b1e0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003ad40:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b1f0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003ad50:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b200:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003ad60:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b210:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003ad70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b220:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003ad80:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b230:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003ad90:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b240:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003ada0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b250:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003adb0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b260:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003adc0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b270:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003add0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b280:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003ade0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003b290:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003adf0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b2a0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n0003ae00:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
0003b2b0:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
0003b2c0:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
0003b2d0:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
0003b2e0:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto0003ae10:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003ae20:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003ae30:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003ae40:·6d73·0a69·6620·2820·2120·2820·5b20·2224··ms.if·(·!·(·[·"$
 0003ae50:·7b63·6f6e·7461·696e·6572·3a2d·7d22·203d··{container:-}"·=
 0003ae60:·3d20·2262·7772·6170·2d6f·7362·7569·6c64··=·"bwrap-osbuild
 0003ae70:·2220·5d20·2920·2661·6d70·3b26·616d·703b··"·]·)·&amp;&amp;
 0003ae80:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 0003ae90:·6b65·726e·656c·207c·7c20·7270·6d20·2d2d··kernel·||·rpm·--
 0003aea0:·7175·6965·7420·2d71·206b·6572·6e65·6c2d··quiet·-q·kernel-
 0003aeb0:·7565·6b20·293b·2074·6865·6e0a·0a69·6620··uek·);·then..if·
 0003aec0:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 0003aed0:·2022·6472·6163·7574·2d66·6970·7322·203b···"dracut-fips"·;
 0003aee0:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in
 0003aef0:·7374·616c·6c20·2d79·2022·6472·6163·7574··stall·-y·"dracut
 0003af00:·2d66·6970·7322·0a66·690a·0a65·6c73·650a··-fips".fi..else.
 0003af10:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 0003af20:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 0003af30:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 0003af40:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 0003af50:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
 0003af60:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
Max diff block lines reached; 672795/705391 bytes (95.38%) of diff not shown.
53.2 KB
html2text {}
    
Offset 92, 19 lines modifiedOffset 92, 14 lines modified
92 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.692 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.6.6
93 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.693 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.13,·SR·2.6,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
94 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.294 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.6.2.1,·A.6.2.2
95 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.195 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·······CIP-003-8·R4.2,·CIP-007-3·R5.1
96 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-1296 ············_\x8n_\x8i_\x8s_\x8t···········SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
97 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-497 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.PT-4
98 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-0022398 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000033-GPOS-00014,·SRG-OS-000396-GPOS-00176,·SRG-OS-000478-GPOS-00223
99 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
100 [[packages]] 
101 name·=·"dracut-fips" 
102 version·=·"*" 
103 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
104 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low100 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
105 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low101 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
106 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false102 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
107 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable103 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
108 #·Remediation·is·applicable·only·in·certain·platforms104 #·Remediation·is·applicable·only·in·certain·platforms
109 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then105 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
Offset 159, 33 lines modifiedOffset 154, 38 lines modified
159 ··-·NIST-800-53-SC-13154 ··-·NIST-800-53-SC-13
160 ··-·enable_strategy155 ··-·enable_strategy
161 ··-·low_complexity156 ··-·low_complexity
162 ··-·low_disruption157 ··-·low_disruption
163 ··-·medium_severity158 ··-·medium_severity
164 ··-·no_reboot_needed159 ··-·no_reboot_needed
165 ··-·package_dracut-fips_installed160 ··-·package_dracut-fips_installed
 161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 166 package·--add=dracut-fips
 167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 168 [[packages]]
 169 name·=·"dracut-fips"
 170 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
171 include·install_dracut-fips176 include·install_dracut-fips
  
172 class·install_dracut-fips·{177 class·install_dracut-fips·{
173 ··package·{·'dracut-fips':178 ··package·{·'dracut-fips':
174 ····ensure·=>·'installed',179 ····ensure·=>·'installed',
175 ··}180 ··}
176 }181 }
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
182 package·--add=dracut-fips 
183 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*182 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·i\x8in\x8n·G\x8GR\x8RU\x8UB\x8B2\x82·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
184 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:183 To·ensure·FIPS·mode·is·enabled,·install·package·dracut-fips,·and·rebuild·initramfs·by·running·the·following·commands:
185 $·sudo·yum·install·dracut-fips184 $·sudo·yum·install·dracut-fips
186 dracut·-f185 dracut·-f
187 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:186 After·the·dracut·command·has·been·run,·add·the·argument·fips=1·to·the·default·GRUB·2·command·line·for·the·Linux·operating·system·in·/etc/default/grub,·in·the·manner·below:
188 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"187 GRUB_CMDLINE_LINUX="crashkernel=auto·rd.lvm.lv=VolGroup/LogVol06·rd.lvm.lv=VolGroup/lv_swap·rhgb·quiet·rd.shell=0·fips=1"
189 Finally,·rebuild·the·grub.cfg·file·by·using·the188 Finally,·rebuild·the·grub.cfg·file·by·using·the
Offset 7956, 19 lines modifiedOffset 7956, 14 lines modified
7956 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.37956 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3
7957 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)7957 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
7958 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-77958 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-7
7959 ············_\x8o_\x8s_\x8p_\x8p···········FMT_MOF_EXT.17959 ············_\x8o_\x8s_\x8p_\x8p···········FMT_MOF_EXT.1
7960 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000029-GPOS-000107960 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000029-GPOS-00010
7961 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-0100907961 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010090
7962 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255900r958402_rule7962 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255900r958402_rule
7963 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
7964 [[packages]] 
7965 name·=·"screen" 
7966 version·=·"*" 
7967 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87963 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7968 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7964 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7969 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7965 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7970 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7966 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7971 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7967 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7972 #·Remediation·is·applicable·only·in·certain·platforms7968 #·Remediation·is·applicable·only·in·certain·platforms
7973 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then7969 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 8010, 51 lines modifiedOffset 8005, 52 lines modified
8010 ··-·NIST-800-53-CM-6(a)8005 ··-·NIST-800-53-CM-6(a)
8011 ··-·enable_strategy8006 ··-·enable_strategy
8012 ··-·low_complexity8007 ··-·low_complexity
8013 ··-·low_disruption8008 ··-·low_disruption
8014 ··-·medium_severity8009 ··-·medium_severity
8015 ··-·no_reboot_needed8010 ··-·no_reboot_needed
8016 ··-·package_screen_installed8011 ··-·package_screen_installed
 8012 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 8013 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 8014 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 8015 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 8016 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 8017 package·--add=screen
 8018 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 8019 [[packages]]
 8020 name·=·"screen"
 8021 version·=·"*"
8017 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88022 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8018 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8023 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8019 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8024 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8020 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8025 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8021 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8026 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8022 include·install_screen8027 include·install_screen
  
8023 class·install_screen·{8028 class·install_screen·{
8024 ··package·{·'screen':8029 ··package·{·'screen':
8025 ····ensure·=>·'installed',8030 ····ensure·=>·'installed',
8026 ··}8031 ··}
8027 }8032 }
8028 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
8029 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
8030 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
8031 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
8032 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
8033 package·--add=screen 
8034 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·d\x8de\x8eb\x8bu\x8ug\x8g-\x8-s\x8sh\x8he\x8el\x8ll\x8l·S\x8Sy\x8ys\x8st\x8te\x8em\x8mD\x8D·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*8033 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8is\x8sa\x8ab\x8bl\x8le\x8e·d\x8de\x8eb\x8bu\x8ug\x8g-\x8-s\x8sh\x8he\x8el\x8ll\x8l·S\x8Sy\x8ys\x8st\x8te\x8em\x8mD\x8D·S\x8Se\x8er\x8rv\x8vi\x8ic\x8ce\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
8035 SystemD's·debug-shell·service·is·intended·to·diagnose·SystemD·related·boot·issues·with·various·systemctl·commands.·Once·enabled·and·following·a·system·reboot,·the·root·shell·will·be·available·on·tty9·which·is·access·by·pressing·CTRL-ALT-F9.·The·debug-shell·service·should·only·be·used·for·SystemD·related·issues·and·should·otherwise·be·disabled.8034 SystemD's·debug-shell·service·is·intended·to·diagnose·SystemD·related·boot·issues·with·various·systemctl·commands.·Once·enabled·and·following·a·system·reboot,·the·root·shell·will·be·available·on·tty9·which·is·access·by·pressing·CTRL-ALT-F9.·The·debug-shell·service·should·only·be·used·for·SystemD·related·issues·and·should·otherwise·be·disabled.
  
Max diff block lines reached; 48464/54475 bytes (88.97%) of diff not shown.
295 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-pci-dss.html
    
Offset 16629, 221 lines modifiedOffset 16629, 221 lines modified
00040f40:·6172·6765·743d·2223·6964·6d35·3635·3122··arget="#idm5651"00040f40:·6172·6765·743d·2223·6964·6d35·3635·3122··arget="#idm5651"
00040f50:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00040f50:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00040f60:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00040f60:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00040f70:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00040f70:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00040f80:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00040f80:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00040f90:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00040f90:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00040fa0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00040fa0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00040fb0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
00040fb0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
00040fc0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
00040fd0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00040fe0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00040ff0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00041000:·2269·646d·3536·3531·223e·3c70·7265·3e3c··"idm5651"><pre>< 
00041010:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
00041020:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
00041030:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
00041040:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
00041050:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
00041060:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
00041070:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00041080:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
00041090:·2223·6964·6d35·3635·3222·2074·6162·696e··"#idm5652"·tabin 
000410a0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
000410b0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
000410c0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
000410d0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
000410e0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
000410f0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
00041100:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
00041110:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00041120:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00041130:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00041140:·6d35·3635·3222·3e3c·7461·626c·6520·636c··m5652"><table·cl 
00041150:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
00041160:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00041170:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00041180:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00041190:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
000411a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
000411b0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
000411c0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
000411d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
000411e0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
000411f0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
00041200:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
00041210:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
00041220:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
00041230:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
00041240:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
00041250:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
00041260:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
00041270:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu 
00041280:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·|| 
00041290:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
000412a0:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then 
000412b0:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
000412c0:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
000412d0:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst 
000412e0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
000412f0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
00041300:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
00041310:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
00041320:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
00041330:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
00041340:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
00041350:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
00041360:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00041370:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00041380:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00041390:·3d22·2369·646d·3536·3533·2220·7461·6269··="#idm5653"·tabi 
000413a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
000413b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
000413c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
000413d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
000413e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
000413f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
00041400:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
00041410:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl00040fc0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
00041420:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00040fd0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
00041430:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00040fe0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
00041440:·3d22·6964·6d35·3635·3322·3e3c·7461·626c··="idm5653"><tabl00040ff0:·6964·3d22·6964·6d35·3635·3122·3e3c·7461··id="idm5651"><ta
00041450:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00041000:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
00041460:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00041010:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
00041470:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00041020:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
00041480:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00041030:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
00041490:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00041040:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
000414a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00041050:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
000414b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
000414c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
000414d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
000414e0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
000414f0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00041500:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St00041060:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00041070:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 00041080:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00041090:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 000410a0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 000410b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00041510:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>000410c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00041520:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>000410d0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
00041530:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co000410e0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
00041540:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
00041550:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
00041560:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
00041570:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
00041580:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
00041590:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
000415a0:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O 
000415b0:·4c30·372d·3030·2d30·3230·3032·390a·2020··L07-00-020029.·· 
000415c0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
000415d0:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
000415e0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
000415f0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
00041600:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
00041610:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
00041620:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d 
00041630:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me 
00041640:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.·· 
00041650:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need 
00041660:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a 
00041670:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..- 
00041680:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai 
00041690:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed. 
000416a0:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n 
000416b0:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st 
000416c0:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w 
Max diff block lines reached; 240581/269727 bytes (89.19%) of diff not shown.
31.2 KB
html2text {}
    
Offset 509, 19 lines modifiedOffset 509, 14 lines modified
509 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3509 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
510 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5510 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
511 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199511 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
512 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029512 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
513 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79513 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
514 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2514 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
515 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule515 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule
516 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
517 [[packages]] 
518 name·=·"aide" 
519 version·=·"*" 
520 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8516 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
521 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low517 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
522 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low518 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
523 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false519 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
524 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable520 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
525 #·Remediation·is·applicable·only·in·certain·platforms521 #·Remediation·is·applicable·only·in·certain·platforms
526 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then522 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 567, 33 lines modifiedOffset 562, 38 lines modified
567 ··-·PCI-DSSv4-11.5.2562 ··-·PCI-DSSv4-11.5.2
568 ··-·enable_strategy563 ··-·enable_strategy
569 ··-·low_complexity564 ··-·low_complexity
570 ··-·low_disruption565 ··-·low_disruption
571 ··-·medium_severity566 ··-·medium_severity
572 ··-·no_reboot_needed567 ··-·no_reboot_needed
573 ··-·package_aide_installed568 ··-·package_aide_installed
 569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 570 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 571 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 572 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 573 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 574 package·--add=aide
 575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 576 [[packages]]
 577 name·=·"aide"
 578 version·=·"*"
574 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8579 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
575 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low580 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
576 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low581 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
577 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false582 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
578 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable583 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
579 include·install_aide584 include·install_aide
  
580 class·install_aide·{585 class·install_aide·{
581 ··package·{·'aide':586 ··package·{·'aide':
582 ····ensure·=>·'installed',587 ····ensure·=>·'installed',
583 ··}588 ··}
584 }589 }
585 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
586 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
587 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
588 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
589 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
590 package·--add=aide 
591 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*590 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
592 Run·the·following·command·to·generate·a·new·database:591 Run·the·following·command·to·generate·a·new·database:
593 $·sudo·/usr/sbin/aide·--init592 $·sudo·/usr/sbin/aide·--init
594 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:593 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
595 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz594 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
596 To·initiate·a·manual·check,·run·the·following·command:595 To·initiate·a·manual·check,·run·the·following·command:
597 $·sudo·/usr/sbin/aide·--check596 $·sudo·/usr/sbin/aide·--check
Offset 8967, 14 lines modifiedOffset 8967, 38 lines modified
8967 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"8967 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
8968 fi8968 fi
8969 fi8969 fi
  
8970 else8970 else
8971 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'8971 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
8972 fi8972 fi
 8973 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 8974 ---
 8975 apiVersion:·machineconfiguration.openshift.io/v1
 8976 kind:·MachineConfig
 8977 spec:
 8978 ··config:
 8979 ····ignition:
 8980 ······version:·3.1.0
 8981 ····storage:
 8982 ······files:
 8983 ······-·contents:
 8984 ··········source:
 8985 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 8986 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 8987 ········mode:·0644
 8988 ········path:·/etc/pam.d/password-auth
 8989 ········overwrite:·true
 8990 ······-·contents:
 8991 ··········source:
 8992 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 8993 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 8994 ········mode:·0644
 8995 ········path:·/etc/pam.d/system-auth
 8996 ········overwrite:·true
8973 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88997 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8974 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8998 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8975 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium8999 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
8976 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9000 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8977 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure9001 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
8978 -·name:·Gather·the·package·facts9002 -·name:·Gather·the·package·facts
8979 ··package_facts:9003 ··package_facts:
Offset 9117, 38 lines modifiedOffset 9141, 14 lines modified
9117 ··-·PCI-DSSv4-8.3.19141 ··-·PCI-DSSv4-8.3.1
9118 ··-·configure_strategy9142 ··-·configure_strategy
9119 ··-·high_severity9143 ··-·high_severity
9120 ··-·low_complexity9144 ··-·low_complexity
9121 ··-·medium_disruption9145 ··-·medium_disruption
9122 ··-·no_empty_passwords9146 ··-·no_empty_passwords
9123 ··-·no_reboot_needed9147 ··-·no_reboot_needed
9124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9125 --- 
9126 apiVersion:·machineconfiguration.openshift.io/v1 
9127 kind:·MachineConfig 
9128 spec: 
9129 ··config: 
9130 ····ignition: 
9131 ······version:·3.1.0 
9132 ····storage: 
9133 ······files: 
9134 ······-·contents: 
9135 ··········source: 
9136 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
9137 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
9138 ········mode:·0644 
Max diff block lines reached; 10910/31886 bytes (34.22%) of diff not shown.
163 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-sap.html
    
Offset 14650, 177 lines modifiedOffset 14650, 177 lines modified
00039390:·7461·7267·6574·3d22·2369·646d·3839·3931··target="#idm899100039390:·7461·7267·6574·3d22·2369·646d·3839·3931··target="#idm8991
000393a0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r000393a0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
000393b0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari000393b0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
000393c0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals000393c0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
000393d0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa000393d0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
000393e0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr000393e0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
000393f0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat000393f0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00039400:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
00039400:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
00039410:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
00039420:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00039430:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
00039440:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
00039450:·3d22·6964·6d38·3939·3122·3e3c·7072·653e··="idm8991"><pre> 
00039460:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
00039470:·735d·5d0a·6e61·6d65·203d·2022·676c·6962··s]].name·=·"glib 
00039480:·6322·0a76·6572·7369·6f6e·203d·2022·2a22··c".version·=·"*" 
00039490:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
000394a0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
000394b0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
000394c0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
000394d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
000394e0:·743d·2223·6964·6d38·3939·3222·2074·6162··t="#idm8992"·tab 
000394f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
00039500:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
00039510:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
00039520:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
00039530:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
00039540:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
00039550:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
00039560:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
00039570:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00039580:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00039590:·6964·6d38·3939·3222·3e3c·7461·626c·6520··idm8992"><table· 
000395a0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
000395b0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
000395c0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
000395d0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
000395e0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
000395f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00039600:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00039610:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00039620:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00039630:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
00039640:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
00039650:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00039660:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
00039670:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
00039680:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
00039690:·3e0a·6966·2021·2072·706d·202d·7120·2d2d··>.if·!·rpm·-q·-- 
000396a0:·7175·6965·7420·2267·6c69·6263·2220·3b20··quiet·"glibc"·;· 
000396b0:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins 
000396c0:·7461·6c6c·202d·7920·2267·6c69·6263·220a··tall·-y·"glibc". 
000396d0:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
000396e0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
000396f0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00039700:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00039710:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00039720:·6765·743d·2223·6964·6d38·3939·3322·2074··get="#idm8993"·t 
00039730:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00039740:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
00039750:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
00039760:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
00039770:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
00039780:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
00039790:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
000397a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div00039410:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
000397b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co00039420:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
000397c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00039430:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
000397d0:·2069·643d·2269·646d·3839·3933·223e·3c74···id="idm8993"><t00039440:·2069·643d·2269·646d·3839·3931·223e·3c74···id="idm8991"><t
000397e0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00039450:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
000397f0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00039460:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
00039800:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00039470:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
00039810:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00039480:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
00039820:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi00039490:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
00039830:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<000394a0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
00039840:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th000394b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00039850:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th000394c0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
00039860:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t000394d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00039870:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot000394e0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
00039880:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<000394f0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 00039500:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00039510:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00039520:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00039530:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00039540:·3c63·6f64·653e·0a69·6620·2120·7270·6d20··<code>.if·!·rpm·
 00039550:·2d71·202d·2d71·7569·6574·2022·676c·6962··-q·--quiet·"glib
 00039560:·6322·203b·2074·6865·6e0a·2020·2020·7975··c"·;·then.····yu
 00039570:·6d20·696e·7374·616c·6c20·2d79·2022·676c··m·install·-y·"gl
 00039580:·6962·6322·0a66·690a·3c2f·636f·6465·3e3c··ibc".fi.</code><
 00039590:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 000395a0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 000395b0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 000395c0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 000395d0:·612d·7461·7267·6574·3d22·2369·646d·3839··a-target="#idm89
 000395e0:·3932·2220·7461·6269·6e64·6578·3d22·3022··92"·tabindex="0"
 000395f0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
 00039600:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
 00039610:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
 00039620:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
 00039630:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 00039640:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
 00039650:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00039660:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00039670:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00039680:·6170·7365·2220·6964·3d22·6964·6d38·3939··apse"·id="idm899
 00039690:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class=
 000396a0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 000396b0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 000396c0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 000396d0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 000396e0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 000396f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00039700:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 00039710:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00039720:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 00039730:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 00039740:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 00039750:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 00039760:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 00039770:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 00039780:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
 00039790:·653a·2045·6e73·7572·6520·676c·6962·6320··e:·Ensure·glibc·
 000397a0:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p
 000397b0:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name
 000397c0:·3a20·676c·6962·630a·2020·2020·7374·6174··:·glibc.····stat
 000397d0:·653a·2070·7265·7365·6e74·0a20·2074·6167··e:·present.··tag
Max diff block lines reached; 130132/153206 bytes (84.94%) of diff not shown.
13.1 KB
html2text {}
    
Offset 64, 19 lines modifiedOffset 64, 14 lines modified
64 The·package·glibc·is·installed·on·Linux·by·default,·but·the·glibc·version·might·not·be·sufficient·for·SAP.·Please·refer·to·SAP·note·of·your·Linux·version·for·the64 The·package·glibc·is·installed·on·Linux·by·default,·but·the·glibc·version·might·not·be·sufficient·for·SAP.·Please·refer·to·SAP·note·of·your·Linux·version·for·the
65 minimum·requirement·on·glibc.·The·glibc·package·can·be·installed·with·the·following·command:65 minimum·requirement·on·glibc.·The·glibc·package·can·be·installed·with·the·following·command:
66 $·sudo·yum·install·glibc66 $·sudo·yum·install·glibc
67 Rationale:·The·glibc·package·contains·standard·C·and·math·libraries·used·by·multiple·programs·on·Linux.·The·glibc·shipped·with·first·release·of·each·major·Linux67 Rationale:·The·glibc·package·contains·standard·C·and·math·libraries·used·by·multiple·programs·on·Linux.·The·glibc·shipped·with·first·release·of·each·major·Linux
68 ···········version·is·often·not·sufficient·for·SAP.·An·update·is·required·after·the·first·OS·installation.68 ···········version·is·often·not·sufficient·for·SAP.·An·update·is·required·after·the·first·OS·installation.
69 Severity: ·medium69 Severity: ·medium
70 Rule·ID:···xccdf_org.ssgproject.content_rule_package_glibc_installed70 Rule·ID:···xccdf_org.ssgproject.content_rule_package_glibc_installed
71 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
72 [[packages]] 
73 name·=·"glibc" 
74 version·=·"*" 
75 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x871 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
76 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low72 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
77 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low73 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
78 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false74 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
79 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable75 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
80 if·!·rpm·-q·--quiet·"glibc"·;·then76 if·!·rpm·-q·--quiet·"glibc"·;·then
Offset 94, 46 lines modifiedOffset 89, 46 lines modified
94 ··tags:89 ··tags:
95 ··-·enable_strategy90 ··-·enable_strategy
96 ··-·low_complexity91 ··-·low_complexity
97 ··-·low_disruption92 ··-·low_disruption
98 ··-·medium_severity93 ··-·medium_severity
99 ··-·no_reboot_needed94 ··-·no_reboot_needed
100 ··-·package_glibc_installed95 ··-·package_glibc_installed
 96 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 97 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 98 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 99 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 100 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 101 package·--add=glibc
 102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 103 [[packages]]
 104 name·=·"glibc"
 105 version·=·"*"
101 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
102 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
103 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
104 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
105 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
106 include·install_glibc111 include·install_glibc
  
107 class·install_glibc·{112 class·install_glibc·{
108 ··package·{·'glibc':113 ··package·{·'glibc':
109 ····ensure·=>·'installed',114 ····ensure·=>·'installed',
110 ··}115 ··}
111 }116 }
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
117 package·--add=glibc 
118 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·u\x8uu\x8ui\x8id\x8dd\x8d·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*117 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·u\x8uu\x8ui\x8id\x8dd\x8d·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
119 The·package·uuidd·is·not·installed·on·normal·Linux·distribution·by·default.·Applications·require·this·package·to·avoid·database·inconsistences·caused·by·duplicated118 The·package·uuidd·is·not·installed·on·normal·Linux·distribution·by·default.·Applications·require·this·package·to·avoid·database·inconsistences·caused·by·duplicated
120 UUIDs.·Especially·in·banking·services·with·SAP·where·massive·UUIDs·are·created·in·a·short·time·period,·it·is·important·to·install·the·package·uuidd.·More·information119 UUIDs.·Especially·in·banking·services·with·SAP·where·massive·UUIDs·are·created·in·a·short·time·period,·it·is·important·to·install·the·package·uuidd.·More·information
121 can·be·found·in·SAP·note·1391070.·The·uuidd·package·can·be·installed·with·the·following·command:120 can·be·found·in·SAP·note·1391070.·The·uuidd·package·can·be·installed·with·the·following·command:
122 $·sudo·yum·install·uuidd121 $·sudo·yum·install·uuidd
123 Rationale:·The·uuidd·package·contains·a·userspace·daemon·(uuidd)·which·is·used·to·generate·unique·identifiers·even·at·very·high·rates·on·SMP·systems.122 Rationale:·The·uuidd·package·contains·a·userspace·daemon·(uuidd)·which·is·used·to·generate·unique·identifiers·even·at·very·high·rates·on·SMP·systems.
124 Severity: ·medium123 Severity: ·medium
125 Rule·ID:···xccdf_org.ssgproject.content_rule_package_uuidd_installed124 Rule·ID:···xccdf_org.ssgproject.content_rule_package_uuidd_installed
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
127 [[packages]] 
128 name·=·"uuidd" 
129 version·=·"*" 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
135 if·!·rpm·-q·--quiet·"uuidd"·;·then130 if·!·rpm·-q·--quiet·"uuidd"·;·then
Offset 151, 33 lines modifiedOffset 146, 38 lines modified
151 ··tags:146 ··tags:
152 ··-·enable_strategy147 ··-·enable_strategy
153 ··-·low_complexity148 ··-·low_complexity
154 ··-·low_disruption149 ··-·low_disruption
155 ··-·medium_severity150 ··-·medium_severity
156 ··-·no_reboot_needed151 ··-·no_reboot_needed
157 ··-·package_uuidd_installed152 ··-·package_uuidd_installed
 153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 154 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 155 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 156 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 157 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 158 package·--add=uuidd
 159 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 160 [[packages]]
 161 name·=·"uuidd"
 162 version·=·"*"
158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
163 include·install_uuidd168 include·install_uuidd
  
164 class·install_uuidd·{169 class·install_uuidd·{
165 ··package·{·'uuidd':170 ··package·{·'uuidd':
166 ····ensure·=>·'installed',171 ····ensure·=>·'installed',
167 ··}172 ··}
168 }173 }
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·--add=uuidd 
175 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·O\x8On\x8nl\x8ly\x8y·s\x8si\x8id\x8da\x8ad\x8dm\x8m·a\x8an\x8nd\x8d·o\x8or\x8ra\x8as\x8si\x8id\x8d/\x8/o\x8or\x8ra\x8ac\x8cl\x8le\x8e·U\x8Us\x8se\x8er\x8r·A\x8Ac\x8cc\x8co\x8ou\x8un\x8nt\x8ts\x8s·E\x8Ex\x8xi\x8is\x8st\x8t·o\x8on\x8n·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*174 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·O\x8On\x8nl\x8ly\x8y·s\x8si\x8id\x8da\x8ad\x8dm\x8m·a\x8an\x8nd\x8d·o\x8or\x8ra\x8as\x8si\x8id\x8d/\x8/o\x8or\x8ra\x8ac\x8cl\x8le\x8e·U\x8Us\x8se\x8er\x8r·A\x8Ac\x8cc\x8co\x8ou\x8un\x8nt\x8ts\x8s·E\x8Ex\x8xi\x8is\x8st\x8t·o\x8on\x8n·O\x8Op\x8pe\x8er\x8ra\x8at\x8ti\x8in\x8ng\x8g·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
176 SAP·tends·to·use·the·server·or·virtual·machine·exclusively.·There·should·be·only·SAP·system·users·sidadm·and·orasid·that·exist·on·the·operating·system·(or·virtual175 SAP·tends·to·use·the·server·or·virtual·machine·exclusively.·There·should·be·only·SAP·system·users·sidadm·and·orasid·that·exist·on·the·operating·system·(or·virtual
177 machine).·If·SAP·Host·Agent·is·installed,·the·user·sapadm·must·exist·too.·With·Oracle·Database·using·oracle·user,·the·user·oracle·should·exist·as·well.·While·SID·is176 machine).·If·SAP·Host·Agent·is·installed,·the·user·sapadm·must·exist·too.·With·Oracle·Database·using·oracle·user,·the·user·oracle·should·exist·as·well.·While·SID·is
178 the·SAP·System·ID,·which·is·always·three·alphanumeric·characters·in·upper·case,·beginning·with·an·alphabetic·character,·the·user·names·sidadm·and·orasid·are·in·lower177 the·SAP·System·ID,·which·is·always·three·alphanumeric·characters·in·upper·case,·beginning·with·an·alphabetic·character,·the·user·names·sidadm·and·orasid·are·in·lower
179 case.178 case.
  
180 Besides·the·above·SAP·users·that·are·automatically·detected,·other·operating·system·users·can·be·customized·in·the·refine·value·variable179 Besides·the·above·SAP·users·that·are·automatically·detected,·other·operating·system·users·can·be·customized·in·the·refine·value·variable
Offset 426, 33 lines modifiedOffset 426, 33 lines modified
426 ··-·PCI-DSSv4-2.2.4426 ··-·PCI-DSSv4-2.2.4
427 ··-·disable_strategy427 ··-·disable_strategy
Max diff block lines reached; 7681/13430 bytes (57.19%) of diff not shown.
486 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-standard.html
    
Offset 19584, 857 lines modifiedOffset 19584, 857 lines modified
0004c7f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0004c7f0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0004c800:·6d31·3537·3031·2220·7461·6269·6e64·6578··m15701"·tabindex0004c800:·6d31·3537·3031·2220·7461·6269·6e64·6578··m15701"·tabindex
0004c810:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0004c810:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0004c820:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0004c820:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0004c830:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0004c830:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0004c840:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0004c840:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0004c850:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0004c850:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0004c860:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl0004c860:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern
 0004c870:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·...
 0004c880:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0004c890:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0004c870:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a 
0004c880:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0004c890:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0004c8a0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0004c8b0:·6d31·3537·3031·223e·3c74·6162·6c65·2063··m15701"><table·c 
0004c8c0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0004c8d0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0004c8e0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0004c8f0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0004c900:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0004c910:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0004c920:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0004c930:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m 
0004c940:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr>< 
0004c950:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0004c960:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0004c970:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0004c980:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0004c990:·636f·6e66·6967·7572·653c·2f74·643e·3c2f··configure</td></ 
0004c9a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0004c9b0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4761··<code>-·name:·Ga 
0004c9c0:·7468·6572·2074·6865·2070·6163·6b61·6765··ther·the·package 
0004c9d0:·2066·6163·7473·0a20·2070·6163·6b61·6765···facts.··package 
0004c9e0:·5f66·6163·7473·3a0a·2020·2020·6d61·6e61··_facts:.····mana 
0004c9f0:·6765·723a·2061·7574·6f0a·2020·7461·6773··ger:·auto.··tags 
0004ca00:·3a0a·2020·2d20·434a·4953·2d35·2e35·2e32··:.··-·CJIS-5.5.2 
0004ca10:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O 
0004ca20:·4c30·372d·3030·2d30·3130·3239·300a·2020··L07-00-010290.·· 
0004ca30:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-3 
0004ca40:·2e31·2e31·0a20·202d·204e·4953·542d·3830··.1.1.··-·NIST-80 
0004ca50:·302d·3137·312d·332e·312e·350a·2020·2d20··0-171-3.1.5.··-· 
0004ca60:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0004ca70:·2861·290a·2020·2d20·4e49·5354·2d38·3030··(a).··-·NIST-800 
0004ca80:·2d35·332d·4941·2d35·2831·2928·6129·0a20··-53-IA-5(1)(a).· 
0004ca90:·202d·204e·4953·542d·3830·302d·3533·2d49···-·NIST-800-53-I 
0004caa0:·412d·3528·6329·0a20·202d·2050·4349·2d44··A-5(c).··-·PCI-D 
0004cab0:·5353·2d52·6571·2d38·2e32·2e33·0a20·202d··SS-Req-8.2.3.··- 
0004cac0:·2050·4349·2d44·5353·7634·2d38·2e33·0a20···PCI-DSSv4-8.3.· 
0004cad0:·202d·2050·4349·2d44·5353·7634·2d38·2e33···-·PCI-DSSv4-8.3 
0004cae0:·2e31·0a20·202d·2063·6f6e·6669·6775·7265··.1.··-·configure 
0004caf0:·5f73·7472·6174·6567·790a·2020·2d20·6869··_strategy.··-·hi 
0004cb00:·6768·5f73·6576·6572·6974·790a·2020·2d20··gh_severity.··-· 
0004cb10:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.· 
0004cb20:·202d·206d·6564·6975·6d5f·6469·7372·7570···-·medium_disrup 
0004cb30:·7469·6f6e·0a20·202d·206e·6f5f·656d·7074··tion.··-·no_empt 
0004cb40:·795f·7061·7373·776f·7264·730a·2020·2d20··y_passwords.··-· 
0004cb50:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0004cb60:·0a0a·2d20·6e61·6d65·3a20·5072·6576·656e··..-·name:·Preven 
0004cb70:·7420·4c6f·6769·6e20·746f·2041·6363·6f75··t·Login·to·Accou 
0004cb80:·6e74·7320·5769·7468·2045·6d70·7479·2050··nts·With·Empty·P 
0004cb90:·6173·7377·6f72·6420·2d20·4368·6563·6b20··assword·-·Check· 
0004cba0:·6966·2073·7973·7465·6d20·7265·6c69·6573··if·system·relies 
0004cbb0:·206f·6e0a·2020·2020·6175·7468·7365·6c65···on.····authsele 
0004cbc0:·6374·0a20·2061·6e73·6962·6c65·2e62·7569··ct.··ansible.bui 
0004cbd0:·6c74·696e·2e73·7461·743a·0a20·2020·2070··ltin.stat:.····p 
0004cbe0:·6174·683a·202f·7573·722f·6269·6e2f·6175··ath:·/usr/bin/au 
0004cbf0:·7468·7365·6c65·6374·0a20·2072·6567·6973··thselect.··regis 
0004cc00:·7465·723a·2072·6573·756c·745f·6175·7468··ter:·result_auth 
0004cc10:·7365·6c65·6374·5f70·7265·7365·6e74·0a20··select_present.· 
0004cc20:·2077·6865·6e3a·2028·226b·6572·6e65·6c22···when:·("kernel" 
0004cc30:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
0004cc40:·732e·7061·636b·6167·6573·206f·7220·226b··s.packages·or·"k 
0004cc50:·6572·6e65·6c2d·7565·6b22·2069·6e20·616e··ernel-uek"·in·an 
0004cc60:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack 
0004cc70:·6167·6573·290a·2020·7461·6773·3a0a·2020··ages).··tags:.·· 
0004cc80:·2d20·434a·4953·2d35·2e35·2e32·0a20·202d··-·CJIS-5.5.2.··- 
0004cc90:·2044·4953·412d·5354·4947·2d4f·4c30·372d···DISA-STIG-OL07- 
0004cca0:·3030·2d30·3130·3239·300a·2020·2d20·4e49··00-010290.··-·NI 
0004ccb0:·5354·2d38·3030·2d31·3731·2d33·2e31·2e31··ST-800-171-3.1.1 
0004ccc0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17 
0004ccd0:·312d·332e·312e·350a·2020·2d20·4e49·5354··1-3.1.5.··-·NIST 
0004cce0:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a). 
0004ccf0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
0004cd00:·4941·2d35·2831·2928·6129·0a20·202d·204e··IA-5(1)(a).··-·N 
0004cd10:·4953·542d·3830·302d·3533·2d49·412d·3528··IST-800-53-IA-5( 
0004cd20:·6329·0a20·202d·2050·4349·2d44·5353·2d52··c).··-·PCI-DSS-R 
0004cd30:·6571·2d38·2e32·2e33·0a20·202d·2050·4349··eq-8.2.3.··-·PCI 
0004cd40:·2d44·5353·7634·2d38·2e33·0a20·202d·2050··-DSSv4-8.3.··-·P 
0004cd50:·4349·2d44·5353·7634·2d38·2e33·2e31·0a20··CI-DSSv4-8.3.1.· 
0004cd60:·202d·2063·6f6e·6669·6775·7265·5f73·7472···-·configure_str 
0004cd70:·6174·6567·790a·2020·2d20·6869·6768·5f73··ategy.··-·high_s 
0004cd80:·6576·6572·6974·790a·2020·2d20·6c6f·775f··everity.··-·low_ 
0004cd90:·636f·6d70·6c65·7869·7479·0a20·202d·206d··complexity.··-·m 
0004cda0:·6564·6975·6d5f·6469·7372·7570·7469·6f6e··edium_disruption 
0004cdb0:·0a20·202d·206e·6f5f·656d·7074·795f·7061··.··-·no_empty_pa 
0004cdc0:·7373·776f·7264·730a·2020·2d20·6e6f·5f72··sswords.··-·no_r 
0004cdd0:·6562·6f6f·745f·6e65·6564·6564·0a0a·2d20··eboot_needed..-· 
0004cde0:·6e61·6d65·3a20·5072·6576·656e·7420·4c6f··name:·Prevent·Lo 
0004cdf0:·6769·6e20·746f·2041·6363·6f75·6e74·7320··gin·to·Accounts· 
0004ce00:·5769·7468·2045·6d70·7479·2050·6173·7377··With·Empty·Passw 
0004ce10:·6f72·6420·2d20·5265·6d65·6469·6174·6520··ord·-·Remediate· 
0004ce20:·7573·696e·6720·6175·7468·7365·6c65·6374··using·authselect 
0004ce30:·0a20·2062·6c6f·636b·3a0a·0a20·202d·206e··.··block:..··-·n 
0004ce40:·616d·653a·2050·7265·7665·6e74·204c·6f67··ame:·Prevent·Log 
0004ce50:·696e·2074·6f20·4163·636f·756e·7473·2057··in·to·Accounts·W 
0004ce60:·6974·6820·456d·7074·7920·5061·7373·776f··ith·Empty·Passwo 
0004ce70:·7264·202d·2043·6865·636b·2069·6e74·6567··rd·-·Check·integ 
0004ce80:·7269·7479·206f·6620·6175·7468·7365·6c65··rity·of·authsele 
0004ce90:·6374·0a20·2020·2020·2063·7572·7265·6e74··ct.······current 
0004cea0:·2070·726f·6669·6c65·0a20·2020·2061·6e73···profile.····ans 
0004ceb0:·6962·6c65·2e62·7569·6c74·696e·2e63·6f6d··ible.builtin.com 
0004cec0:·6d61·6e64·3a0a·2020·2020·2020·636d·643a··mand:.······cmd: 
0004ced0:·2061·7574·6873·656c·6563·7420·6368·6563···authselect·chec 
0004cee0:·6b0a·2020·2020·7265·6769·7374·6572·3a20··k.····register:· 
0004cef0:·7265·7375·6c74·5f61·7574·6873·656c·6563··result_authselec 
0004cf00:·745f·6368·6563·6b5f·636d·640a·2020·2020··t_check_cmd.···· 
0004cf10:·6368·616e·6765·645f·7768·656e·3a20·6661··changed_when:·fa 
0004cf20:·6c73·650a·2020·2020·6661·696c·6564·5f77··lse.····failed_w 
0004cf30:·6865·6e3a·2066·616c·7365·0a0a·2020·2d20··hen:·false..··-· 
0004cf40:·6e61·6d65·3a20·5072·6576·656e·7420·4c6f··name:·Prevent·Lo 
0004cf50:·6769·6e20·746f·2041·6363·6f75·6e74·7320··gin·to·Accounts· 
0004cf60:·5769·7468·2045·6d70·7479·2050·6173·7377··With·Empty·Passw 
0004cf70:·6f72·6420·2d20·496e·666f·726d·6174·6976··ord·-·Informativ 
0004cf80:·6520·6d65·7373·6167·6520·6261·7365·640a··e·message·based. 
0004cf90:·2020·2020·2020·6f6e·2074·6865·2061·7574········on·the·aut 
0004cfa0:·6873·656c·6563·7420·696e·7465·6772·6974··hselect·integrit 
Max diff block lines reached; 410526/458578 bytes (89.52%) of diff not shown.
38.4 KB
html2text {}
    
Offset 983, 14 lines modifiedOffset 983, 38 lines modified
983 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"983 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
984 fi984 fi
985 fi985 fi
  
986 else986 else
987 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'987 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
988 fi988 fi
 989 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 990 ---
 991 apiVersion:·machineconfiguration.openshift.io/v1
 992 kind:·MachineConfig
 993 spec:
 994 ··config:
 995 ····ignition:
 996 ······version:·3.1.0
 997 ····storage:
 998 ······files:
 999 ······-·contents:
 1000 ··········source:
 1001 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1002 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1003 ········mode:·0644
 1004 ········path:·/etc/pam.d/password-auth
 1005 ········overwrite:·true
 1006 ······-·contents:
 1007 ··········source:
 1008 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1009 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1010 ········mode:·0644
 1011 ········path:·/etc/pam.d/system-auth
 1012 ········overwrite:·true
989 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81013 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
990 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1014 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
991 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1015 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
992 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1016 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
993 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure1017 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
994 -·name:·Gather·the·package·facts1018 -·name:·Gather·the·package·facts
995 ··package_facts:1019 ··package_facts:
Offset 1133, 38 lines modifiedOffset 1157, 14 lines modified
1133 ··-·PCI-DSSv4-8.3.11157 ··-·PCI-DSSv4-8.3.1
1134 ··-·configure_strategy1158 ··-·configure_strategy
1135 ··-·high_severity1159 ··-·high_severity
1136 ··-·low_complexity1160 ··-·low_complexity
1137 ··-·medium_disruption1161 ··-·medium_disruption
1138 ··-·no_empty_passwords1162 ··-·no_empty_passwords
1139 ··-·no_reboot_needed1163 ··-·no_reboot_needed
1140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1141 --- 
1142 apiVersion:·machineconfiguration.openshift.io/v1 
1143 kind:·MachineConfig 
1144 spec: 
1145 ··config: 
1146 ····ignition: 
1147 ······version:·3.1.0 
1148 ····storage: 
1149 ······files: 
1150 ······-·contents: 
1151 ··········source: 
1152 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1153 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1154 ········mode:·0644 
1155 ········path:·/etc/pam.d/password-auth 
1156 ········overwrite:·true 
1157 ······-·contents: 
1158 ··········source: 
1159 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1160 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1161 ········mode:·0644 
1162 ········path:·/etc/pam.d/system-auth 
1163 ········overwrite:·true 
1164 Group  ·Secure·Session·Configuration·Files·for·Login·Accounts·  Group·contains·1·group·and·2·rules1164 Group  ·Secure·Session·Configuration·Files·for·Login·Accounts·  Group·contains·1·group·and·2·rules
1165 _\x8[_\x8r_\x8e_\x8f_\x8]  ·When·a·user·logs·into·a·Unix·account,·the·system·configures·the·user's·session·by·reading·a·number·of·files.·Many·of·these·files·are·located·in·the·user's·home·directory,·and·may·have·weak·permissions·as·a·result·of·user·error·or·misconfiguration.·If·an·attacker·can·modify·or·even·read·certain·types·of·account·configuration·information,·they·can·often·gain·full·access·to·the·affected·user's·account.·Therefore,·it·is·important·to·test·and·correct·configuration·file·permissions·for·interactive·accounts,·particularly·those·of·privileged·users·such·as·root·or·system·administrators.1165 _\x8[_\x8r_\x8e_\x8f_\x8]  ·When·a·user·logs·into·a·Unix·account,·the·system·configures·the·user's·session·by·reading·a·number·of·files.·Many·of·these·files·are·located·in·the·user's·home·directory,·and·may·have·weak·permissions·as·a·result·of·user·error·or·misconfiguration.·If·an·attacker·can·modify·or·even·read·certain·types·of·account·configuration·information,·they·can·often·gain·full·access·to·the·affected·user's·account.·Therefore,·it·is·important·to·test·and·correct·configuration·file·permissions·for·interactive·accounts,·particularly·those·of·privileged·users·such·as·root·or·system·administrators.
1166 Group  ·Ensure·that·No·Dangerous·Directories·Exist·in·Root's·Path·  Group·contains·2·rules1166 Group  ·Ensure·that·No·Dangerous·Directories·Exist·in·Root's·Path·  Group·contains·2·rules
1167 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·active·path·of·the·root·account·can·be·obtained·by·starting·a·new·root·shell·and·running:1167 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·active·path·of·the·root·account·can·be·obtained·by·starting·a·new·root·shell·and·running:
1168 #·echo·$PATH1168 #·echo·$PATH
1169 This·will·produce·a·colon-separated·list·of·directories·in·the·path.1169 This·will·produce·a·colon-separated·list·of·directories·in·the·path.
  
Offset 1259, 19 lines modifiedOffset 1259, 14 lines modified
1259 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.312(a)(2)(ii)1259 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.312(a)(2)(ii)
1260 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.41260 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4
1261 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91261 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1262 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11262 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1263 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1263 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1264 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11264 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1265 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-002271265 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
1266 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1267 [[packages]] 
1268 name·=·"rsyslog" 
1269 version·=·"*" 
1270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81266 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1271 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1267 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1272 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1268 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1273 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1269 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1274 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1270 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1275 #·Remediation·is·applicable·only·in·certain·platforms1271 #·Remediation·is·applicable·only·in·certain·platforms
1276 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1272 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1309, 33 lines modifiedOffset 1304, 38 lines modified
1309 ··-·NIST-800-53-CM-6(a)1304 ··-·NIST-800-53-CM-6(a)
1310 ··-·enable_strategy1305 ··-·enable_strategy
1311 ··-·low_complexity1306 ··-·low_complexity
1312 ··-·low_disruption1307 ··-·low_disruption
1313 ··-·medium_severity1308 ··-·medium_severity
1314 ··-·no_reboot_needed1309 ··-·no_reboot_needed
1315 ··-·package_rsyslog_installed1310 ··-·package_rsyslog_installed
 1311 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1312 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1313 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1314 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1315 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1316 package·--add=rsyslog
 1317 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1318 [[packages]]
 1319 name·=·"rsyslog"
 1320 version·=·"*"
1316 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81321 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1317 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1322 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1318 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1323 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1319 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1324 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1320 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1325 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1321 include·install_rsyslog1326 include·install_rsyslog
  
1322 class·install_rsyslog·{1327 class·install_rsyslog·{
1323 ··package·{·'rsyslog':1328 ··package·{·'rsyslog':
1324 ····ensure·=>·'installed',1329 ····ensure·=>·'installed',
Max diff block lines reached; 18204/39257 bytes (46.37%) of diff not shown.
576 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-stig.html
    
Offset 17388, 222 lines modifiedOffset 17388, 222 lines modified
00043eb0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00043eb0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00043ec0:·2223·6964·6d35·3635·3122·2074·6162·696e··"#idm5651"·tabin00043ec0:·2223·6964·6d35·3635·3122·2074·6162·696e··"#idm5651"·tabin
00043ed0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00043ed0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00043ee0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00043ee0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00043ef0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00043ef0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00043f00:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00043f00:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00043f10:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00043f10:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00043f20:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB00043f20:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 00043f30:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
00043f30:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
00043f40:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00043f50:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00043f60:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00043f70:·6c61·7073·6522·2069·643d·2269·646d·3536··lapse"·id="idm56 
00043f80:·3531·223e·3c70·7265·3e3c·636f·6465·3e0a··51"><pre><code>. 
00043f90:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
00043fa0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
00043fb0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
00043fc0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00043fd0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00043fe0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00043ff0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00044000:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm5 
00044010:·3635·3222·2074·6162·696e·6465·783d·2230··652"·tabindex="0 
00044020:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
00044030:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
00044040:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
00044050:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
00044060:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
00044070:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
00044080:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
00044090:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
000440a0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
000440b0:·7365·2220·6964·3d22·6964·6d35·3635·3222··se"·id="idm5652" 
000440c0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
000440d0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
000440e0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
000440f0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00044100:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00044110:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00044120:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00044130:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00044140:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00044150:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00044160:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
00044170:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
00044180:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00044190:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
000441a0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
000441b0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
000441c0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
000441d0:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
000441e0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
000441f0:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
00044200:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·- 
00044210:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel 
00044220:·2d75·656b·3b20·7468·656e·0a0a·6966·2021··-uek;·then..if·! 
00044230:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
00044240:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
00044250:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y 
00044260:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
00044270:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
00044280:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
00044290:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
000442a0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
000442b0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
000442c0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
000442d0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
000442e0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
000442f0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
00044300:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
00044310:·3536·3533·2220·7461·6269·6e64·6578·3d22··5653"·tabindex=" 
00044320:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
00044330:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
00044340:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
00044350:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
00044360:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
00044370:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
00044380:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
00044390:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p00043f40:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
000443a0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co00043f50:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
000443b0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm500043f60:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
000443c0:·3635·3322·3e3c·7461·626c·6520·636c·6173··653"><table·clas00043f70:·6d35·3635·3122·3e3c·7461·626c·6520·636c··m5651"><table·cl
000443d0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s00043f80:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
000443e0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor00043f90:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
000443f0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond00043fa0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
00044400:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C00043fb0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
00044410:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><00043fc0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
00044420:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00043fd0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
00044430:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti00043fe0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
00044440:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<00043ff0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
00044450:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00044000:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
00044460:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td00044010:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
00044470:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>00044020:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
00044480:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy00044030:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
00044490:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable00044040:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
000444a0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl00044050:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
000444b0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n00044060:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
000444c0:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
000444d0:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
000444e0:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
000444f0:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto 
00044500:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI 
00044510:·532d·352e·3130·2e31·2e33·0a20·202d·2044··S-5.10.1.3.··-·D 
00044520:·4953·412d·5354·4947·2d4f·4c30·372d·3030··ISA-STIG-OL07-00 
00044530:·2d30·3230·3032·390a·2020·2d20·4e49·5354··-020029.··-·NIST 
00044540:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a). 
00044550:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req- 
00044560:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS 
00044570:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en 
00044580:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.·· 
00044590:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity 
000445a0:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt 
000445b0:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s 
000445c0:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r 
000445d0:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··- 
000445e0:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in 
000445f0:·7374·616c·6c65·640a·0a2d·206e·616d·653a··stalled..-·name: 
00044600:·2045·6e73·7572·6520·6169·6465·2069·7320···Ensure·aide·is· 
00044610:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack 
00044620:·6167·653a·0a20·2020·206e·616d·653a·2061··age:.····name:·a 
00044630:·6964·650a·2020·2020·7374·6174·653a·2070··ide.····state:·p 
00044640:·7265·7365·6e74·0a20·2077·6865·6e3a·2028··resent.··when:·(00044070:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 00044080:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 00044090:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 000440a0:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 000440b0:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·||
Max diff block lines reached; 500158/529442 bytes (94.47%) of diff not shown.
59.3 KB
html2text {}
    
Offset 698, 19 lines modifiedOffset 698, 14 lines modified
698 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3698 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
699 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5699 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
700 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199700 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
701 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029701 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
702 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79702 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
703 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2703 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
704 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule704 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule
705 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
706 [[packages]] 
707 name·=·"aide" 
708 version·=·"*" 
709 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8705 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
710 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low706 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
711 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low707 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
712 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false708 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
713 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable709 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
714 #·Remediation·is·applicable·only·in·certain·platforms710 #·Remediation·is·applicable·only·in·certain·platforms
715 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then711 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 756, 33 lines modifiedOffset 751, 38 lines modified
756 ··-·PCI-DSSv4-11.5.2751 ··-·PCI-DSSv4-11.5.2
757 ··-·enable_strategy752 ··-·enable_strategy
758 ··-·low_complexity753 ··-·low_complexity
759 ··-·low_disruption754 ··-·low_disruption
760 ··-·medium_severity755 ··-·medium_severity
761 ··-·no_reboot_needed756 ··-·no_reboot_needed
762 ··-·package_aide_installed757 ··-·package_aide_installed
 758 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 759 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 760 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 761 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 762 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 763 package·--add=aide
 764 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 765 [[packages]]
 766 name·=·"aide"
 767 version·=·"*"
763 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8768 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
764 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low769 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
765 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low770 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
766 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false771 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
767 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable772 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
768 include·install_aide773 include·install_aide
  
769 class·install_aide·{774 class·install_aide·{
770 ··package·{·'aide':775 ··package·{·'aide':
771 ····ensure·=>·'installed',776 ····ensure·=>·'installed',
772 ··}777 ··}
773 }778 }
774 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
775 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
776 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
777 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
778 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
779 package·--add=aide 
780 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*779 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
781 Run·the·following·command·to·generate·a·new·database:780 Run·the·following·command·to·generate·a·new·database:
782 $·sudo·/usr/sbin/aide·--init781 $·sudo·/usr/sbin/aide·--init
783 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:782 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
784 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz783 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
785 To·initiate·a·manual·check,·run·the·following·command:784 To·initiate·a·manual·check,·run·the·following·command:
786 $·sudo·/usr/sbin/aide·--check785 $·sudo·/usr/sbin/aide·--check
Offset 16273, 19 lines modifiedOffset 16273, 14 lines modified
16273 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.316273 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3
16274 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)16274 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
16275 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-716275 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-7
16276 ············_\x8o_\x8s_\x8p_\x8p···········FMT_MOF_EXT.116276 ············_\x8o_\x8s_\x8p_\x8p···········FMT_MOF_EXT.1
16277 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000029-GPOS-0001016277 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000029-GPOS-00010
16278 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-01009016278 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010090
16279 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255900r958402_rule16279 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255900r958402_rule
16280 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
16281 [[packages]] 
16282 name·=·"screen" 
16283 version·=·"*" 
16284 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x816280 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
16285 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16281 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
16286 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low16282 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
16287 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false16283 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
16288 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable16284 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
16289 #·Remediation·is·applicable·only·in·certain·platforms16285 #·Remediation·is·applicable·only·in·certain·platforms
16290 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then16286 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 16327, 33 lines modifiedOffset 16322, 38 lines modified
16327 ··-·NIST-800-53-CM-6(a)16322 ··-·NIST-800-53-CM-6(a)
16328 ··-·enable_strategy16323 ··-·enable_strategy
16329 ··-·low_complexity16324 ··-·low_complexity
16330 ··-·low_disruption16325 ··-·low_disruption
16331 ··-·medium_severity16326 ··-·medium_severity
16332 ··-·no_reboot_needed16327 ··-·no_reboot_needed
16333 ··-·package_screen_installed16328 ··-·package_screen_installed
 16329 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 16330 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 16331 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 16332 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 16333 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 16334 package·--add=screen
 16335 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 16336 [[packages]]
 16337 name·=·"screen"
 16338 version·=·"*"
16334 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816339 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
16335 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16340 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
16336 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low16341 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
16337 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false16342 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
16338 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable16343 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
16339 include·install_screen16344 include·install_screen
  
16340 class·install_screen·{16345 class·install_screen·{
16341 ··package·{·'screen':16346 ··package·{·'screen':
16342 ····ensure·=>·'installed',16347 ····ensure·=>·'installed',
16343 ··}16348 ··}
16344 }16349 }
16345 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
16346 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
16347 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
16348 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
16349 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
16350 package·--add=screen 
16351 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·3·rules16350 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·3·rules
16352 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Oracle·Linux·7·servers,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.16351 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Oracle·Linux·7·servers,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.
16353 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·S\x8Sm\x8ma\x8ar\x8rt\x8t·C\x8Ca\x8ar\x8rd\x8d·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*16352 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·S\x8Sm\x8ma\x8ar\x8rt\x8t·C\x8Ca\x8ar\x8rd\x8d·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Max diff block lines reached; 54832/60745 bytes (90.27%) of diff not shown.
577 KB
./usr/share/doc/ssg-nondebian/ssg-ol7-guide-stig_gui.html
    
Offset 17407, 221 lines modifiedOffset 17407, 221 lines modified
00043fe0:·6765·743d·2223·6964·6d35·3635·3122·2074··get="#idm5651"·t00043fe0:·6765·743d·2223·6964·6d35·3635·3122·2074··get="#idm5651"·t
00043ff0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00043ff0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00044000:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00044000:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00044010:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00044010:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00044020:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00044020:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00044030:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00044030:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00044040:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00044040:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 00044050:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
00044050:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
00044060:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
00044070:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00044080:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00044090:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
000440a0:·646d·3536·3531·223e·3c70·7265·3e3c·636f··dm5651"><pre><co 
000440b0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
000440c0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
000440d0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
000440e0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
000440f0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00044100:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00044110:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00044120:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00044130:·6964·6d35·3635·3222·2074·6162·696e·6465··idm5652"·tabinde 
00044140:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00044150:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00044160:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00044170:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
00044180:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
00044190:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
000441a0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
000441b0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
000441c0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
000441d0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
000441e0:·3635·3222·3e3c·7461·626c·6520·636c·6173··652"><table·clas 
000441f0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00044200:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00044210:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00044220:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00044230:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
00044240:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00044250:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00044260:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
00044270:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
00044280:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
00044290:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
000442a0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
000442b0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
000442c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
000442d0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
000442e0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
000442f0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
00044300:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
00044310:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
00044320:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r 
00044330:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
00044340:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then.. 
00044350:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
00044360:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
00044370:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal 
00044380:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
00044390:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
000443a0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
000443b0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
000443c0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
000443d0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
000443e0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
000443f0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00044400:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00044410:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00044420:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00044430:·2369·646d·3536·3533·2220·7461·6269·6e64··#idm5653"·tabind 
00044440:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00044450:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00044460:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00044470:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00044480:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00044490:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
000444a0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
000444b0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00044060:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
000444c0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00044070:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
000444d0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00044080:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
000444e0:·6964·6d35·3635·3322·3e3c·7461·626c·6520··idm5653"><table·00044090:·3d22·6964·6d35·3635·3122·3e3c·7461·626c··="idm5651"><tabl
000444f0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab000440a0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
00044500:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table000440b0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
00044510:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-000440c0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
00044520:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><000440d0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
00044530:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</000440e0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
00044540:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><000440f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00044550:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr00044100:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
00044560:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>00044110:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
00044570:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr00044120:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00044580:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th00044130:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
00044590:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><00044140:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
000445a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra00044150:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
000445b0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en00044160:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
000445c0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></00044170:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
000445d0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code00044180:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
000445e0:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather· 
000445f0:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact 
00044600:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact 
00044610:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:· 
00044620:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··- 
00044630:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
00044640:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL0 
00044650:·372d·3030·2d30·3230·3032·390a·2020·2d20··7-00-020029.··-· 
00044660:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
00044670:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
00044680:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
00044690:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
000446a0:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
000446b0:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
000446c0:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
000446d0:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
000446e0:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
000446f0:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
00044700:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
00044710:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
00044720:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
00044730:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
00044740:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
00044750:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
00044760:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe00044190:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 000441a0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 000441b0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 000441c0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm·
 000441d0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 000441e0:·6c20·7c7c·2072·706d·202d·2d71·7569·6574··l·||·rpm·--quiet
Max diff block lines reached; 500434/529580 bytes (94.50%) of diff not shown.
59.3 KB
html2text {}
    
Offset 702, 19 lines modifiedOffset 702, 14 lines modified
702 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3702 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
703 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5703 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
704 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199704 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
705 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029705 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-020029
706 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79706 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
707 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2707 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
708 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule708 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251701r958944_rule
709 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
710 [[packages]] 
711 name·=·"aide" 
712 version·=·"*" 
713 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8709 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
714 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low710 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
715 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low711 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
716 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false712 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
717 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable713 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
718 #·Remediation·is·applicable·only·in·certain·platforms714 #·Remediation·is·applicable·only·in·certain·platforms
719 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then715 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 760, 33 lines modifiedOffset 755, 38 lines modified
760 ··-·PCI-DSSv4-11.5.2755 ··-·PCI-DSSv4-11.5.2
761 ··-·enable_strategy756 ··-·enable_strategy
762 ··-·low_complexity757 ··-·low_complexity
763 ··-·low_disruption758 ··-·low_disruption
764 ··-·medium_severity759 ··-·medium_severity
765 ··-·no_reboot_needed760 ··-·no_reboot_needed
766 ··-·package_aide_installed761 ··-·package_aide_installed
 762 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 763 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 764 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 765 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 766 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 767 package·--add=aide
 768 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 769 [[packages]]
 770 name·=·"aide"
 771 version·=·"*"
767 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8772 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
768 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low773 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
769 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low774 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
770 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false775 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
771 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable776 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
772 include·install_aide777 include·install_aide
  
773 class·install_aide·{778 class·install_aide·{
774 ··package·{·'aide':779 ··package·{·'aide':
775 ····ensure·=>·'installed',780 ····ensure·=>·'installed',
776 ··}781 ··}
777 }782 }
778 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
779 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
780 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
781 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
782 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
783 package·--add=aide 
784 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*783 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
785 Run·the·following·command·to·generate·a·new·database:784 Run·the·following·command·to·generate·a·new·database:
786 $·sudo·/usr/sbin/aide·--init785 $·sudo·/usr/sbin/aide·--init
787 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:786 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
788 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz787 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
789 To·initiate·a·manual·check,·run·the·following·command:788 To·initiate·a·manual·check,·run·the·following·command:
790 $·sudo·/usr/sbin/aide·--check789 $·sudo·/usr/sbin/aide·--check
Offset 16277, 19 lines modifiedOffset 16277, 14 lines modified
16277 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.316277 References:·_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.18.1.4,·A.9.2.1,·A.9.2.4,·A.9.3.1,·A.9.4.2,·A.9.4.3
16278 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)16278 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
16279 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-716279 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-7
16280 ············_\x8o_\x8s_\x8p_\x8p···········FMT_MOF_EXT.116280 ············_\x8o_\x8s_\x8p_\x8p···········FMT_MOF_EXT.1
16281 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000029-GPOS-0001016281 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000029-GPOS-00010
16282 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-01009016282 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL07-00-010090
16283 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255900r958402_rule16283 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255900r958402_rule
16284 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
16285 [[packages]] 
16286 name·=·"screen" 
16287 version·=·"*" 
16288 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x816284 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
16289 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16285 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
16290 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low16286 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
16291 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false16287 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
16292 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable16288 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
16293 #·Remediation·is·applicable·only·in·certain·platforms16289 #·Remediation·is·applicable·only·in·certain·platforms
16294 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then16290 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 16331, 33 lines modifiedOffset 16326, 38 lines modified
16331 ··-·NIST-800-53-CM-6(a)16326 ··-·NIST-800-53-CM-6(a)
16332 ··-·enable_strategy16327 ··-·enable_strategy
16333 ··-·low_complexity16328 ··-·low_complexity
16334 ··-·low_disruption16329 ··-·low_disruption
16335 ··-·medium_severity16330 ··-·medium_severity
16336 ··-·no_reboot_needed16331 ··-·no_reboot_needed
16337 ··-·package_screen_installed16332 ··-·package_screen_installed
 16333 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 16334 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 16335 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 16336 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 16337 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 16338 package·--add=screen
 16339 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 16340 [[packages]]
 16341 name·=·"screen"
 16342 version·=·"*"
16338 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x816343 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
16339 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low16344 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
16340 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low16345 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
16341 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false16346 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
16342 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable16347 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
16343 include·install_screen16348 include·install_screen
  
16344 class·install_screen·{16349 class·install_screen·{
16345 ··package·{·'screen':16350 ··package·{·'screen':
16346 ····ensure·=>·'installed',16351 ····ensure·=>·'installed',
16347 ··}16352 ··}
16348 }16353 }
16349 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
16350 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
16351 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
16352 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
16353 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
16354 package·--add=screen 
16355 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·3·rules16354 Group  ·Hardware·Tokens·for·Authentication·  Group·contains·3·rules
16356 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Oracle·Linux·7·servers,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.16355 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·use·of·hardware·tokens·such·as·smart·cards·for·system·login·provides·stronger,·two-factor·authentication·than·using·a·username·and·password.·In·Oracle·Linux·7·servers,·hardware·token·login·is·not·enabled·by·default·and·must·be·enabled·in·the·system·settings.
16357 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·S\x8Sm\x8ma\x8ar\x8rt\x8t·C\x8Ca\x8ar\x8rd\x8d·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*16356 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·S\x8Sm\x8ma\x8ar\x8rt\x8t·C\x8Ca\x8ar\x8rd\x8d·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8es\x8s·F\x8Fo\x8or\x8r·M\x8Mu\x8ul\x8lt\x8ti\x8if\x8fa\x8ac\x8ct\x8to\x8or\x8r·A\x8Au\x8ut\x8th\x8he\x8en\x8nt\x8ti\x8ic\x8ca\x8at\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Max diff block lines reached; 54832/60745 bytes (90.27%) of diff not shown.
706 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_enhanced.html
    
Offset 15058, 222 lines modifiedOffset 15058, 222 lines modified
0003ad10:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003ad10:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003ad20:·3d22·2369·646d·3536·3936·2220·7461·6269··="#idm5696"·tabi0003ad20:·3d22·2369·646d·3536·3936·2220·7461·6269··="#idm5696"·tabi
0003ad30:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003ad30:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003ad40:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003ad40:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003ad50:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003ad50:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003ad60:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003ad60:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003ad70:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003ad70:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003ad80:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003ad80:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003ad90:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003ada0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003adb0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003adc0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003add0:·646d·3536·3936·223e·3c74·6162·6c65·2063··dm5696"><table·c
 0003ade0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003adf0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003ae00:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003ae10:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003ae20:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003ae30:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003ae40:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003ae50:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003ae60:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003ae70:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003ae80:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003ae90:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003aea0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003ad90:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003ada0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003adb0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003adc0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003add0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003ade0:·3639·3622·3e3c·7072·653e·3c63·6f64·653e··696"><pre><code> 
0003adf0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003ae00:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003ae10:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003ae20:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003ae30:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003ae40:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003ae50:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003ae60:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003ae70:·3536·3937·2220·7461·6269·6e64·6578·3d22··5697"·tabindex=" 
0003ae80:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003ae90:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003aea0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003aeb0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003aec0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003aed0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003aee0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003aef0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003af00:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003af10:·7073·6522·2069·643d·2269·646d·3536·3937··pse"·id="idm5697 
0003af20:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003af30:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003af40:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003af50:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003af60:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003af70:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003af80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003af90:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003afa0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003afb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003afc0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003afd0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003aeb0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003afe0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003aff0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003b000:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b010:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003b020:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b030:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b040:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b050:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003b060:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm· 
0003b070:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003b080:·6c2d·7565·6b3b·2074·6865·6e0a·0a69·6620··l-uek;·then..if· 
0003b090:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003b0a0:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003b0b0:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·- 
0003b0c0:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003b0d0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b0e0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b0f0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b100:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b110:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b120:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b130:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b140:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b150:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b160:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b170:·6d35·3639·3822·2074·6162·696e·6465·783d··m5698"·tabindex= 
0003b180:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b190:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b1a0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b1b0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b1c0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b1d0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b1e0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b1f0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b200:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b210:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b220:·3536·3938·223e·3c74·6162·6c65·2063·6c61··5698"><table·cla 
0003b230:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b240:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b250:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b260:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b270:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b280:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b290:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b2a0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b2b0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b2c0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b2d0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b2e0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b2f0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b300:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b310:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·0003aec0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003b320:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
0003b330:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
0003b340:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
0003b350:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
0003b360:·6f0a·2020·7461·6773·3a0a·2020·2d20·434a··o.··tags:.··-·CJ 
0003b370:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003b380:·4449·5341·2d53·5449·472d·4f4c·3038·2d30··DISA-STIG-OL08-0 
0003b390:·302d·3031·3033·3539·0a20·202d·204e·4953··0-010359.··-·NIS 
0003b3a0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003b3b0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003b3c0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003b3d0:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
Max diff block lines reached; 625774/655058 bytes (95.53%) of diff not shown.
66.6 KB
html2text {}
    
Offset 116, 19 lines modifiedOffset 116, 14 lines modified
116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359119 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
120 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79120 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule122 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
124 [[packages]] 
125 name·=·"aide" 
126 version·=·"*" 
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
132 #·Remediation·is·applicable·only·in·certain·platforms128 #·Remediation·is·applicable·only·in·certain·platforms
133 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then129 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 174, 33 lines modifiedOffset 169, 38 lines modified
174 ··-·PCI-DSSv4-11.5.2169 ··-·PCI-DSSv4-11.5.2
175 ··-·enable_strategy170 ··-·enable_strategy
176 ··-·low_complexity171 ··-·low_complexity
177 ··-·low_disruption172 ··-·low_disruption
178 ··-·medium_severity173 ··-·medium_severity
179 ··-·no_reboot_needed174 ··-·no_reboot_needed
180 ··-·package_aide_installed175 ··-·package_aide_installed
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 181 package·--add=aide
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
186 include·install_aide191 include·install_aide
  
187 class·install_aide·{192 class·install_aide·{
188 ··package·{·'aide':193 ··package·{·'aide':
189 ····ensure·=>·'installed',194 ····ensure·=>·'installed',
190 ··}195 ··}
191 }196 }
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·--add=aide 
198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
199 Run·the·following·command·to·generate·a·new·database:198 Run·the·following·command·to·generate·a·new·database:
200 $·sudo·/usr/sbin/aide·--init199 $·sudo·/usr/sbin/aide·--init
201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
202 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these201 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
203 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their202 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
204 integrity.·The·newly-generated·database·can·be·installed·as·follows:203 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 651, 19 lines modifiedOffset 651, 14 lines modified
651 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235651 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
652 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386652 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
653 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)653 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
654 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1654 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
655 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125655 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
656 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33656 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
657 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2657 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
658 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
659 [[packages]] 
660 name·=·"sudo" 
661 version·=·"*" 
662 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8658 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
663 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low659 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
664 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low660 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
665 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false661 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
666 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable662 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
667 #·Remediation·is·applicable·only·in·certain·platforms663 #·Remediation·is·applicable·only·in·certain·platforms
668 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then664 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 705, 33 lines modifiedOffset 700, 38 lines modified
705 ··-·PCI-DSSv4-2.2.6700 ··-·PCI-DSSv4-2.2.6
706 ··-·enable_strategy701 ··-·enable_strategy
707 ··-·low_complexity702 ··-·low_complexity
708 ··-·low_disruption703 ··-·low_disruption
709 ··-·medium_severity704 ··-·medium_severity
710 ··-·no_reboot_needed705 ··-·no_reboot_needed
711 ··-·package_sudo_installed706 ··-·package_sudo_installed
 707 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 708 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 709 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 710 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 711 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 712 package·--add=sudo
 713 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 714 [[packages]]
 715 name·=·"sudo"
 716 version·=·"*"
712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8717 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low718 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low719 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false720 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable721 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
717 include·install_sudo722 include·install_sudo
  
718 class·install_sudo·{723 class·install_sudo·{
719 ··package·{·'sudo':724 ··package·{·'sudo':
720 ····ensure·=>·'installed',725 ····ensure·=>·'installed',
721 ··}726 ··}
722 }727 }
723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
724 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
725 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
726 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
727 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
728 package·--add=sudo 
729 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*728 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
730 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:729 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
731 $·sudo·chgrp·root·/etc/sudoers.d730 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 63004/68223 bytes (92.35%) of diff not shown.
740 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_high.html
    
Offset 15064, 221 lines modifiedOffset 15064, 221 lines modified
0003ad70:·6765·743d·2223·6964·6d35·3639·3622·2074··get="#idm5696"·t0003ad70:·6765·743d·2223·6964·6d35·3639·3622·2074··get="#idm5696"·t
0003ad80:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003ad80:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003ad90:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003ad90:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003ada0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003ada0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003adb0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003adb0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003adc0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003adc0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003add0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003add0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003ade0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
0003ade0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003adf0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003ae00:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003ae10:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003ae20:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003ae30:·646d·3536·3936·223e·3c70·7265·3e3c·636f··dm5696"><pre><co 
0003ae40:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003ae50:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003ae60:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003ae70:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003ae80:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003ae90:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003aea0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003aeb0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003aec0:·6964·6d35·3639·3722·2074·6162·696e·6465··idm5697"·tabinde 
0003aed0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003aee0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003aef0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003af00:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003af10:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003af20:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003af30:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003af40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003af50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003af60:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003af70:·3639·3722·3e3c·7461·626c·6520·636c·6173··697"><table·clas 
0003af80:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003af90:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003afa0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003afb0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003afc0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003afd0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003afe0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003aff0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b000:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b010:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b020:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b030:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b040:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b050:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b060:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b070:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b080:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b090:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b0a0:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003b0b0:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r 
0003b0c0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003b0d0:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then.. 
0003b0e0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b0f0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b100:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal 
0003b110:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b120:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b130:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b140:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b150:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b160:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b170:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b180:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b190:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b1a0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b1b0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b1c0:·2369·646d·3536·3938·2220·7461·6269·6e64··#idm5698"·tabind 
0003b1d0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b1e0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b1f0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b200:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b210:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b220:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
0003b230:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b240:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003adf0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b250:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003ae00:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b260:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003ae10:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b270:·6964·6d35·3639·3822·3e3c·7461·626c·6520··idm5698"><table·0003ae20:·3d22·6964·6d35·3639·3622·3e3c·7461·626c··="idm5696"><tabl
0003b280:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003ae30:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003b290:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003ae40:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003b2a0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003ae50:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003b2b0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003ae60:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003b2c0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003ae70:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003b2d0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003ae80:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b2e0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003ae90:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b2f0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003aea0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b300:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003aeb0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b310:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003aec0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003b320:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003aed0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003b330:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003aee0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003b340:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003aef0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003b350:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003af00:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003b360:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003af10:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003b370:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather· 
0003b380:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact 
0003b390:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact 
0003b3a0:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:· 
0003b3b0:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··- 
0003b3c0:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003b3d0:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL0 
0003b3e0:·382d·3030·2d30·3130·3335·390a·2020·2d20··8-00-010359.··-· 
0003b3f0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003b400:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003b410:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003b420:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003b430:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003b440:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003b450:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003b460:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003b470:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003b480:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003b490:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003b4a0:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
0003b4b0:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
0003b4c0:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
0003b4d0:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
0003b4e0:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
0003b4f0:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe0003af20:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003af30:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003af40:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003af50:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm·
 0003af60:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 0003af70:·6c20·7c7c·2072·706d·202d·2d71·7569·6574··l·||·rpm·--quiet
Max diff block lines reached; 654976/684122 bytes (95.74%) of diff not shown.
72.0 KB
html2text {}
    
Offset 117, 19 lines modifiedOffset 117, 14 lines modified
117 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3117 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
119 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199119 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
120 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359120 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
121 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79121 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2122 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
123 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule123 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
125 [[packages]] 
126 name·=·"aide" 
127 version·=·"*" 
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
133 #·Remediation·is·applicable·only·in·certain·platforms129 #·Remediation·is·applicable·only·in·certain·platforms
134 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then130 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 175, 33 lines modifiedOffset 170, 38 lines modified
175 ··-·PCI-DSSv4-11.5.2170 ··-·PCI-DSSv4-11.5.2
176 ··-·enable_strategy171 ··-·enable_strategy
177 ··-·low_complexity172 ··-·low_complexity
178 ··-·low_disruption173 ··-·low_disruption
179 ··-·medium_severity174 ··-·medium_severity
180 ··-·no_reboot_needed175 ··-·no_reboot_needed
181 ··-·package_aide_installed176 ··-·package_aide_installed
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 182 package·--add=aide
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 184 [[packages]]
 185 name·=·"aide"
 186 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
187 include·install_aide192 include·install_aide
  
188 class·install_aide·{193 class·install_aide·{
189 ··package·{·'aide':194 ··package·{·'aide':
190 ····ensure·=>·'installed',195 ····ensure·=>·'installed',
191 ··}196 ··}
192 }197 }
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
198 package·--add=aide 
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
200 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
201 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
203 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these202 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
204 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their203 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
205 integrity.·The·newly-generated·database·can·be·installed·as·follows:204 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 1204, 19 lines modifiedOffset 1204, 14 lines modified
1204 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351204 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1205 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861205 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1206 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1206 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1207 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11207 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1208 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251208 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1209 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331209 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1210 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21210 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1212 [[packages]] 
1213 name·=·"sudo" 
1214 version·=·"*" 
1215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1220 #·Remediation·is·applicable·only·in·certain·platforms1216 #·Remediation·is·applicable·only·in·certain·platforms
1221 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1217 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1258, 33 lines modifiedOffset 1253, 38 lines modified
1258 ··-·PCI-DSSv4-2.2.61253 ··-·PCI-DSSv4-2.2.6
1259 ··-·enable_strategy1254 ··-·enable_strategy
1260 ··-·low_complexity1255 ··-·low_complexity
1261 ··-·low_disruption1256 ··-·low_disruption
1262 ··-·medium_severity1257 ··-·medium_severity
1263 ··-·no_reboot_needed1258 ··-·no_reboot_needed
1264 ··-·package_sudo_installed1259 ··-·package_sudo_installed
 1260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1261 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1262 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1263 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1264 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1265 package·--add=sudo
 1266 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1267 [[packages]]
 1268 name·=·"sudo"
 1269 version·=·"*"
1265 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1266 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1271 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1267 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1272 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1268 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1273 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1269 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1274 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1270 include·install_sudo1275 include·install_sudo
  
1271 class·install_sudo·{1276 class·install_sudo·{
1272 ··package·{·'sudo':1277 ··package·{·'sudo':
1273 ····ensure·=>·'installed',1278 ····ensure·=>·'installed',
1274 ··}1279 ··}
1275 }1280 }
1276 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1277 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1278 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1279 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1280 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1281 package·--add=sudo 
1282 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1281 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1283 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:1282 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
1284 $·sudo·chgrp·root·/etc/sudoers.d1283 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 68436/73659 bytes (92.91%) of diff not shown.
591 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_intermediary.html
    
Offset 15054, 221 lines modifiedOffset 15054, 221 lines modified
0003acd0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003acd0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003ace0:·6964·6d35·3639·3622·2074·6162·696e·6465··idm5696"·tabinde0003ace0:·6964·6d35·3639·3622·2074·6162·696e·6465··idm5696"·tabinde
0003acf0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003acf0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003ad00:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003ad00:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003ad10:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003ad10:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003ad20:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003ad20:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003ad30:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003ad30:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003ad40:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003ad40:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0003ad50:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003ad60:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003ad70:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003ad80:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003ad90:·7073·6522·2069·643d·2269·646d·3536·3936··pse"·id="idm5696 
0003ada0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003adb0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003adc0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003add0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003ade0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003adf0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003ae00:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003ae10:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003ae20:·2d74·6172·6765·743d·2223·6964·6d35·3639··-target="#idm569 
0003ae30:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"· 
0003ae40:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003ae50:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003ae60:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003ae70:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003ae80:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003ae90:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003aea0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003aeb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003aec0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003aed0:·2220·6964·3d22·6964·6d35·3639·3722·3e3c··"·id="idm5697">< 
0003aee0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003aef0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003af00:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003af10:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003af20:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003af30:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003af40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003af50:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003af60:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003af70:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003af80:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003af90:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003afa0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003afb0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003afc0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003afd0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003afe0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003aff0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b000:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b010:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003b020:·6572·6e65·6c20·7c7c·2072·706d·202d·2d71··ernel·||·rpm·--q 
0003b030:·7569·6574·202d·7120·6b65·726e·656c·2d75··uiet·-q·kernel-u 
0003b040:·656b·3b20·7468·656e·0a0a·6966·2021·2072··ek;·then..if·!·r 
0003b050:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003b060:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003b070:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·" 
0003b080:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003b090:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003b0a0:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003b0b0:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003b0c0:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003b0d0:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003b0e0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b0f0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b100:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b110:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b120:·612d·7461·7267·6574·3d22·2369·646d·3536··a-target="#idm56 
0003b130:·3938·2220·7461·6269·6e64·6578·3d22·3022··98"·tabindex="0" 
0003b140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b190:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003b1a0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br0003ad50:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003b1b0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003ad60:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b1c0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003ad70:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b1d0:·6170·7365·2220·6964·3d22·6964·6d35·3639··apse"·id="idm5690003ad80:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
0003b1e0:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=0003ad90:·3639·3622·3e3c·7461·626c·6520·636c·6173··696"><table·clas
0003b1f0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003ada0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b200:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003adb0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003b210:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003adc0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003b220:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003add0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003b230:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003ade0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003b240:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003adf0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b250:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003ae00:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003b260:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003ae10:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003b270:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0003ae20:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b280:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003ae30:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003b290:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0003ae40:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003b2a0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<0003ae50:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003b2b0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</0003ae60:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003b2c0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>0003ae70:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b2d0:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam0003ae80:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
0003b2e0:·653a·2047·6174·6865·7220·7468·6520·7061··e:·Gather·the·pa 
0003b2f0:·636b·6167·6520·6661·6374·730a·2020·7061··ckage·facts.··pa 
0003b300:·636b·6167·655f·6661·6374·733a·0a20·2020··ckage_facts:.··· 
0003b310:·206d·616e·6167·6572·3a20·6175·746f·0a20···manager:·auto.· 
0003b320:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS- 
0003b330:·352e·3130·2e31·2e33·0a20·202d·2044·4953··5.10.1.3.··-·DIS 
0003b340:·412d·5354·4947·2d4f·4c30·382d·3030·2d30··A-STIG-OL08-00-0 
0003b350:·3130·3335·390a·2020·2d20·4e49·5354·2d38··10359.··-·NIST-8 
0003b360:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).·· 
0003b370:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11 
0003b380:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4 
0003b390:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab 
0003b3a0:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-· 
0003b3b0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.· 
0003b3c0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio 
0003b3d0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev 
0003b3e0:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb 
0003b3f0:·6f6f·745f·6e65·6564·6564·0a20·202d·2070··oot_needed.··-·p 
0003b400:·6163·6b61·6765·5f61·6964·655f·696e·7374··ackage_aide_inst 
0003b410:·616c·6c65·640a·0a2d·206e·616d·653a·2045··alled..-·name:·E 
0003b420:·6e73·7572·6520·6169·6465·2069·7320·696e··nsure·aide·is·in 
0003b430:·7374·616c·6c65·640a·2020·7061·636b·6167··stalled.··packag 
0003b440:·653a·0a20·2020·206e·616d·653a·2061·6964··e:.····name:·aid 
0003b450:·650a·2020·2020·7374·6174·653a·2070·7265··e.····state:·pre 
0003b460:·7365·6e74·0a20·2077·6865·6e3a·2028·226b··sent.··when:·("k0003ae90:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003aea0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003aeb0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003aec0:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 0003aed0:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r
 0003aee0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
Max diff block lines reached; 517330/546476 bytes (94.67%) of diff not shown.
57.0 KB
html2text {}
    
Offset 115, 19 lines modifiedOffset 115, 14 lines modified
115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
118 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359118 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
121 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule121 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
123 [[packages]] 
124 name·=·"aide" 
125 version·=·"*" 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
131 #·Remediation·is·applicable·only·in·certain·platforms127 #·Remediation·is·applicable·only·in·certain·platforms
132 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then128 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 173, 33 lines modifiedOffset 168, 38 lines modified
173 ··-·PCI-DSSv4-11.5.2168 ··-·PCI-DSSv4-11.5.2
174 ··-·enable_strategy169 ··-·enable_strategy
175 ··-·low_complexity170 ··-·low_complexity
176 ··-·low_disruption171 ··-·low_disruption
177 ··-·medium_severity172 ··-·medium_severity
178 ··-·no_reboot_needed173 ··-·no_reboot_needed
179 ··-·package_aide_installed174 ··-·package_aide_installed
 175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 180 package·--add=aide
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 182 [[packages]]
 183 name·=·"aide"
 184 version·=·"*"
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
185 include·install_aide190 include·install_aide
  
186 class·install_aide·{191 class·install_aide·{
187 ··package·{·'aide':192 ··package·{·'aide':
188 ····ensure·=>·'installed',193 ····ensure·=>·'installed',
189 ··}194 ··}
190 }195 }
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
196 package·--add=aide 
197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
198 Run·the·following·command·to·generate·a·new·database:197 Run·the·following·command·to·generate·a·new·database:
199 $·sudo·/usr/sbin/aide·--init198 $·sudo·/usr/sbin/aide·--init
200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the199 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
201 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these200 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
202 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their201 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
203 integrity.·The·newly-generated·database·can·be·installed·as·follows:202 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 615, 19 lines modifiedOffset 615, 14 lines modified
615 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235615 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
616 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386616 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
617 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)617 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
618 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1618 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
619 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125619 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
620 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33620 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
621 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2621 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
622 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
623 [[packages]] 
624 name·=·"sudo" 
625 version·=·"*" 
626 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8622 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
627 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low623 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
628 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low624 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
629 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false625 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
630 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable626 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
631 #·Remediation·is·applicable·only·in·certain·platforms627 #·Remediation·is·applicable·only·in·certain·platforms
632 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then628 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 669, 33 lines modifiedOffset 664, 38 lines modified
669 ··-·PCI-DSSv4-2.2.6664 ··-·PCI-DSSv4-2.2.6
670 ··-·enable_strategy665 ··-·enable_strategy
671 ··-·low_complexity666 ··-·low_complexity
672 ··-·low_disruption667 ··-·low_disruption
673 ··-·medium_severity668 ··-·medium_severity
674 ··-·no_reboot_needed669 ··-·no_reboot_needed
675 ··-·package_sudo_installed670 ··-·package_sudo_installed
 671 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 672 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 673 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 674 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 675 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 676 package·--add=sudo
 677 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 678 [[packages]]
 679 name·=·"sudo"
 680 version·=·"*"
676 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8681 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
677 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low682 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
678 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low683 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
679 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false684 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
680 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable685 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
681 include·install_sudo686 include·install_sudo
  
682 class·install_sudo·{687 class·install_sudo·{
683 ··package·{·'sudo':688 ··package·{·'sudo':
684 ····ensure·=>·'installed',689 ····ensure·=>·'installed',
685 ··}690 ··}
686 }691 }
687 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
688 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
689 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
690 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
691 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
692 package·--add=sudo 
693 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*692 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
694 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:693 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
695 $·sudo·chgrp·root·/etc/sudoers.d694 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 53106/58325 bytes (91.05%) of diff not shown.
174 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-anssi_bp28_minimal.html
    
Offset 14725, 228 lines modifiedOffset 14725, 228 lines modified
00039840:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i00039840:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
00039850:·646d·3130·3539·3722·2074·6162·696e·6465··dm10597"·tabinde00039850:·646d·3130·3539·3722·2074·6162·696e·6465··dm10597"·tabinde
00039860:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt00039860:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
00039870:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande00039870:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
00039880:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=00039880:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
00039890:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev00039890:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
000398a0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R000398a0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
000398b0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui000398b0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
000398c0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
000398d0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
000398e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
000398f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00039900:·7073·6522·2069·643d·2269·646d·3130·3539··pse"·id="idm1059000398c0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 000398d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 000398e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 000398f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d31··llapse"·id="idm1
 00039900:·3035·3937·223e·3c74·6162·6c65·2063·6c61··0597"><table·cla
 00039910:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 00039920:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 00039930:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 00039940:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 00039950:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 00039960:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00039970:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 00039980:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 00039990:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000399a0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 000399b0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 000399c0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 000399d0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 000399e0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
00039910:·3722·3e3c·7072·653e·3c63·6f64·653e·0a5b··7"><pre><code>.[000399f0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
00039920:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name00039a00:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 00039a10:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 00039a20:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 00039a30:·726d·730a·6966·2021·2028·207b·2072·706d··rms.if·!·(·{·rpm
 00039a40:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 00039a50:·656c·203b·7d20·2661·6d70·3b26·616d·703b··el·;}·&amp;&amp;
 00039a60:·207b·2072·706d·202d·2d71·7569·6574·202d···{·rpm·--quiet·-
 00039a70:·7120·7270·6d2d·6f73·7472·6565·203b·7d20··q·rpm-ostree·;}·
 00039a80:·2661·6d70·3b26·616d·703b·207b·2072·706d··&amp;&amp;·{·rpm
 00039a90:·202d·2d71·7569·6574·202d·7120·626f·6f74···--quiet·-q·boot
 00039aa0:·6320·3b7d·2026·616d·703b·2661·6d70·3b20··c·;}·&amp;&amp;·
 00039ab0:·7b20·2120·7270·6d20·2d2d·7175·6965·7420··{·!·rpm·--quiet·
 00039ac0:·2d71·206f·7065·6e73·6869·6674·2d6b·7562··-q·openshift-kub
 00039ad0:·656c·6574·203b·7d20·293b·2074·6865·6e0a··elet·;}·);·then.
 00039ae0:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q
00039930:·203d·2022·646e·662d·6175·746f·6d61·7469···=·"dnf-automati00039af0:·7569·6574·2022·646e·662d·6175·746f·6d61··uiet·"dnf-automa
00039940:·6322·0a76·6572·7369·6f6e·203d·2022·2a22··c".version·=·"*"00039b00:·7469·6322·203b·2074·6865·6e0a·2020·2020··tic"·;·then.····
 00039b10:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 00039b20:·646e·662d·6175·746f·6d61·7469·6322·0a66··dnf-automatic".f
 00039b30:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt;
 00039b40:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 00039b50:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 00039b60:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 00039b70:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
00039950:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></00039b80:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
00039960:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt00039b90:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
00039970:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d00039ba0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
00039980:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll00039bb0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
00039990:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00039bc0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
000399a0:·743d·2223·6964·6d31·3035·3938·2220·7461··t="#idm10598"·ta00039bd0:·743d·2223·6964·6d31·3035·3938·2220·7461··t="#idm10598"·ta
000399b0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00039be0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
000399c0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00039bf0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
000399d0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00039c00:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
000399e0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00039c10:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
000399f0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00039c20:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00039a00:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00039c30:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00039c40:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
 00039c50:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 00039c60:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 00039c70:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 00039c80:·6964·3d22·6964·6d31·3035·3938·223e·3c74··id="idm10598"><t
 00039c90:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00039ca0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00039cb0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00039cc0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00039cd0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
00039a10:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
00039a20:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00039a30:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00039a40:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00039a50:·2269·646d·3130·3539·3822·3e3c·7461·626c··"idm10598"><tabl 
00039a60:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00039a70:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00039a80:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00039a90:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00039aa0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00039ab0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00039ac0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00039ad0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00039ae0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00039af0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00039b00:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00039b10:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00039b20:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00039b30:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00039b40:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00039b50:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
00039b60:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
00039b70:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
00039b80:·6c61·7466·6f72·6d73·0a69·6620·2120·2820··latforms.if·!·(· 
00039b90:·7b20·7270·6d20·2d2d·7175·6965·7420·2d71··{·rpm·--quiet·-q 
00039ba0:·206b·6572·6e65·6c20·3b7d·2026·616d·703b···kernel·;}·&amp; 
00039bb0:·2661·6d70·3b20·7b20·7270·6d20·2d2d·7175··&amp;·{·rpm·--qu 
00039bc0:·6965·7420·2d71·2072·706d·2d6f·7374·7265··iet·-q·rpm-ostre 
00039bd0:·6520·3b7d·2026·616d·703b·2661·6d70·3b20··e·;}·&amp;&amp;· 
00039be0:·7b20·7270·6d20·2d2d·7175·6965·7420·2d71··{·rpm·--quiet·-q 
00039bf0:·2062·6f6f·7463·203b·7d20·2661·6d70·3b26···bootc·;}·&amp;& 
00039c00:·616d·703b·207b·2021·2072·706d·202d·2d71··amp;·{·!·rpm·--q 
00039c10:·7569·6574·202d·7120·6f70·656e·7368·6966··uiet·-q·openshif 
00039c20:·742d·6b75·6265·6c65·7420·3b7d·2029·3b20··t-kubelet·;}·);· 
00039c30:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
00039c40:·7120·2d2d·7175·6965·7420·2264·6e66·2d61··q·--quiet·"dnf-a 
00039c50:·7574·6f6d·6174·6963·2220·3b20·7468·656e··utomatic"·;·then 
00039c60:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install 
00039c70:·202d·7920·2264·6e66·2d61·7574·6f6d·6174···-y·"dnf-automat 
00039c80:·6963·220a·6669·0a0a·656c·7365·0a20·2020··ic".fi..else.··· 
00039c90:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
00039ca0:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
00039cb0:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
00039cc0:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
00039cd0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
00039ce0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
00039cf0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
00039d00:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
00039d10:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
Max diff block lines reached; 124124/154236 bytes (80.48%) of diff not shown.
23.2 KB
html2text {}
    
Offset 81, 19 lines modifiedOffset 81, 14 lines modified
81 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade81 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
82 ············suitable·for·automatic,·regular·execution.82 ············suitable·for·automatic,·regular·execution.
83 Severity: ··medium83 Severity: ··medium
84 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed84 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
85 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.285 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
86 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008086 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
87 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R6187 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
88 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
89 [[packages]] 
90 name·=·"dnf-automatic" 
91 version·=·"*" 
92 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
93 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low89 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
94 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low90 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
95 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false91 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
96 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable92 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
97 #·Remediation·is·applicable·only·in·certain·platforms93 #·Remediation·is·applicable·only·in·certain·platforms
98 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-94 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 133, 33 lines modifiedOffset 128, 38 lines modified
133 ··tags:128 ··tags:
134 ··-·enable_strategy129 ··-·enable_strategy
135 ··-·low_complexity130 ··-·low_complexity
136 ··-·low_disruption131 ··-·low_disruption
137 ··-·medium_severity132 ··-·medium_severity
138 ··-·no_reboot_needed133 ··-·no_reboot_needed
139 ··-·package_dnf-automatic_installed134 ··-·package_dnf-automatic_installed
 135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 140 package·--add=dnf-automatic
 141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 142 [[packages]]
 143 name·=·"dnf-automatic"
 144 version·=·"*"
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
145 include·install_dnf-automatic150 include·install_dnf-automatic
  
146 class·install_dnf-automatic·{151 class·install_dnf-automatic·{
147 ··package·{·'dnf-automatic':152 ··package·{·'dnf-automatic':
148 ····ensure·=>·'installed',153 ····ensure·=>·'installed',
149 ··}154 ··}
150 }155 }
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
156 package·--add=dnf-automatic 
157 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*156 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
158 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed157 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
159 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/158 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
160 automatic.conf.159 automatic.conf.
161 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation160 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
162 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and161 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
163 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in162 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 11845, 33 lines modifiedOffset 11845, 33 lines modified
11845 ··-·PCI-DSSv4-2.2.411845 ··-·PCI-DSSv4-2.2.4
11846 ··-·disable_strategy11846 ··-·disable_strategy
11847 ··-·low_complexity11847 ··-·low_complexity
11848 ··-·low_disruption11848 ··-·low_disruption
11849 ··-·medium_severity11849 ··-·medium_severity
11850 ··-·no_reboot_needed11850 ··-·no_reboot_needed
11851 ··-·package_dhcp_removed11851 ··-·package_dhcp_removed
 11852 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11853 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11854 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11855 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11856 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11857 package·--remove=dhcp
11852 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811858 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11853 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11859 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11854 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11860 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11855 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11861 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11856 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11862 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11857 include·remove_dhcp11863 include·remove_dhcp
  
11858 class·remove_dhcp·{11864 class·remove_dhcp·{
11859 ··package·{·'dhcp':11865 ··package·{·'dhcp':
11860 ····ensure·=>·'purged',11866 ····ensure·=>·'purged',
11861 ··}11867 ··}
11862 }11868 }
11863 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
11864 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
11865 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
11866 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
11867 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
11868 package·--remove=dhcp 
11869 Group  ·Mail·Server·Software·  Group·contains·1·rule11869 Group  ·Mail·Server·Software·  Group·contains·1·rule
11870 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very11870 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very
11871 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure11871 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure
11872 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as11872 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as
11873 possible.11873 possible.
  
11874 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.11874 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.
Offset 11968, 33 lines modifiedOffset 11968, 33 lines modified
11968 ··-·NIST-800-53-CM-7(b)11968 ··-·NIST-800-53-CM-7(b)
11969 ··-·disable_strategy11969 ··-·disable_strategy
11970 ··-·low_complexity11970 ··-·low_complexity
11971 ··-·low_disruption11971 ··-·low_disruption
11972 ··-·medium_severity11972 ··-·medium_severity
11973 ··-·no_reboot_needed11973 ··-·no_reboot_needed
11974 ··-·package_sendmail_removed11974 ··-·package_sendmail_removed
 11975 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11976 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11977 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11978 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11979 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11980 package·--remove=sendmail
11975 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811981 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11976 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11982 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11977 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11983 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11978 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11984 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11979 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11985 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11980 include·remove_sendmail11986 include·remove_sendmail
Max diff block lines reached; 18588/23747 bytes (78.28%) of diff not shown.
1.36 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-cui.html
    
Offset 15098, 221 lines modifiedOffset 15098, 221 lines modified
0003af90:·6172·6765·743d·2223·6964·6d35·3639·3622··arget="#idm5696"0003af90:·6172·6765·743d·2223·6964·6d35·3639·3622··arget="#idm5696"
0003afa0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003afa0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003afb0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003afb0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003afc0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003afc0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003afd0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003afd0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003afe0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003afe0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003aff0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003aff0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003b000:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
0003b000:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003b010:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003b020:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b030:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b040:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b050:·2269·646d·3536·3936·223e·3c70·7265·3e3c··"idm5696"><pre>< 
0003b060:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003b070:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003b080:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003b090:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b0a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b0b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b0c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b0d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b0e0:·2223·6964·6d35·3639·3722·2074·6162·696e··"#idm5697"·tabin 
0003b0f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b100:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b110:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b120:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b130:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b140:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b150:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003b160:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b170:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b180:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b190:·6d35·3639·3722·3e3c·7461·626c·6520·636c··m5697"><table·cl 
0003b1a0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b1b0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b1c0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b1d0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b1e0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b1f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b200:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b210:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b220:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b230:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003b240:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003b250:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003b260:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003b270:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003b280:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0003b290:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b2a0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b2b0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b2c0:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu 
0003b2d0:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·|| 
0003b2e0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003b2f0:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then 
0003b300:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b310:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b320:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst 
0003b330:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b340:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b350:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b360:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b370:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b380:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b390:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b3a0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b3b0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b3c0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b3d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b3e0:·3d22·2369·646d·3536·3938·2220·7461·6269··="#idm5698"·tabi 
0003b3f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b400:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b410:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b420:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b430:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b440:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003b450:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b460:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003b010:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003b470:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003b020:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b480:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003b030:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b490:·3d22·6964·6d35·3639·3822·3e3c·7461·626c··="idm5698"><tabl0003b040:·6964·3d22·6964·6d35·3639·3622·3e3c·7461··id="idm5696"><ta
0003b4a0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003b050:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003b4b0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003b060:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003b4c0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003b070:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003b4d0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003b080:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003b4e0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003b090:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003b4f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b0a0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003b500:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003b0b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b510:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003b0c0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003b520:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b0d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003b530:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003b0e0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003b540:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003b0f0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003b550:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003b100:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b560:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b110:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003b570:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003b120:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003b580:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003b130:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003b590:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
0003b5a0:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
0003b5b0:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
0003b5c0:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
0003b5d0:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
0003b5e0:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003b5f0:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O 
0003b600:·4c30·382d·3030·2d30·3130·3335·390a·2020··L08-00-010359.·· 
0003b610:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
0003b620:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
0003b630:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
0003b640:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
0003b650:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
0003b660:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
0003b670:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d 
0003b680:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me 
0003b690:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.·· 
0003b6a0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need 
0003b6b0:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a 
0003b6c0:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..- 
0003b6d0:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai 
0003b6e0:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed. 
0003b6f0:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n 
0003b700:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st 
0003b710:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w 
0003b720:·6865·6e3a·2028·226b·6572·6e65·6c22·2069··hen:·("kernel"·i0003b140:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0003b150:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0003b160:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0003b170:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp
 0003b180:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
Max diff block lines reached; 1233437/1262583 bytes (97.69%) of diff not shown.
155 KB
html2text {}
    
Offset 108, 19 lines modifiedOffset 108, 14 lines modified
108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3108 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199110 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
111 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359111 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
112 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79112 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2113 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
114 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule114 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
116 [[packages]] 
117 name·=·"aide" 
118 version·=·"*" 
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
124 #·Remediation·is·applicable·only·in·certain·platforms120 #·Remediation·is·applicable·only·in·certain·platforms
125 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then121 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 166, 33 lines modifiedOffset 161, 38 lines modified
166 ··-·PCI-DSSv4-11.5.2161 ··-·PCI-DSSv4-11.5.2
167 ··-·enable_strategy162 ··-·enable_strategy
168 ··-·low_complexity163 ··-·low_complexity
169 ··-·low_disruption164 ··-·low_disruption
170 ··-·medium_severity165 ··-·medium_severity
171 ··-·no_reboot_needed166 ··-·no_reboot_needed
172 ··-·package_aide_installed167 ··-·package_aide_installed
 168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 173 package·--add=aide
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 175 [[packages]]
 176 name·=·"aide"
 177 version·=·"*"
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
178 include·install_aide183 include·install_aide
  
179 class·install_aide·{184 class·install_aide·{
180 ··package·{·'aide':185 ··package·{·'aide':
181 ····ensure·=>·'installed',186 ····ensure·=>·'installed',
182 ··}187 ··}
183 }188 }
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·--add=aide 
190 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules189 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
191 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.190 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
192 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.191 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.
  
193 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.192 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 340, 31 lines modifiedOffset 340, 31 lines modified
340 ············_\x8i_\x8s_\x8m······1446340 ············_\x8i_\x8s_\x8m······1446
341 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1341 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
342 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12342 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
343 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1343 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
344 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176344 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
345 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020345 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020
346 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule346 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule
347 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
348 [customizations] 
349 fips·=·true 
350 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8347 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
351 #·Remediation·is·applicable·only·in·certain·platforms348 #·Remediation·is·applicable·only·in·certain·platforms
352 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then349 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
353 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then350 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
354 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF351 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
355 kargs·=·["fips=1"]352 kargs·=·["fips=1"]
356 EOF353 EOF
357 fi354 fi
  
358 else355 else
359 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'356 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
360 fi357 fi
 358 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 359 [customizations]
 360 fips·=·true
361 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules361 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules
362 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:362 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
363 ····*·GnuTLS·library363 ····*·GnuTLS·library
364 ····*·OpenSSL·library364 ····*·OpenSSL·library
365 ····*·NSS·library365 ····*·NSS·library
366 ····*·OpenJDK366 ····*·OpenJDK
367 ····*·Libkrb5367 ····*·Libkrb5
Offset 376, 19 lines modifiedOffset 376, 14 lines modified
376 $·sudo·yum·install·crypto-policies376 $·sudo·yum·install·crypto-policies
377 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.377 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
378 Severity: ··medium378 Severity: ··medium
379 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed379 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
380 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123380 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
381 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1381 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
382 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174382 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
384 [[packages]] 
385 name·=·"crypto-policies" 
386 version·=·"*" 
387 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8383 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
388 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low384 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
389 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low385 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
390 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false386 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
391 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable387 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
392 if·!·rpm·-q·--quiet·"crypto-policies"·;·then388 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 406, 33 lines modifiedOffset 401, 38 lines modified
406 ··tags:401 ··tags:
407 ··-·enable_strategy402 ··-·enable_strategy
408 ··-·low_complexity403 ··-·low_complexity
409 ··-·low_disruption404 ··-·low_disruption
410 ··-·medium_severity405 ··-·medium_severity
Max diff block lines reached; 152367/159118 bytes (95.76%) of diff not shown.
664 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-e8.html
    
Offset 19374, 285 lines modifiedOffset 19374, 285 lines modified
0004bad0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0004bad0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0004bae0:·6964·6d31·3031·3432·2220·7461·6269·6e64··idm10142"·tabind0004bae0:·6964·6d31·3031·3432·2220·7461·6269·6e64··idm10142"·tabind
0004baf0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0004baf0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0004bb00:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0004bb00:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0004bb10:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0004bb10:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0004bb20:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0004bb20:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0004bb30:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0004bb30:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0004bb40:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0004bb40:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
0004bb50:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0004bb60:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0004bb70:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0004bb80:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0004bb90:·6170·7365·2220·6964·3d22·6964·6d31·3031··apse"·id="idm101 
0004bba0:·3432·223e·3c70·7265·3e3c·636f·6465·3e0a··42"><pre><code>. 
0004bbb0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0004bbc0:·6520·3d20·2272·6561·7222·0a76·6572·7369··e·=·"rear".versi 
0004bbd0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0004bbe0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0004bbf0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0004bc00:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0004bc10:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0004bc20:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
0004bc30:·3031·3433·2220·7461·6269·6e64·6578·3d22··0143"·tabindex=" 
0004bc40:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0004bc50:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0004bc60:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0004bc70:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0004bc80:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0004bc90:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0004bca0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0004bb50:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
0004bcb0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0004bb60:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0004bcc0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0004bb70:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0004bcd0:·7073·6522·2069·643d·2269·646d·3130·3134··pse"·id="idm10140004bb80:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0004bce0:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=0004bb90:·3130·3134·3222·3e3c·7461·626c·6520·636c··10142"><table·cl
0004bcf0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0004bba0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0004bd00:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0004bbb0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0004bd10:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0004bbc0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0004bd20:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0004bbd0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0004bd30:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0004bbe0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0004bd40:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0004bbf0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0004bd50:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0004bc00:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0004bd60:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0004bc10:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0004bd70:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R0004bc20:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0004bd80:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0004bc30:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0004bc40:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0004bc50:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0004bc60:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0004bd90:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t0004bc70:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0004bda0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0004bdb0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0004bdc0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0004bdd0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem0004bc80:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
0004bde0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl0004bc90:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
0004bdf0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c0004bca0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
0004be00:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms0004bcb0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
0004be10:·0a69·6620·2120·2820·2820·2820·2820·6772··.if·!·(·(·(·(·gr0004bcc0:·6f72·6d73·0a69·6620·2120·2820·2820·2820··orms.if·!·(·(·(·
0004be20:·6570·202d·7371·4520·225e·2e2a·5c2e·6161··ep·-sqE·"^.*\.aa0004bcd0:·2820·6772·6570·202d·7371·4520·225e·2e2a··(·grep·-sqE·"^.*
0004be30:·7263·6836·3424·2220·2f70·726f·632f·7379··rch64$"·/proc/sy 
0004be40:·732f·6b65·726e·656c·2f6f·7372·656c·6561··s/kernel/osrelea 
0004be50:·7365·207c·7c20·6772·6570·202d·7371·4520··se·||·grep·-sqE· 
0004be60:·225e·6161·7263·6836·3424·2220·2f70·726f··"^aarch64$"·/pro0004bce0:·5c2e·6161·7263·6836·3424·2220·2f70·726f··\.aarch64$"·/pro
0004be70:·632f·7379·732f·6b65·726e·656c·2f61·7263··c/sys/kernel/arc0004bcf0:·632f·7379·732f·6b65·726e·656c·2f6f·7372··c/sys/kernel/osr
0004be80:·683b·2029·2026·616d·703b·2661·6d70·3b20··h;·)·&amp;&amp;· 
0004be90:·6772·6570·202d·7150·2022·5e49·443d·5b5c··grep·-qP·"^ID=[\ 
0004bea0:·2227·5d3f·6f6c·5b5c·2227·5d3f·2422·2022··"']?ol[\"']?$"·" 
0004beb0:·2f65·7463·2f6f·732d·7265·6c65·6173·6522··/etc/os-release" 
0004bec0:·2026·616d·703b·2661·6d70·3b20·7b20·7265···&amp;&amp;·{·re 
0004bed0:·616c·3d22·2428·6772·6570·202d·5020·225e··al="$(grep·-P·"^ 
0004bee0:·5645·5253·494f·4e5f·4944·3d5b·5c22·275d··VERSION_ID=[\"'] 
0004bef0:·3f5b·5c77·2e5d·2b5b·5c22·275d·3f24·2220··?[\w.]+[\"']?$"· 
0004bf00:·2f65·7463·2f6f·732d·7265·6c65·6173·6520··/etc/os-release· 
0004bf10:·7c20·7365·6420·2273·2f5e·5645·5253·494f··|·sed·"s/^VERSIO 
0004bf20:·4e5f·4944·3d5b·5c22·275d·5c3f·5c28·5b5e··N_ID=[\"']\?\([^ 
0004bf30:·5c22·275d·5c2b·5c29·5b5c·2227·5d5c·3f24··\"']\+\)[\"']\?$ 
0004bf40:·2f5c·312f·2229·223b·2065·7870·6563·7465··/\1/")";·expecte 
0004bf50:·643d·2239·2e30·223b·2070·7269·6e74·6620··d="9.0";·printf· 
0004bf60:·2225·735c·6e25·7322·2022·2465·7870·6563··"%s\n%s"·"$expec 
0004bf70:·7465·6422·2022·2472·6561·6c22·207c·2073··ted"·"$real"·|·s 
0004bf80:·6f72·7420·2d56·433b·207d·2029·207c·7c20··ort·-VC;·}·)·||· 
0004bf90:·2820·2820·6772·6570·202d·7371·4520·225e··(·(·grep·-sqE·"^ 
0004bfa0:·2e2a·5c2e·6161·7263·6836·3424·2220·2f70··.*\.aarch64$"·/p 
0004bfb0:·726f·632f·7379·732f·6b65·726e·656c·2f6f··roc/sys/kernel/o 
0004bfc0:·7372·656c·6561·7365·207c·7c20·6772·6570··srelease·||·grep0004bd00:·656c·6561·7365·207c·7c20·6772·6570·202d··elease·||·grep·-
0004bfd0:·202d·7371·4520·225e·6161·7263·6836·3424···-sqE·"^aarch64$0004bd10:·7371·4520·225e·6161·7263·6836·3424·2220··sqE·"^aarch64$"·
 0004bd20:·2f70·726f·632f·7379·732f·6b65·726e·656c··/proc/sys/kernel
 0004bd30:·2f61·7263·683b·2029·2026·616d·703b·2661··/arch;·)·&amp;&a
 0004bd40:·6d70·3b20·6772·6570·202d·7150·2022·5e49··mp;·grep·-qP·"^I
 0004bd50:·443d·5b5c·2227·5d3f·6f6c·5b5c·2227·5d3f··D=[\"']?ol[\"']?
 0004bd60:·2422·2022·2f65·7463·2f6f·732d·7265·6c65··$"·"/etc/os-rele
 0004bd70:·6173·6522·2026·616d·703b·2661·6d70·3b20··ase"·&amp;&amp;·
 0004bd80:·7b20·7265·616c·3d22·2428·6772·6570·202d··{·real="$(grep·-
 0004bd90:·5020·225e·5645·5253·494f·4e5f·4944·3d5b··P·"^VERSION_ID=[
 0004bda0:·5c22·275d·3f5b·5c77·2e5d·2b5b·5c22·275d··\"']?[\w.]+[\"']
 0004bdb0:·3f24·2220·2f65·7463·2f6f·732d·7265·6c65··?$"·/etc/os-rele
 0004bdc0:·6173·6520·7c20·7365·6420·2273·2f5e·5645··ase·|·sed·"s/^VE
 0004bdd0:·5253·494f·4e5f·4944·3d5b·5c22·275d·5c3f··RSION_ID=[\"']\?
 0004bde0:·5c28·5b5e·5c22·275d·5c2b·5c29·5b5c·2227··\([^\"']\+\)[\"'
 0004bdf0:·5d5c·3f24·2f5c·312f·2229·223b·2065·7870··]\?$/\1/")";·exp
 0004be00:·6563·7465·643d·2239·2e30·223b·2070·7269··ected="9.0";·pri
 0004be10:·6e74·6620·2225·735c·6e25·7322·2022·2465··ntf·"%s\n%s"·"$e
 0004be20:·7870·6563·7465·6422·2022·2472·6561·6c22··xpected"·"$real"
 0004be30:·207c·2073·6f72·7420·2d56·433b·207d·2029···|·sort·-VC;·}·)
 0004be40:·207c·7c20·2820·2820·6772·6570·202d·7371···||·(·(·grep·-sq
 0004be50:·4520·225e·2e2a·5c2e·6161·7263·6836·3424··E·"^.*\.aarch64$
0004bfe0:·2220·2f70·726f·632f·7379·732f·6b65·726e··"·/proc/sys/kern0004be60:·2220·2f70·726f·632f·7379·732f·6b65·726e··"·/proc/sys/kern
 0004be70:·656c·2f6f·7372·656c·6561·7365·207c·7c20··el/osrelease·||·
 0004be80:·6772·6570·202d·7371·4520·225e·6161·7263··grep·-sqE·"^aarc
 0004be90:·6836·3424·2220·2f70·726f·632f·7379·732f··h64$"·/proc/sys/
0004bff0:·656c·2f61·7263·683b·2029·2026·616d·703b··el/arch;·)·&amp;0004bea0:·6b65·726e·656c·2f61·7263·683b·2029·2026··kernel/arch;·)·&
 0004beb0:·616d·703b·2661·6d70·3b20·6772·6570·202d··amp;&amp;·grep·-
0004c000:·2661·6d70·3b20·6772·6570·202d·7150·2022··&amp;·grep·-qP·" 
0004c010:·5e49·443d·5b5c·2227·5d3f·7268·656c·5b5c··^ID=[\"']?rhel[\ 
0004c020:·2227·5d3f·2422·2022·2f65·7463·2f6f·732d··"']?$"·"/etc/os- 
0004c030:·7265·6c65·6173·6522·2026·616d·703b·2661··release"·&amp;&a 
0004c040:·6d70·3b20·7b20·7265·616c·3d22·2428·6772··mp;·{·real="$(gr 
0004c050:·6570·202d·5020·225e·5645·5253·494f·4e5f··ep·-P·"^VERSION_ 
0004c060:·4944·3d5b·5c22·275d·3f5b·5c77·2e5d·2b5b··ID=[\"']?[\w.]+[ 
0004c070:·5c22·275d·3f24·2220·2f65·7463·2f6f·732d··\"']?$"·/etc/os- 
0004c080:·7265·6c65·6173·6520·7c20·7365·6420·2273··release·|·sed·"s 
0004c090:·2f5e·5645·5253·494f·4e5f·4944·3d5b·5c22··/^VERSION_ID=[\" 
0004c0a0:·275d·5c3f·5c28·5b5e·5c22·275d·5c2b·5c29··']\?\([^\"']\+\) 
0004c0b0:·5b5c·2227·5d5c·3f24·2f5c·312f·2229·223b··[\"']\?$/\1/")"; 
0004c0c0:·2065·7870·6563·7465·643d·2239·2e30·223b···expected="9.0"; 
0004c0d0:·2070·7269·6e74·6620·2225·735c·6e25·7322···printf·"%s\n%s" 
0004c0e0:·2022·2465·7870·6563·7465·6422·2022·2472···"$expected"·"$r 
0004c0f0:·6561·6c22·207c·2073·6f72·7420·2d56·433b··eal"·|·sort·-VC; 
0004c100:·207d·2029·207c·7c20·2820·6772·6570·202d···}·)·||·(·grep·- 
Max diff block lines reached; 575547/613525 bytes (93.81%) of diff not shown.
65.0 KB
html2text {}
    
Offset 1099, 19 lines modifiedOffset 1099, 14 lines modified
1099 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.1099 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.
1100 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1100 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1101 The·rear·package·can·be·installed·with·the·following·command:1101 The·rear·package·can·be·installed·with·the·following·command:
1102 $·sudo·yum·install·rear1102 $·sudo·yum·install·rear
1103 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.1103 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.
1104 Severity: ·medium1104 Severity: ·medium
1105 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed1105 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed
1106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1107 [[packages]] 
1108 name·=·"rear" 
1109 version·=·"*" 
1110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1115 #·Remediation·is·applicable·only·in·certain·platforms1111 #·Remediation·is·applicable·only·in·certain·platforms
1116 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1112 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1140, 33 lines modifiedOffset 1135, 38 lines modified
1140 ··tags:1135 ··tags:
1141 ··-·enable_strategy1136 ··-·enable_strategy
1142 ··-·low_complexity1137 ··-·low_complexity
1143 ··-·low_disruption1138 ··-·low_disruption
1144 ··-·medium_severity1139 ··-·medium_severity
1145 ··-·no_reboot_needed1140 ··-·no_reboot_needed
1146 ··-·package_rear_installed1141 ··-·package_rear_installed
 1142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1147 package·--add=rear
 1148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1149 [[packages]]
 1150 name·=·"rear"
 1151 version·=·"*"
1147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81152 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1153 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1154 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1155 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1156 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1152 include·install_rear1157 include·install_rear
  
1153 class·install_rear·{1158 class·install_rear·{
1154 ··package·{·'rear':1159 ··package·{·'rear':
1155 ····ensure·=>·'installed',1160 ····ensure·=>·'installed',
1156 ··}1161 ··}
1157 }1162 }
1158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1163 package·--add=rear 
1164 Group  ·Updating·Software·  Group·contains·6·rules1163 Group  ·Updating·Software·  Group·contains·6·rules
1165 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1164 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1166 Oracle·Linux·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1165 Oracle·Linux·8·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1167 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1166 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1168 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.1167 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
Offset 1878, 14 lines modifiedOffset 1878, 38 lines modified
1878 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"1878 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
1879 fi1879 fi
1880 fi1880 fi
  
1881 else1881 else
1882 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1882 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1883 fi1883 fi
 1884 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1885 ---
 1886 apiVersion:·machineconfiguration.openshift.io/v1
 1887 kind:·MachineConfig
 1888 spec:
 1889 ··config:
 1890 ····ignition:
 1891 ······version:·3.1.0
 1892 ····storage:
 1893 ······files:
 1894 ······-·contents:
 1895 ··········source:
 1896 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1897 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1898 ········mode:·0644
 1899 ········path:·/etc/pam.d/password-auth
 1900 ········overwrite:·true
 1901 ······-·contents:
 1902 ··········source:
 1903 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1904 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1905 ········mode:·0644
 1906 ········path:·/etc/pam.d/system-auth
 1907 ········overwrite:·true
1884 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81908 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1885 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1909 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1886 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1910 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1887 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1911 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1888 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure1912 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
1889 -·name:·Gather·the·package·facts1913 -·name:·Gather·the·package·facts
1890 ··package_facts:1914 ··package_facts:
Offset 2032, 38 lines modifiedOffset 2056, 14 lines modified
2032 ··-·PCI-DSSv4-8.3.12056 ··-·PCI-DSSv4-8.3.1
2033 ··-·configure_strategy2057 ··-·configure_strategy
2034 ··-·high_severity2058 ··-·high_severity
2035 ··-·low_complexity2059 ··-·low_complexity
2036 ··-·medium_disruption2060 ··-·medium_disruption
2037 ··-·no_empty_passwords2061 ··-·no_empty_passwords
2038 ··-·no_reboot_needed2062 ··-·no_reboot_needed
2039 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2040 --- 
2041 apiVersion:·machineconfiguration.openshift.io/v1 
2042 kind:·MachineConfig 
2043 spec: 
2044 ··config: 
2045 ····ignition: 
2046 ······version:·3.1.0 
2047 ····storage: 
2048 ······files: 
2049 ······-·contents: 
2050 ··········source: 
2051 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
2052 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
2053 ········mode:·0644 
Max diff block lines reached; 44145/66584 bytes (66.30%) of diff not shown.
615 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-hipaa.html
    
Offset 21738, 311 lines modifiedOffset 21738, 311 lines modified
00054e90:·743d·2223·6964·6d31·3431·3238·2220·7461··t="#idm14128"·ta00054e90:·743d·2223·6964·6d31·3431·3238·2220·7461··t="#idm14128"·ta
00054ea0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00054ea0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00054eb0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00054eb0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00054ec0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00054ec0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00054ed0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00054ed0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00054ee0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00054ee0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00054ef0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00054ef0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00054f00:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 00054f10:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00054f20:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00054f30:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00054f40:·2269·646d·3134·3132·3822·3e3c·7461·626c··"idm14128"><tabl
 00054f50:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00054f60:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00054f70:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00054f80:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00054f90:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00054fa0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00054fb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00054fc0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00054fd0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00054fe0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 00054ff0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 00055000:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00055010:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00055020:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr
 00055030:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00055040:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 00055050:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 00055060:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 00055070:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 00055080:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 00055090:·656c·207c·7c20·7270·6d20·2d2d·7175·6965··el·||·rpm·--quie
 000550a0:·7420·2d71·206b·6572·6e65·6c2d·7565·6b3b··t·-q·kernel-uek;
 000550b0:·2074·6865·6e0a·0a53·5953·5445·4d43·544c···then..SYSTEMCTL
 000550c0:·5f45·5845·433d·272f·7573·722f·6269·6e2f··_EXEC='/usr/bin/
 000550d0:·7379·7374·656d·6374·6c27·0a69·6620·5b5b··systemctl'.if·[[
 000550e0:·2024·2822·2453·5953·5445·4d43·544c·5f45···$("$SYSTEMCTL_E
 000550f0:·5845·4322·2069·732d·7379·7374·656d·2d72··XEC"·is-system-r
 00055100:·756e·6e69·6e67·2920·213d·2022·6f66·666c··unning)·!=·"offl
 00055110:·696e·6522·205d·5d3b·2074·6865·6e0a·2020··ine"·]];·then.··
00054f00:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
00054f10:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
00054f20:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00054f30:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00054f40:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00054f50:·6d31·3431·3238·223e·3c70·7265·3e3c·636f··m14128"><pre><co 
00054f60:·6465·3e0a·5b63·7573·746f·6d69·7a61·7469··de>.[customizati 
00054f70:·6f6e·732e·7365·7276·6963·6573·5d0a·6d61··ons.services].ma 
00054f80:·736b·6564·203d·205b·2264·6562·7567·2d73··sked·=·["debug-s 
00054f90:·6865·6c6c·225d·0a3c·2f63·6f64·653e·3c2f··hell"].</code></ 
00054fa0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00054fb0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00054fc0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00054fd0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00054fe0:·2d74·6172·6765·743d·2223·6964·6d31·3431··-target="#idm141 
00054ff0:·3239·2220·7461·6269·6e64·6578·3d22·3022··29"·tabindex="0" 
00055000:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00055010:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00055020:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00055030:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
00055040:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
00055050:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
00055060:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
00055070:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
00055080:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
00055090:·6522·2069·643d·2269·646d·3134·3132·3922··e"·id="idm14129" 
000550a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
000550b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
000550c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
000550d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
000550e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
000550f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00055100:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00055110:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00055120:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00055130:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00055140:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
00055150:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
00055160:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00055170:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t 
00055180:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
00055190:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
000551a0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
000551b0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
000551c0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
000551d0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
000551e0:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm· 
000551f0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
00055200:·6c2d·7565·6b3b·2074·6865·6e0a·0a53·5953··l-uek;·then..SYS 
00055210:·5445·4d43·544c·5f45·5845·433d·272f·7573··TEMCTL_EXEC='/us 
00055220:·722f·6269·6e2f·7379·7374·656d·6374·6c27··r/bin/systemctl' 
00055230:·0a69·6620·5b5b·2024·2822·2453·5953·5445··.if·[[·$("$SYSTE 
00055240:·4d43·544c·5f45·5845·4322·2069·732d·7379··MCTL_EXEC"·is-sy 
00055250:·7374·656d·2d72·756e·6e69·6e67·2920·213d··stem-running)·!= 
00055260:·2022·6f66·666c·696e·6522·205d·5d3b·2074···"offline"·]];·t 
00055270:·6865·6e0a·2020·2224·5359·5354·454d·4354··hen.··"$SYSTEMCT 
00055280:·4c5f·4558·4543·2220·7374·6f70·2027·6465··L_EXEC"·stop·'de 
00055290:·6275·672d·7368·656c·6c2e·7365·7276·6963··bug-shell.servic 
000552a0:·6527·0a66·690a·2224·5359·5354·454d·4354··e'.fi."$SYSTEMCT 
000552b0:·4c5f·4558·4543·2220·6469·7361·626c·6520··L_EXEC"·disable· 
000552c0:·2764·6562·7567·2d73·6865·6c6c·2e73·6572··'debug-shell.ser 
000552d0:·7669·6365·270a·2224·5359·5354·454d·4354··vice'."$SYSTEMCT 
000552e0:·4c5f·4558·4543·2220·6d61·736b·2027·6465··L_EXEC"·mask·'de 
000552f0:·6275·672d·7368·656c·6c2e·7365·7276·6963··bug-shell.servic 
00055300:·6527·0a23·2044·6973·6162·6c65·2073·6f63··e'.#·Disable·soc 
00055310:·6b65·7420·6163·7469·7661·7469·6f6e·2069··ket·activation·i 
00055320:·6620·7765·2068·6176·6520·6120·756e·6974··f·we·have·a·unit 
00055330:·2066·696c·6520·666f·7220·6974·0a69·6620···file·for·it.if· 
00055340:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC00055120:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC
 00055130:·2220·7374·6f70·2027·6465·6275·672d·7368··"·stop·'debug-sh
 00055140:·656c·6c2e·7365·7276·6963·6527·0a66·690a··ell.service'.fi.
00055350:·2220·2d71·206c·6973·742d·756e·6974·2d66··"·-q·list-unit-f 
00055360:·696c·6573·2064·6562·7567·2d73·6865·6c6c··iles·debug-shell 
00055370:·2e73·6f63·6b65·743b·2074·6865·6e0a·2020··.socket;·then.·· 
00055380:·2020·6966·205b·5b20·2428·2224·5359·5354····if·[[·$("$SYST 
00055390:·454d·4354·4c5f·4558·4543·2220·6973·2d73··EMCTL_EXEC"·is-s 
000553a0:·7973·7465·6d2d·7275·6e6e·696e·6729·2021··ystem-running)·! 
000553b0:·3d20·226f·6666·6c69·6e65·2220·5d5d·3b20··=·"offline"·]];· 
000553c0:·7468·656e·0a20·2020·2020·2022·2453·5953··then.······"$SYS 
000553d0:·5445·4d43·544c·5f45·5845·4322·2073·746f··TEMCTL_EXEC"·sto 
000553e0:·7020·2764·6562·7567·2d73·6865·6c6c·2e73··p·'debug-shell.s 
000553f0:·6f63·6b65·7427·0a20·2020·2066·690a·2020··ocket'.····fi.·· 
00055400:·2020·2224·5359·5354·454d·4354·4c5f·4558····"$SYSTEMCTL_EX00055150:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC
 00055160:·2220·6469·7361·626c·6520·2764·6562·7567··"·disable·'debug
 00055170:·2d73·6865·6c6c·2e73·6572·7669·6365·270a··-shell.service'.
 00055180:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC
Max diff block lines reached; 531257/572823 bytes (92.74%) of diff not shown.
55.5 KB
html2text {}
    
Offset 1556, 18 lines modifiedOffset 1556, 14 lines modified
1556 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-0022351556 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-002235
1557 ············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1557 ············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1558 References:·_\x8n_\x8i_\x8s_\x8t····CM-61558 References:·_\x8n_\x8i_\x8s_\x8t····CM-6
1559 ············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.11559 ············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.1
1560 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271560 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1561 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··OL08-00-0401801561 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··OL08-00-040180
1562 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-248872r991589_rule1562 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-248872r991589_rule
1563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1564 [customizations.services] 
1565 masked·=·["debug-shell"] 
1566 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1567 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1564 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1568 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1565 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1569 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1566 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1570 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1567 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1571 #·Remediation·is·applicable·only·in·certain·platforms1568 #·Remediation·is·applicable·only·in·certain·platforms
1572 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1569 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1684, 14 lines modifiedOffset 1680, 18 lines modified
1684 ··-·NIST-800-53-CM-61680 ··-·NIST-800-53-CM-6
1685 ··-·disable_strategy1681 ··-·disable_strategy
1686 ··-·low_complexity1682 ··-·low_complexity
1687 ··-·low_disruption1683 ··-·low_disruption
1688 ··-·medium_severity1684 ··-·medium_severity
1689 ··-·no_reboot_needed1685 ··-·no_reboot_needed
1690 ··-·service_debug-shell_disabled1686 ··-·service_debug-shell_disabled
 1687 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1688 [customizations.services]
 1689 masked·=·["debug-shell"]
1691 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81690 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1692 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1691 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1693 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1692 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1694 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1693 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1695 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1694 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1696 include·disable_debug-shell1695 include·disable_debug-shell
  
Offset 2198, 14 lines modifiedOffset 2198, 38 lines modified
2198 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"2198 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
2199 fi2199 fi
2200 fi2200 fi
  
2201 else2201 else
2202 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2202 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2203 fi2203 fi
 2204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2205 ---
 2206 apiVersion:·machineconfiguration.openshift.io/v1
 2207 kind:·MachineConfig
 2208 spec:
 2209 ··config:
 2210 ····ignition:
 2211 ······version:·3.1.0
 2212 ····storage:
 2213 ······files:
 2214 ······-·contents:
 2215 ··········source:
 2216 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 2217 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 2218 ········mode:·0644
 2219 ········path:·/etc/pam.d/password-auth
 2220 ········overwrite:·true
 2221 ······-·contents:
 2222 ··········source:
 2223 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 2224 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 2225 ········mode:·0644
 2226 ········path:·/etc/pam.d/system-auth
 2227 ········overwrite:·true
2204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2229 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2230 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2231 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure2232 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
2209 -·name:·Gather·the·package·facts2233 -·name:·Gather·the·package·facts
2210 ··package_facts:2234 ··package_facts:
Offset 2352, 38 lines modifiedOffset 2376, 14 lines modified
2352 ··-·PCI-DSSv4-8.3.12376 ··-·PCI-DSSv4-8.3.1
2353 ··-·configure_strategy2377 ··-·configure_strategy
2354 ··-·high_severity2378 ··-·high_severity
2355 ··-·low_complexity2379 ··-·low_complexity
2356 ··-·medium_disruption2380 ··-·medium_disruption
2357 ··-·no_empty_passwords2381 ··-·no_empty_passwords
2358 ··-·no_reboot_needed2382 ··-·no_reboot_needed
2359 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2360 --- 
2361 apiVersion:·machineconfiguration.openshift.io/v1 
2362 kind:·MachineConfig 
2363 spec: 
2364 ··config: 
2365 ····ignition: 
2366 ······version:·3.1.0 
2367 ····storage: 
2368 ······files: 
2369 ······-·contents: 
2370 ··········source: 
2371 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
2372 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
2373 ········mode:·0644 
2374 ········path:·/etc/pam.d/password-auth 
2375 ········overwrite:·true 
2376 ······-·contents: 
2377 ··········source: 
2378 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
2379 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
2380 ········mode:·0644 
2381 ········path:·/etc/pam.d/system-auth 
2382 ········overwrite:·true 
2383 Group  ·Restrict·Root·Logins·  Group·contains·3·rules2383 Group  ·Restrict·Root·Logins·  Group·contains·3·rules
2384 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.2384 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.
2385 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8ir\x8re\x8ec\x8ct\x8t·r\x8ro\x8oo\x8ot\x8t·L\x8Lo\x8og\x8gi\x8in\x8ns\x8s·N\x8No\x8ot\x8t·A\x8Al\x8ll\x8lo\x8ow\x8we\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2385 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8ir\x8re\x8ec\x8ct\x8t·r\x8ro\x8oo\x8ot\x8t·L\x8Lo\x8og\x8gi\x8in\x8ns\x8s·N\x8No\x8ot\x8t·A\x8Al\x8ll\x8lo\x8ow\x8we\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2386 To·further·limit·access·to·the·root·account,·administrators·can·disable·root·logins·at·the·console·by·editing·the·/etc/securetty·file.·This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does·not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the·system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous·as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in·plain·text·over·the·network.·By·default,·Oracle·Linux·8's·/etc/securetty·file·only·allows·the·root·user·to·login·at·the·console·physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the·contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this·file·by·typing·the·following·command:2386 To·further·limit·access·to·the·root·account,·administrators·can·disable·root·logins·at·the·console·by·editing·the·/etc/securetty·file.·This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does·not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the·system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous·as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in·plain·text·over·the·network.·By·default,·Oracle·Linux·8's·/etc/securetty·file·only·allows·the·root·user·to·login·at·the·console·physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the·contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this·file·by·typing·the·following·command:
2387 $·sudo·echo·>·/etc/securetty2387 $·sudo·echo·>·/etc/securetty
2388 Warning: ·This·rule·only·checks·the·/etc/securetty·file·existence·and·its·content.·If·you·need·to·restrict·user·access·using·the·/etc/securetty·file,·make·sure·the·pam_securetty.so·PAM·module·is·properly·enabled·in·relevant·PAM·files.2388 Warning: ·This·rule·only·checks·the·/etc/securetty·file·existence·and·its·content.·If·you·need·to·restrict·user·access·using·the·/etc/securetty·file,·make·sure·the·pam_securetty.so·PAM·module·is·properly·enabled·in·relevant·PAM·files.
2389 Rationale:··Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor·authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate·to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low·and·FISMA·Moderate·systems.2389 Rationale:··Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor·authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate·to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low·and·FISMA·Moderate·systems.
Offset 3493, 18 lines modifiedOffset 3493, 14 lines modified
3493 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.63493 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
3494 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.33494 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
3495 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-73495 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
3496 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-73496 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
3497 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002273497 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
3498 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-0400703498 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-040070
3499 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-248836r958498_rule3499 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-248836r958498_rule
3500 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3501 [customizations.services] 
3502 masked·=·["autofs"] 
Max diff block lines reached; 33441/56774 bytes (58.90%) of diff not shown.
1.01 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-ism_o.html
    
Offset 17335, 221 lines modifiedOffset 17335, 221 lines modified
00043b60:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00043b60:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00043b70:·3536·3936·2220·7461·6269·6e64·6578·3d22··5696"·tabindex="00043b70:·3536·3936·2220·7461·6269·6e64·6578·3d22··5696"·tabindex="
00043b80:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00043b80:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00043b90:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00043b90:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00043ba0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00043ba0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00043bb0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00043bb0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00043bc0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00043bc0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00043bd0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·00043bd0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
00043be0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
00043bf0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00043c00:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00043c10:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00043c20:·2220·6964·3d22·6964·6d35·3639·3622·3e3c··"·id="idm5696">< 
00043c30:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
00043c40:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
00043c50:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=· 
00043c60:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
00043c70:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00043c80:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00043c90:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00043ca0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00043cb0:·7267·6574·3d22·2369·646d·3536·3937·2220··rget="#idm5697"· 
00043cc0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00043cd0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00043ce0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00043cf0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00043d00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
00043d10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
00043d20:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
00043d30:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00043d40:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00043d50:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00043d60:·643d·2269·646d·3536·3937·223e·3c74·6162··d="idm5697"><tab 
00043d70:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
00043d80:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
00043d90:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
00043da0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
00043db0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
00043dc0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00043dd0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
00043de0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
00043df0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00043e00:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
00043e10:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
00043e20:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
00043e30:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
00043e40:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
00043e50:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
00043e60:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
00043e70:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
00043e80:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
00043e90:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm 
00043ea0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern 
00043eb0:·656c·207c·7c20·7270·6d20·2d2d·7175·6965··el·||·rpm·--quie 
00043ec0:·7420·2d71·206b·6572·6e65·6c2d·7565·6b3b··t·-q·kernel-uek; 
00043ed0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
00043ee0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
00043ef0:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum 
00043f00:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
00043f10:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
00043f20:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
00043f30:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
00043f40:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
00043f50:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
00043f60:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
00043f70:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
00043f80:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
00043f90:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
00043fa0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
00043fb0:·6172·6765·743d·2223·6964·6d35·3639·3822··arget="#idm5698" 
00043fc0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
00043fd0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
00043fe0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
00043ff0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
00044000:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
00044010:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
00044020:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
00044030:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d00043be0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
00044040:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-00043bf0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
00044050:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00043c00:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
00044060:·6522·2069·643d·2269·646d·3536·3938·223e··e"·id="idm5698">00043c10:·7073·6522·2069·643d·2269·646d·3536·3936··pse"·id="idm5696
00044070:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta00043c20:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
00044080:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe00043c30:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
00044090:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered00043c40:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
000440a0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed00043c50:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
000440b0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple00043c60:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
000440c0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo00043c70:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
000440d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><00043c80:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
000440e0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</00043c90:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
000440f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00043ca0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
00044100:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo00043cb0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
00044110:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals00043cc0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
00044120:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><00043cd0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
00044130:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th00043ce0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
00044140:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>00043cf0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
00044150:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr00043d00:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
00044160:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·00043d10:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
00044170:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa00043d20:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 00043d30:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 00043d40:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00043d50:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 00043d60:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm·
 00043d70:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 00043d80:·6c2d·7565·6b3b·2074·6865·6e0a·0a69·6620··l-uek;·then..if·
 00043d90:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet
 00043da0:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.·
 00043db0:·2020·2079·756d·2069·6e73·7461·6c6c·202d·····yum·install·-
 00043dc0:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els
 00043dd0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 00043de0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 00043df0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 00043e00:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 00043e10:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 00043e20:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00043e30:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00043e40:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 00043e50:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 00043e60:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 00043e70:·6d35·3639·3722·2074·6162·696e·6465·783d··m5697"·tabindex=
 00043e80:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 00043e90:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 00043ea0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 00043eb0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 00043ec0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 00043ed0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
 00043ee0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
 00043ef0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
Max diff block lines reached; 926547/955693 bytes (96.95%) of diff not shown.
97.6 KB
html2text {}
    
Offset 683, 19 lines modifiedOffset 683, 14 lines modified
683 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3683 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
684 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5684 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
685 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199685 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
686 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359686 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
687 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79687 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
688 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2688 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
689 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule689 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
690 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
691 [[packages]] 
692 name·=·"aide" 
693 version·=·"*" 
694 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8690 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
695 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low691 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
696 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low692 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
697 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false693 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
698 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable694 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
699 #·Remediation·is·applicable·only·in·certain·platforms695 #·Remediation·is·applicable·only·in·certain·platforms
700 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then696 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 741, 33 lines modifiedOffset 736, 38 lines modified
741 ··-·PCI-DSSv4-11.5.2736 ··-·PCI-DSSv4-11.5.2
742 ··-·enable_strategy737 ··-·enable_strategy
743 ··-·low_complexity738 ··-·low_complexity
744 ··-·low_disruption739 ··-·low_disruption
745 ··-·medium_severity740 ··-·medium_severity
746 ··-·no_reboot_needed741 ··-·no_reboot_needed
747 ··-·package_aide_installed742 ··-·package_aide_installed
 743 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 744 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 745 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 746 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 747 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 748 package·--add=aide
 749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 750 [[packages]]
 751 name·=·"aide"
 752 version·=·"*"
748 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8753 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
749 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low754 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
750 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low755 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
751 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false756 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
752 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable757 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
753 include·install_aide758 include·install_aide
  
754 class·install_aide·{759 class·install_aide·{
755 ··package·{·'aide':760 ··package·{·'aide':
756 ····ensure·=>·'installed',761 ····ensure·=>·'installed',
757 ··}762 ··}
758 }763 }
759 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
760 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
761 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
762 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
763 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
764 package·--add=aide 
765 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules764 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
766 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.765 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
767 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.766 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.
  
768 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.767 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
769 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*768 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 915, 31 lines modifiedOffset 915, 31 lines modified
915 ············_\x8i_\x8s_\x8m······1446915 ············_\x8i_\x8s_\x8m······1446
916 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1916 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
917 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12917 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
918 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1918 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
919 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176919 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
920 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020920 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020
921 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule921 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule
922 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
923 [customizations] 
924 fips·=·true 
925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8922 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
926 #·Remediation·is·applicable·only·in·certain·platforms923 #·Remediation·is·applicable·only·in·certain·platforms
927 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then924 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
928 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then925 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
929 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF926 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
930 kargs·=·["fips=1"]927 kargs·=·["fips=1"]
931 EOF928 EOF
932 fi929 fi
  
933 else930 else
934 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'931 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
935 fi932 fi
 933 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 934 [customizations]
 935 fips·=·true
936 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules936 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules
937 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:937 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
938 ····*·GnuTLS·library938 ····*·GnuTLS·library
939 ····*·OpenSSL·library939 ····*·OpenSSL·library
940 ····*·NSS·library940 ····*·NSS·library
941 ····*·OpenJDK941 ····*·OpenJDK
942 ····*·Libkrb5942 ····*·Libkrb5
Offset 1250, 19 lines modifiedOffset 1250, 14 lines modified
1250 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351250 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1251 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861251 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1252 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1252 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1253 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11253 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1254 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251254 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1255 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331255 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1256 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21256 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1258 [[packages]] 
1259 name·=·"sudo" 
1260 version·=·"*" 
1261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81257 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1262 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1258 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1263 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1259 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1264 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1260 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1265 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1261 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1266 #·Remediation·is·applicable·only·in·certain·platforms1262 #·Remediation·is·applicable·only·in·certain·platforms
1267 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1263 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1304, 33 lines modifiedOffset 1299, 38 lines modified
1304 ··-·PCI-DSSv4-2.2.61299 ··-·PCI-DSSv4-2.2.6
1305 ··-·enable_strategy1300 ··-·enable_strategy
1306 ··-·low_complexity1301 ··-·low_complexity
1307 ··-·low_disruption1302 ··-·low_disruption
1308 ··-·medium_severity1303 ··-·medium_severity
Max diff block lines reached; 93531/99953 bytes (93.57%) of diff not shown.
1.36 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-ospp.html
    
Offset 15073, 221 lines modifiedOffset 15073, 221 lines modified
0003ae00:·6172·6765·743d·2223·6964·6d35·3639·3622··arget="#idm5696"0003ae00:·6172·6765·743d·2223·6964·6d35·3639·3622··arget="#idm5696"
0003ae10:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003ae10:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003ae20:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003ae20:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003ae30:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003ae30:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003ae40:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003ae40:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003ae50:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003ae50:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003ae60:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003ae60:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003ae70:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
0003ae70:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003ae80:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003ae90:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003aea0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003aeb0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003aec0:·2269·646d·3536·3936·223e·3c70·7265·3e3c··"idm5696"><pre>< 
0003aed0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003aee0:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003aef0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003af00:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003af10:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003af20:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003af30:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003af40:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003af50:·2223·6964·6d35·3639·3722·2074·6162·696e··"#idm5697"·tabin 
0003af60:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003af70:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003af80:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003af90:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003afa0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003afb0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003afc0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
0003afd0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003afe0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003aff0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b000:·6d35·3639·3722·3e3c·7461·626c·6520·636c··m5697"><table·cl 
0003b010:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b020:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b030:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b040:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b050:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b060:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b070:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b080:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b090:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b0a0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003b0b0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003b0c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003b0d0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003b0e0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003b0f0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0003b100:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b110:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b120:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b130:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu 
0003b140:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·|| 
0003b150:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003b160:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then 
0003b170:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b180:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b190:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst 
0003b1a0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b1b0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b1c0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b1d0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b1e0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b1f0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b200:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b210:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b220:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b230:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b240:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b250:·3d22·2369·646d·3536·3938·2220·7461·6269··="#idm5698"·tabi 
0003b260:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b270:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b280:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b290:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b2a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b2b0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003b2c0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b2d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003ae80:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003b2e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003ae90:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003b2f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003aea0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003b300:·3d22·6964·6d35·3639·3822·3e3c·7461·626c··="idm5698"><tabl0003aeb0:·6964·3d22·6964·6d35·3639·3622·3e3c·7461··id="idm5696"><ta
0003b310:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003aec0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003b320:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003aed0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003b330:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003aee0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003b340:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003aef0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003b350:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003af00:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003b360:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003af10:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003b370:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0003af20:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b380:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t0003af30:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003b390:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003af40:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003b3a0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0003af50:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003b3b0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td0003af60:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003b3c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003af70:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b3d0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003af80:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003b3e0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>0003af90:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
0003b3f0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0003afa0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
0003b400:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
0003b410:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
0003b420:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
0003b430:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
0003b440:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
0003b450:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003b460:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O 
0003b470:·4c30·382d·3030·2d30·3130·3335·390a·2020··L08-00-010359.·· 
0003b480:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
0003b490:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
0003b4a0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
0003b4b0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
0003b4c0:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
0003b4d0:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
0003b4e0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d 
0003b4f0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me 
0003b500:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.·· 
0003b510:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need 
0003b520:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a 
0003b530:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..- 
0003b540:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai 
0003b550:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed. 
0003b560:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n 
0003b570:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st 
0003b580:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w 
0003b590:·6865·6e3a·2028·226b·6572·6e65·6c22·2069··hen:·("kernel"·i0003afb0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0003afc0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0003afd0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0003afe0:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp
 0003aff0:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
Max diff block lines reached; 1234127/1263273 bytes (97.69%) of diff not shown.
155 KB
html2text {}
    
Offset 101, 19 lines modifiedOffset 101, 14 lines modified
101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
104 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359104 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
105 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79105 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
107 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule107 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
109 [[packages]] 
110 name·=·"aide" 
111 version·=·"*" 
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
117 #·Remediation·is·applicable·only·in·certain·platforms113 #·Remediation·is·applicable·only·in·certain·platforms
118 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then114 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 159, 33 lines modifiedOffset 154, 38 lines modified
159 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy155 ··-·enable_strategy
161 ··-·low_complexity156 ··-·low_complexity
162 ··-·low_disruption157 ··-·low_disruption
163 ··-·medium_severity158 ··-·medium_severity
164 ··-·no_reboot_needed159 ··-·no_reboot_needed
165 ··-·package_aide_installed160 ··-·package_aide_installed
 161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 166 package·--add=aide
 167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 168 [[packages]]
 169 name·=·"aide"
 170 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
171 include·install_aide176 include·install_aide
  
172 class·install_aide·{177 class·install_aide·{
173 ··package·{·'aide':178 ··package·{·'aide':
174 ····ensure·=>·'installed',179 ····ensure·=>·'installed',
175 ··}180 ··}
176 }181 }
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
182 package·--add=aide 
183 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules182 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
184 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.183 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
185 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.184 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·8.
  
186 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.185 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
187 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*186 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 333, 31 lines modifiedOffset 333, 31 lines modified
333 ············_\x8i_\x8s_\x8m······1446333 ············_\x8i_\x8s_\x8m······1446
334 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1334 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
335 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12335 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
336 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1336 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
337 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176337 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
338 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020338 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020
339 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule339 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule
340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
341 [customizations] 
342 fips·=·true 
343 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8340 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
344 #·Remediation·is·applicable·only·in·certain·platforms341 #·Remediation·is·applicable·only·in·certain·platforms
345 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then342 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
346 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then343 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
347 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF344 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
348 kargs·=·["fips=1"]345 kargs·=·["fips=1"]
349 EOF346 EOF
350 fi347 fi
  
351 else348 else
352 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'349 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
353 fi350 fi
 351 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 352 [customizations]
 353 fips·=·true
354 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules354 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules
355 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:355 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
356 ····*·GnuTLS·library356 ····*·GnuTLS·library
357 ····*·OpenSSL·library357 ····*·OpenSSL·library
358 ····*·NSS·library358 ····*·NSS·library
359 ····*·OpenJDK359 ····*·OpenJDK
360 ····*·Libkrb5360 ····*·Libkrb5
Offset 369, 19 lines modifiedOffset 369, 14 lines modified
369 $·sudo·yum·install·crypto-policies369 $·sudo·yum·install·crypto-policies
370 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.370 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
371 Severity: ··medium371 Severity: ··medium
372 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed372 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
373 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123373 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
374 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1374 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
375 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174375 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
376 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
377 [[packages]] 
378 name·=·"crypto-policies" 
379 version·=·"*" 
380 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8376 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
381 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low377 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
382 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low378 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
383 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false379 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
384 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable380 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
385 if·!·rpm·-q·--quiet·"crypto-policies"·;·then381 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 399, 33 lines modifiedOffset 394, 38 lines modified
399 ··tags:394 ··tags:
400 ··-·enable_strategy395 ··-·enable_strategy
401 ··-·low_complexity396 ··-·low_complexity
402 ··-·low_disruption397 ··-·low_disruption
403 ··-·medium_severity398 ··-·medium_severity
Max diff block lines reached; 152367/159118 bytes (95.76%) of diff not shown.
857 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-pci-dss.html
    
Offset 16590, 221 lines modifiedOffset 16590, 221 lines modified
00040cd0:·6172·6765·743d·2223·6964·6d35·3639·3622··arget="#idm5696"00040cd0:·6172·6765·743d·2223·6964·6d35·3639·3622··arget="#idm5696"
00040ce0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00040ce0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00040cf0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00040cf0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00040d00:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00040d00:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00040d10:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00040d10:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00040d20:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00040d20:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
00040d30:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati00040d30:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 00040d40:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
00040d40:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
00040d50:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
00040d60:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
00040d70:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
00040d80:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00040d90:·2269·646d·3536·3936·223e·3c70·7265·3e3c··"idm5696"><pre>< 
00040da0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
00040db0:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
00040dc0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
00040dd0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
00040de0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
00040df0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
00040e00:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
00040e10:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
00040e20:·2223·6964·6d35·3639·3722·2074·6162·696e··"#idm5697"·tabin 
00040e30:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
00040e40:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
00040e50:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
00040e60:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
00040e70:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
00040e80:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
00040e90:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a 
00040ea0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00040eb0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00040ec0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00040ed0:·6d35·3639·3722·3e3c·7461·626c·6520·636c··m5697"><table·cl 
00040ee0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
00040ef0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00040f00:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00040f10:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00040f20:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00040f30:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00040f40:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00040f50:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
00040f60:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00040f70:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
00040f80:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
00040f90:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
00040fa0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
00040fb0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
00040fc0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
00040fd0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
00040fe0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
00040ff0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
00041000:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu 
00041010:·6965·7420·2d71·206b·6572·6e65·6c20·7c7c··iet·-q·kernel·|| 
00041020:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
00041030:·6b65·726e·656c·2d75·656b·3b20·7468·656e··kernel-uek;·then 
00041040:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
00041050:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
00041060:·6865·6e0a·2020·2020·7975·6d20·696e·7374··hen.····yum·inst 
00041070:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
00041080:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
00041090:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
000410a0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
000410b0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
000410c0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
000410d0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
000410e0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
000410f0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
00041100:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
00041110:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
00041120:·3d22·2369·646d·3536·3938·2220·7461·6269··="#idm5698"·tabi 
00041130:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
00041140:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
00041150:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00041160:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00041170:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00041180:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
00041190:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
000411a0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl00040d50:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
000411b0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00040d60:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
000411c0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00040d70:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
000411d0:·3d22·6964·6d35·3639·3822·3e3c·7461·626c··="idm5698"><tabl00040d80:·6964·3d22·6964·6d35·3639·3622·3e3c·7461··id="idm5696"><ta
000411e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t00040d90:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
000411f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab00040da0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
00041200:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl00040db0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
00041210:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr00040dc0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
00041220:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:00040dd0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
00041230:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td00040de0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
00041240:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di00040df0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00041250:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t00040e00:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
00041260:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><00040e10:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
00041270:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</00040e20:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
00041280:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td00040e30:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
00041290:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St00040e40:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
000412a0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>00040e50:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
000412b0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>00040e60:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
000412c0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co00040e70:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
000412d0:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
000412e0:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
000412f0:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
00041300:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
00041310:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
00041320:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
00041330:·0a20·202d·2044·4953·412d·5354·4947·2d4f··.··-·DISA-STIG-O 
00041340:·4c30·382d·3030·2d30·3130·3335·390a·2020··L08-00-010359.·· 
00041350:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
00041360:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
00041370:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
00041380:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
00041390:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
000413a0:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
000413b0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d 
000413c0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me 
000413d0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.·· 
000413e0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need 
000413f0:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a 
00041400:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..- 
00041410:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai 
00041420:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed. 
00041430:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n 
00041440:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st 
00041450:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w 
00041460:·6865·6e3a·2028·226b·6572·6e65·6c22·2069··hen:·("kernel"·i00040e80:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 00040e90:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 00040ea0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 00040eb0:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp
 00040ec0:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
Max diff block lines reached; 759183/788329 bytes (96.30%) of diff not shown.
86.6 KB
html2text {}
    
Offset 497, 19 lines modifiedOffset 497, 14 lines modified
497 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3497 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
498 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5498 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
499 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199499 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
500 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359500 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
501 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79501 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
502 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2502 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
503 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule503 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
504 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
505 [[packages]] 
506 name·=·"aide" 
507 version·=·"*" 
508 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8504 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
509 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low505 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
510 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low506 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
511 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false507 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
512 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable508 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
513 #·Remediation·is·applicable·only·in·certain·platforms509 #·Remediation·is·applicable·only·in·certain·platforms
514 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then510 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 555, 33 lines modifiedOffset 550, 38 lines modified
555 ··-·PCI-DSSv4-11.5.2550 ··-·PCI-DSSv4-11.5.2
556 ··-·enable_strategy551 ··-·enable_strategy
557 ··-·low_complexity552 ··-·low_complexity
558 ··-·low_disruption553 ··-·low_disruption
559 ··-·medium_severity554 ··-·medium_severity
560 ··-·no_reboot_needed555 ··-·no_reboot_needed
561 ··-·package_aide_installed556 ··-·package_aide_installed
 557 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 558 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 559 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 560 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 561 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 562 package·--add=aide
 563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 564 [[packages]]
 565 name·=·"aide"
 566 version·=·"*"
562 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8567 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
563 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low568 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
564 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low569 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
565 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false570 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
566 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable571 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
567 include·install_aide572 include·install_aide
  
568 class·install_aide·{573 class·install_aide·{
569 ··package·{·'aide':574 ··package·{·'aide':
570 ····ensure·=>·'installed',575 ····ensure·=>·'installed',
571 ··}576 ··}
572 }577 }
573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
574 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
575 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
576 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
577 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
578 package·--add=aide 
579 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*578 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
580 Run·the·following·command·to·generate·a·new·database:579 Run·the·following·command·to·generate·a·new·database:
581 $·sudo·/usr/sbin/aide·--init580 $·sudo·/usr/sbin/aide·--init
582 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:581 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
583 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz582 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
584 To·initiate·a·manual·check,·run·the·following·command:583 To·initiate·a·manual·check,·run·the·following·command:
585 $·sudo·/usr/sbin/aide·--check584 $·sudo·/usr/sbin/aide·--check
Offset 2687, 19 lines modifiedOffset 2687, 14 lines modified
2687 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022352687 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
2688 ············_\x8i_\x8s_\x8m·····1382,·1384,·13862688 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
2689 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)2689 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
2690 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.12690 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
2691 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001252691 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
2692 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R332692 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
2693 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.22693 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
2694 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2695 [[packages]] 
2696 name·=·"sudo" 
2697 version·=·"*" 
2698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82694 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2699 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2695 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2700 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2696 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2701 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2697 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2702 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2698 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2703 #·Remediation·is·applicable·only·in·certain·platforms2699 #·Remediation·is·applicable·only·in·certain·platforms
2704 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then2700 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 2741, 33 lines modifiedOffset 2736, 38 lines modified
2741 ··-·PCI-DSSv4-2.2.62736 ··-·PCI-DSSv4-2.2.6
2742 ··-·enable_strategy2737 ··-·enable_strategy
2743 ··-·low_complexity2738 ··-·low_complexity
2744 ··-·low_disruption2739 ··-·low_disruption
2745 ··-·medium_severity2740 ··-·medium_severity
2746 ··-·no_reboot_needed2741 ··-·no_reboot_needed
2747 ··-·package_sudo_installed2742 ··-·package_sudo_installed
 2743 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2744 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2745 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2746 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2747 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2748 package·--add=sudo
 2749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2750 [[packages]]
 2751 name·=·"sudo"
 2752 version·=·"*"
2748 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82753 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2749 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2754 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2750 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2755 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2751 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2756 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2752 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2757 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2753 include·install_sudo2758 include·install_sudo
  
2754 class·install_sudo·{2759 class·install_sudo·{
2755 ··package·{·'sudo':2760 ··package·{·'sudo':
2756 ····ensure·=>·'installed',2761 ····ensure·=>·'installed',
2757 ··}2762 ··}
2758 }2763 }
2759 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2760 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2761 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2762 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2763 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2764 package·--add=sudo 
2765 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2764 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2766 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.2765 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
2767 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.2766 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.
Max diff block lines reached; 82949/88643 bytes (93.58%) of diff not shown.
403 KB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-standard.html
    
Offset 21998, 864 lines modifiedOffset 21998, 864 lines modified
00055ed0:·612d·7461·7267·6574·3d22·2369·646d·3136··a-target="#idm1600055ed0:·612d·7461·7267·6574·3d22·2369·646d·3136··a-target="#idm16
00055ee0:·3638·3322·2074·6162·696e·6465·783d·2230··683"·tabindex="000055ee0:·3638·3322·2074·6162·696e·6465·783d·2230··683"·tabindex="0
00055ef0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00055ef0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00055f00:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00055f00:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00055f10:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00055f10:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00055f20:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00055f20:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00055f30:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00055f30:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00055f40:·6961·7469·6f6e·204b·7562·6572·6e65·7465··iation·Kubernete
 00055f50:·7320·736e·6970·7065·7420·e287·b23c·2f61··s·snippet·...</a
 00055f60:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00055f70:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00055f80:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00055f90:·6d31·3636·3833·223e·3c70·7265·3e3c·636f··m16683"><pre><co
 00055fa0:·6465·3e2d·2d2d·0a61·7069·5665·7273·696f··de>---.apiVersio
00055f40:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
00055f50:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00055f60:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00055f70:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00055f80:·6c61·7073·6522·2069·643d·2269·646d·3136··lapse"·id="idm16 
00055f90:·3638·3322·3e3c·7461·626c·6520·636c·6173··683"><table·clas 
00055fa0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
00055fb0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
00055fc0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
00055fd0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
00055fe0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
00055ff0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00056000:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
00056010:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi 
00056020:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr> 
00056030:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
00056040:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
00056050:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
00056060:·6567·793a·3c2f·7468·3e3c·7464·3e63·6f6e··egy:</th><td>con 
00056070:·6669·6775·7265·3c2f·7464·3e3c·2f74·723e··figure</td></tr> 
00056080:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00056090:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
000560a0:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
000560b0:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
000560c0:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
000560d0:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
000560e0:·202d·2043·4a49·532d·352e·352e·320a·2020···-·CJIS-5.5.2.·· 
000560f0:·2d20·4449·5341·2d53·5449·472d·4f4c·3038··-·DISA-STIG-OL08 
00056100:·2d30·302d·3032·3033·3331·0a20·202d·2044··-00-020331.··-·D 
00056110:·4953·412d·5354·4947·2d4f·4c30·382d·3030··ISA-STIG-OL08-00 
00056120:·2d30·3230·3333·320a·2020·2d20·4e49·5354··-020332.··-·NIST 
00056130:·2d38·3030·2d31·3731·2d33·2e31·2e31·0a20··-800-171-3.1.1.· 
00056140:·202d·204e·4953·542d·3830·302d·3137·312d···-·NIST-800-171- 
00056150:·332e·312e·350a·2020·2d20·4e49·5354·2d38··3.1.5.··-·NIST-8 
00056160:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).·· 
00056170:·2d20·4e49·5354·2d38·3030·2d35·332d·4941··-·NIST-800-53-IA 
00056180:·2d35·2831·2928·6129·0a20·202d·204e·4953··-5(1)(a).··-·NIS 
00056190:·542d·3830·302d·3533·2d49·412d·3528·6329··T-800-53-IA-5(c) 
000561a0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
000561b0:·2d38·2e32·2e33·0a20·202d·2050·4349·2d44··-8.2.3.··-·PCI-D 
000561c0:·5353·7634·2d38·2e33·0a20·202d·2050·4349··SSv4-8.3.··-·PCI 
000561d0:·2d44·5353·7634·2d38·2e33·2e31·0a20·202d··-DSSv4-8.3.1.··- 
000561e0:·2063·6f6e·6669·6775·7265·5f73·7472·6174···configure_strat 
000561f0:·6567·790a·2020·2d20·6869·6768·5f73·6576··egy.··-·high_sev 
00056200:·6572·6974·790a·2020·2d20·6c6f·775f·636f··erity.··-·low_co 
00056210:·6d70·6c65·7869·7479·0a20·202d·206d·6564··mplexity.··-·med 
00056220:·6975·6d5f·6469·7372·7570·7469·6f6e·0a20··ium_disruption.· 
00056230:·202d·206e·6f5f·656d·7074·795f·7061·7373···-·no_empty_pass 
00056240:·776f·7264·730a·2020·2d20·6e6f·5f72·6562··words.··-·no_reb 
00056250:·6f6f·745f·6e65·6564·6564·0a0a·2d20·6e61··oot_needed..-·na 
00056260:·6d65·3a20·5072·6576·656e·7420·4c6f·6769··me:·Prevent·Logi 
00056270:·6e20·746f·2041·6363·6f75·6e74·7320·5769··n·to·Accounts·Wi 
00056280:·7468·2045·6d70·7479·2050·6173·7377·6f72··th·Empty·Passwor 
00056290:·6420·2d20·4368·6563·6b20·6966·2073·7973··d·-·Check·if·sys 
000562a0:·7465·6d20·7265·6c69·6573·206f·6e0a·2020··tem·relies·on.·· 
000562b0:·2020·6175·7468·7365·6c65·6374·0a20·2061····authselect.··a 
000562c0:·6e73·6962·6c65·2e62·7569·6c74·696e·2e73··nsible.builtin.s 
000562d0:·7461·743a·0a20·2020·2070·6174·683a·202f··tat:.····path:·/ 
000562e0:·7573·722f·6269·6e2f·6175·7468·7365·6c65··usr/bin/authsele 
000562f0:·6374·0a20·2072·6567·6973·7465·723a·2072··ct.··register:·r 
00056300:·6573·756c·745f·6175·7468·7365·6c65·6374··esult_authselect 
00056310:·5f70·7265·7365·6e74·0a20·2077·6865·6e3a··_present.··when: 
00056320:·2028·226b·6572·6e65·6c22·2069·6e20·616e···("kernel"·in·an 
00056330:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack 
00056340:·6167·6573·206f·7220·226b·6572·6e65·6c2d··ages·or·"kernel- 
00056350:·7565·6b22·2069·6e20·616e·7369·626c·655f··uek"·in·ansible_ 
00056360:·6661·6374·732e·7061·636b·6167·6573·290a··facts.packages). 
00056370:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS 
00056380:·2d35·2e35·2e32·0a20·202d·2044·4953·412d··-5.5.2.··-·DISA- 
00056390:·5354·4947·2d4f·4c30·382d·3030·2d30·3230··STIG-OL08-00-020 
000563a0:·3333·310a·2020·2d20·4449·5341·2d53·5449··331.··-·DISA-STI 
000563b0:·472d·4f4c·3038·2d30·302d·3032·3033·3332··G-OL08-00-020332 
000563c0:·0a20·202d·204e·4953·542d·3830·302d·3137··.··-·NIST-800-17 
000563d0:·312d·332e·312e·310a·2020·2d20·4e49·5354··1-3.1.1.··-·NIST 
000563e0:·2d38·3030·2d31·3731·2d33·2e31·2e35·0a20··-800-171-3.1.5.· 
000563f0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
00056400:·4d2d·3628·6129·0a20·202d·204e·4953·542d··M-6(a).··-·NIST- 
00056410:·3830·302d·3533·2d49·412d·3528·3129·2861··800-53-IA-5(1)(a 
00056420:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
00056430:·332d·4941·2d35·2863·290a·2020·2d20·5043··3-IA-5(c).··-·PC 
00056440:·492d·4453·532d·5265·712d·382e·322e·330a··I-DSS-Req-8.2.3. 
00056450:·2020·2d20·5043·492d·4453·5376·342d·382e····-·PCI-DSSv4-8. 
00056460:·330a·2020·2d20·5043·492d·4453·5376·342d··3.··-·PCI-DSSv4- 
00056470:·382e·332e·310a·2020·2d20·636f·6e66·6967··8.3.1.··-·config 
00056480:·7572·655f·7374·7261·7465·6779·0a20·202d··ure_strategy.··- 
00056490:·2068·6967·685f·7365·7665·7269·7479·0a20···high_severity.· 
000564a0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
000564b0:·790a·2020·2d20·6d65·6469·756d·5f64·6973··y.··-·medium_dis 
000564c0:·7275·7074·696f·6e0a·2020·2d20·6e6f·5f65··ruption.··-·no_e 
000564d0:·6d70·7479·5f70·6173·7377·6f72·6473·0a20··mpty_passwords.· 
000564e0:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
000564f0:·6465·640a·0a2d·206e·616d·653a·2050·7265··ded..-·name:·Pre 
00056500:·7665·6e74·204c·6f67·696e·2074·6f20·4163··vent·Login·to·Ac 
00056510:·636f·756e·7473·2057·6974·6820·456d·7074··counts·With·Empt 
00056520:·7920·5061·7373·776f·7264·202d·2052·656d··y·Password·-·Rem 
00056530:·6564·6961·7465·2075·7369·6e67·2061·7574··ediate·using·aut 
00056540:·6873·656c·6563·740a·2020·626c·6f63·6b3a··hselect.··block: 
00056550:·0a0a·2020·2d20·6e61·6d65·3a20·5072·6576··..··-·name:·Prev 
00056560:·656e·7420·4c6f·6769·6e20·746f·2041·6363··ent·Login·to·Acc 
00056570:·6f75·6e74·7320·5769·7468·2045·6d70·7479··ounts·With·Empty 
00056580:·2050·6173·7377·6f72·6420·2d20·4368·6563···Password·-·Chec 
00056590:·6b20·696e·7465·6772·6974·7920·6f66·2061··k·integrity·of·a 
000565a0:·7574·6873·656c·6563·740a·2020·2020·2020··uthselect.······ 
000565b0:·6375·7272·656e·7420·7072·6f66·696c·650a··current·profile. 
000565c0:·2020·2020·616e·7369·626c·652e·6275·696c······ansible.buil 
000565d0:·7469·6e2e·636f·6d6d·616e·643a·0a20·2020··tin.command:.··· 
000565e0:·2020·2063·6d64·3a20·6175·7468·7365·6c65·····cmd:·authsele 
000565f0:·6374·2063·6865·636b·0a20·2020·2072·6567··ct·check.····reg 
00056600:·6973·7465·723a·2072·6573·756c·745f·6175··ister:·result_au 
00056610:·7468·7365·6c65·6374·5f63·6865·636b·5f63··thselect_check_c 
00056620:·6d64·0a20·2020·2063·6861·6e67·6564·5f77··md.····changed_w 
00056630:·6865·6e3a·2066·616c·7365·0a20·2020·2066··hen:·false.····f 
00056640:·6169·6c65·645f·7768·656e·3a20·6661·6c73··ailed_when:·fals 
Max diff block lines reached; 328912/378068 bytes (87.00%) of diff not shown.
33.8 KB
html2text {}
    
Offset 1466, 14 lines modifiedOffset 1466, 38 lines modified
1466 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"1466 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
1467 fi1467 fi
1468 fi1468 fi
  
1469 else1469 else
1470 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1470 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1471 fi1471 fi
 1472 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1473 ---
 1474 apiVersion:·machineconfiguration.openshift.io/v1
 1475 kind:·MachineConfig
 1476 spec:
 1477 ··config:
 1478 ····ignition:
 1479 ······version:·3.1.0
 1480 ····storage:
 1481 ······files:
 1482 ······-·contents:
 1483 ··········source:
 1484 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1485 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1486 ········mode:·0644
 1487 ········path:·/etc/pam.d/password-auth
 1488 ········overwrite:·true
 1489 ······-·contents:
 1490 ··········source:
 1491 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1492 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1493 ········mode:·0644
 1494 ········path:·/etc/pam.d/system-auth
 1495 ········overwrite:·true
1472 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81496 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1473 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1497 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1474 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1498 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1475 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1499 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1476 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure1500 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
1477 -·name:·Gather·the·package·facts1501 -·name:·Gather·the·package·facts
1478 ··package_facts:1502 ··package_facts:
Offset 1620, 38 lines modifiedOffset 1644, 14 lines modified
1620 ··-·PCI-DSSv4-8.3.11644 ··-·PCI-DSSv4-8.3.1
1621 ··-·configure_strategy1645 ··-·configure_strategy
1622 ··-·high_severity1646 ··-·high_severity
1623 ··-·low_complexity1647 ··-·low_complexity
1624 ··-·medium_disruption1648 ··-·medium_disruption
1625 ··-·no_empty_passwords1649 ··-·no_empty_passwords
1626 ··-·no_reboot_needed1650 ··-·no_reboot_needed
1627 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1628 --- 
1629 apiVersion:·machineconfiguration.openshift.io/v1 
1630 kind:·MachineConfig 
1631 spec: 
1632 ··config: 
1633 ····ignition: 
1634 ······version:·3.1.0 
1635 ····storage: 
1636 ······files: 
1637 ······-·contents: 
1638 ··········source: 
1639 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1640 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1641 ········mode:·0644 
1642 ········path:·/etc/pam.d/password-auth 
1643 ········overwrite:·true 
1644 ······-·contents: 
1645 ··········source: 
1646 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1647 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1648 ········mode:·0644 
1649 ········path:·/etc/pam.d/system-auth 
1650 ········overwrite:·true 
1651 Group  ·Secure·Session·Configuration·Files·for·Login·Accounts·  Group·contains·1·group·and·2·rules1651 Group  ·Secure·Session·Configuration·Files·for·Login·Accounts·  Group·contains·1·group·and·2·rules
1652 _\x8[_\x8r_\x8e_\x8f_\x8]  ·When·a·user·logs·into·a·Unix·account,·the·system·configures·the·user's·session·by·reading·a·number·of·files.·Many·of·these·files·are·located·in·the·user's·home·directory,·and·may·have·weak·permissions·as·a·result·of·user·error·or·misconfiguration.·If·an·attacker·can·modify·or·even·read·certain·types·of·account·configuration·information,·they·can·often·gain·full·access·to·the·affected·user's·account.·Therefore,·it·is·important·to·test·and·correct·configuration·file·permissions·for·interactive·accounts,·particularly·those·of·privileged·users·such·as·root·or·system·administrators.1652 _\x8[_\x8r_\x8e_\x8f_\x8]  ·When·a·user·logs·into·a·Unix·account,·the·system·configures·the·user's·session·by·reading·a·number·of·files.·Many·of·these·files·are·located·in·the·user's·home·directory,·and·may·have·weak·permissions·as·a·result·of·user·error·or·misconfiguration.·If·an·attacker·can·modify·or·even·read·certain·types·of·account·configuration·information,·they·can·often·gain·full·access·to·the·affected·user's·account.·Therefore,·it·is·important·to·test·and·correct·configuration·file·permissions·for·interactive·accounts,·particularly·those·of·privileged·users·such·as·root·or·system·administrators.
1653 Group  ·Ensure·that·No·Dangerous·Directories·Exist·in·Root's·Path·  Group·contains·2·rules1653 Group  ·Ensure·that·No·Dangerous·Directories·Exist·in·Root's·Path·  Group·contains·2·rules
1654 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·active·path·of·the·root·account·can·be·obtained·by·starting·a·new·root·shell·and·running:1654 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·active·path·of·the·root·account·can·be·obtained·by·starting·a·new·root·shell·and·running:
1655 #·echo·$PATH1655 #·echo·$PATH
1656 This·will·produce·a·colon-separated·list·of·directories·in·the·path.1656 This·will·produce·a·colon-separated·list·of·directories·in·the·path.
  
Offset 1748, 19 lines modifiedOffset 1748, 14 lines modified
1748 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91748 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1749 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11749 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1750 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1750 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1751 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11751 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1752 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-002271752 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
1753 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-0306701753 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-030670
1754 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-248812r991589_rule1754 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-248812r991589_rule
1755 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1756 [[packages]] 
1757 name·=·"rsyslog" 
1758 version·=·"*" 
1759 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81755 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1760 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1756 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1761 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1757 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1762 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1758 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1763 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1759 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1764 #·Remediation·is·applicable·only·in·certain·platforms1760 #·Remediation·is·applicable·only·in·certain·platforms
1765 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1761 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1800, 33 lines modifiedOffset 1795, 38 lines modified
1800 ··-·NIST-800-53-CM-6(a)1795 ··-·NIST-800-53-CM-6(a)
1801 ··-·enable_strategy1796 ··-·enable_strategy
1802 ··-·low_complexity1797 ··-·low_complexity
1803 ··-·low_disruption1798 ··-·low_disruption
1804 ··-·medium_severity1799 ··-·medium_severity
1805 ··-·no_reboot_needed1800 ··-·no_reboot_needed
1806 ··-·package_rsyslog_installed1801 ··-·package_rsyslog_installed
 1802 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1803 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1804 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1805 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1806 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1807 package·--add=rsyslog
 1808 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1809 [[packages]]
 1810 name·=·"rsyslog"
 1811 version·=·"*"
1807 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81812 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1808 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1813 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1809 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1814 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1810 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1815 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1811 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1816 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1812 include·install_rsyslog1817 include·install_rsyslog
  
1813 class·install_rsyslog·{1818 class·install_rsyslog·{
1814 ··package·{·'rsyslog':1819 ··package·{·'rsyslog':
1815 ····ensure·=>·'installed',1820 ····ensure·=>·'installed',
Max diff block lines reached; 13615/34618 bytes (39.33%) of diff not shown.
1.37 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-stig.html
    
Offset 15083, 221 lines modifiedOffset 15083, 221 lines modified
0003aea0:·6765·743d·2223·6964·6d35·3639·3622·2074··get="#idm5696"·t0003aea0:·6765·743d·2223·6964·6d35·3639·3622·2074··get="#idm5696"·t
0003aeb0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003aeb0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003aec0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003aec0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003aed0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003aed0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003aee0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003aee0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003aef0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003aef0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003af00:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003af00:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003af10:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
0003af10:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003af20:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003af30:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003af40:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003af50:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003af60:·646d·3536·3936·223e·3c70·7265·3e3c·636f··dm5696"><pre><co 
0003af70:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003af80:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003af90:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003afa0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003afb0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003afc0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003afd0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003afe0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003aff0:·6964·6d35·3639·3722·2074·6162·696e·6465··idm5697"·tabinde 
0003b000:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b010:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b020:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b030:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b040:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b050:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b060:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0003b070:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b080:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b090:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
0003b0a0:·3639·3722·3e3c·7461·626c·6520·636c·6173··697"><table·clas 
0003b0b0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b0c0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b0d0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b0e0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b0f0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b100:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b110:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b120:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b130:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b140:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b150:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b160:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b170:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b180:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b190:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b1a0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b1b0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b1c0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b1d0:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003b1e0:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r 
0003b1f0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003b200:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then.. 
0003b210:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b220:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b230:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal 
0003b240:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b250:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b260:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b270:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b280:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b290:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b2a0:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b2b0:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b2c0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b2d0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b2e0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b2f0:·2369·646d·3536·3938·2220·7461·6269·6e64··#idm5698"·tabind 
0003b300:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b310:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b320:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b330:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b340:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b350:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi 
0003b360:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b370:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003af20:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003b380:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003af30:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003b390:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003af40:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003b3a0:·6964·6d35·3639·3822·3e3c·7461·626c·6520··idm5698"><table·0003af50:·3d22·6964·6d35·3639·3622·3e3c·7461·626c··="idm5696"><tabl
0003b3b0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003af60:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003b3c0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003af70:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003b3d0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003af80:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003b3e0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003af90:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003b3f0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003afa0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0003b400:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003afb0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b410:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003afc0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
0003b420:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003afd0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003b430:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003afe0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b440:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003aff0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
0003b450:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b000:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
0003b460:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003b010:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
0003b470:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003b020:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0003b480:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003b030:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
0003b490:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b040:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003b4a0:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather· 
0003b4b0:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact 
0003b4c0:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact 
0003b4d0:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:· 
0003b4e0:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··- 
0003b4f0:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003b500:·202d·2044·4953·412d·5354·4947·2d4f·4c30···-·DISA-STIG-OL0 
0003b510:·382d·3030·2d30·3130·3335·390a·2020·2d20··8-00-010359.··-· 
0003b520:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003b530:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003b540:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003b550:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003b560:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003b570:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003b580:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003b590:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003b5a0:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003b5b0:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003b5c0:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003b5d0:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
0003b5e0:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
0003b5f0:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
0003b600:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
0003b610:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
0003b620:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe0003b050:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003b060:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003b070:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003b080:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm·
 0003b090:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 0003b0a0:·6c20·7c7c·2072·706d·202d·2d71·7569·6574··l·||·rpm·--quiet
Max diff block lines reached; 1255470/1284616 bytes (97.73%) of diff not shown.
150 KB
html2text {}
    
Offset 101, 19 lines modifiedOffset 101, 14 lines modified
101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
104 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359104 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
105 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79105 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
107 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule107 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
109 [[packages]] 
110 name·=·"aide" 
111 version·=·"*" 
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
117 #·Remediation·is·applicable·only·in·certain·platforms113 #·Remediation·is·applicable·only·in·certain·platforms
118 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then114 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 159, 33 lines modifiedOffset 154, 38 lines modified
159 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy155 ··-·enable_strategy
161 ··-·low_complexity156 ··-·low_complexity
162 ··-·low_disruption157 ··-·low_disruption
163 ··-·medium_severity158 ··-·medium_severity
164 ··-·no_reboot_needed159 ··-·no_reboot_needed
165 ··-·package_aide_installed160 ··-·package_aide_installed
 161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 166 package·--add=aide
 167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 168 [[packages]]
 169 name·=·"aide"
 170 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
171 include·install_aide176 include·install_aide
  
172 class·install_aide·{177 class·install_aide·{
173 ··package·{·'aide':178 ··package·{·'aide':
174 ····ensure·=>·'installed',179 ····ensure·=>·'installed',
175 ··}180 ··}
176 }181 }
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
182 package·--add=aide 
183 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*182 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
184 Run·the·following·command·to·generate·a·new·database:183 Run·the·following·command·to·generate·a·new·database:
185 $·sudo·/usr/sbin/aide·--init184 $·sudo·/usr/sbin/aide·--init
186 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:185 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
187 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz186 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
188 To·initiate·a·manual·check,·run·the·following·command:187 To·initiate·a·manual·check,·run·the·following·command:
189 $·sudo·/usr/sbin/aide·--check188 $·sudo·/usr/sbin/aide·--check
Offset 1810, 31 lines modifiedOffset 1810, 31 lines modified
1810 ············_\x8i_\x8s_\x8m······14461810 ············_\x8i_\x8s_\x8m······1446
1811 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11811 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1812 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121812 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1813 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11813 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1814 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761814 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1815 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-0100201815 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020
1816 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule1816 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule
1817 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1818 [customizations] 
1819 fips·=·true 
1820 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81817 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1821 #·Remediation·is·applicable·only·in·certain·platforms1818 #·Remediation·is·applicable·only·in·certain·platforms
1822 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then1819 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
1823 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1820 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1824 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1821 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1825 kargs·=·["fips=1"]1822 kargs·=·["fips=1"]
1826 EOF1823 EOF
1827 fi1824 fi
  
1828 else1825 else
1829 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1826 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1830 fi1827 fi
 1828 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1829 [customizations]
 1830 fips·=·true
1831 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1831 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1832 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:1832 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:
1833 fips-mode-setup·--enable1833 fips-mode-setup·--enable
1834 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1834 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1835 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1835 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1836 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1836 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1837 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1837 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 5501, 19 lines modifiedOffset 5501, 14 lines modified
5501 Rationale:··rng-tools·provides·hardware·random·number·generator·tools,·such·as·those·used·in·the·formation·of·x509/PKI·certificates.5501 Rationale:··rng-tools·provides·hardware·random·number·generator·tools,·such·as·those·used·in·the·formation·of·x509/PKI·certificates.
5502 Severity: ··low5502 Severity: ··low
5503 Rule·ID:····xccdf_org.ssgproject.content_rule_package_rng-tools_installed5503 Rule·ID:····xccdf_org.ssgproject.content_rule_package_rng-tools_installed
5504 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003665504 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
5505 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002275505 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00227
5506 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··OL08-00-0104725506 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··OL08-00-010472
5507 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-248600r991589_rule5507 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-248600r991589_rule
5508 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5509 [[packages]] 
5510 name·=·"rng-tools" 
5511 version·=·"*" 
5512 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85508 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5513 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5509 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5514 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5510 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5515 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5511 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5516 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5512 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5517 #·Remediation·is·applicable·only·in·certain·platforms5513 #·Remediation·is·applicable·only·in·certain·platforms
5518 if·(·!·(·[·"$(sysctl·-a·|·grep·-c·'fips_enabled.*1')"·-eq·1·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then5514 if·(·!·(·[·"$(sysctl·-a·|·grep·-c·'fips_enabled.*1')"·-eq·1·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
Offset 5552, 33 lines modifiedOffset 5547, 38 lines modified
5552 ··-·DISA-STIG-OL08-00-0104725547 ··-·DISA-STIG-OL08-00-010472
5553 ··-·enable_strategy5548 ··-·enable_strategy
5554 ··-·low_complexity5549 ··-·low_complexity
5555 ··-·low_disruption5550 ··-·low_disruption
5556 ··-·low_severity5551 ··-·low_severity
Max diff block lines reached; 146323/154009 bytes (95.01%) of diff not shown.
1.37 MB
./usr/share/doc/ssg-nondebian/ssg-ol8-guide-stig_gui.html
    
Offset 15101, 221 lines modifiedOffset 15101, 221 lines modified
0003afc0:·7461·7267·6574·3d22·2369·646d·3536·3936··target="#idm56960003afc0:·7461·7267·6574·3d22·2369·646d·3536·3936··target="#idm5696
0003afd0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003afd0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003afe0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003afe0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003aff0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003aff0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b000:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b000:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b010:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b010:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b020:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b020:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b030:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
0003b030:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003b040:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003b050:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b060:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b070:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b080:·3d22·6964·6d35·3639·3622·3e3c·7072·653e··="idm5696"><pre> 
0003b090:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003b0a0:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003b0b0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003b0c0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b0d0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b0e0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b0f0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b100:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b110:·3d22·2369·646d·3536·3937·2220·7461·6269··="#idm5697"·tabi 
0003b120:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b130:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b140:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b150:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b160:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b170:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003b180:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003b190:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b1a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b1b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b1c0:·646d·3536·3937·223e·3c74·6162·6c65·2063··dm5697"><table·c 
0003b1d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b1e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b1f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b200:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b210:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b220:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b230:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b240:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b250:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b260:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b270:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b280:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b290:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b2a0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b2b0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b2c0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003b2d0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003b2e0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003b2f0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q 
0003b300:·7569·6574·202d·7120·6b65·726e·656c·207c··uiet·-q·kernel·| 
0003b310:·7c20·7270·6d20·2d2d·7175·6965·7420·2d71··|·rpm·--quiet·-q 
0003b320:·206b·6572·6e65·6c2d·7565·6b3b·2074·6865···kernel-uek;·the 
0003b330:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003b340:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003b350:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins 
0003b360:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003b370:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003b380:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b390:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b3a0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b3b0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b3c0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b3d0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b3e0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b3f0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b400:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b410:·743d·2223·6964·6d35·3639·3822·2074·6162··t="#idm5698"·tab 
0003b420:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b430:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b440:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b450:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b460:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b470:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b480:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b490:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003b040:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b4a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003b050:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b4b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b060:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b4c0:·643d·2269·646d·3536·3938·223e·3c74·6162··d="idm5698"><tab0003b070:·2069·643d·2269·646d·3536·3936·223e·3c74···id="idm5696"><t
0003b4d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b080:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b4e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b090:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b4f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b0a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b500:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b0b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b510:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b0c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b520:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b0d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b0e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b0f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003b100:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b110:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b120:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b530:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003b130:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b540:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b550:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b560:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b570:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b580:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b590:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b140:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b5a0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003b150:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003b5b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b160:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003b5c0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003b5d0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f0003b170:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 0003b180:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 0003b190:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 0003b1a0:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 0003b1b0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 0003b1c0:·726e·656c·207c·7c20·7270·6d20·2d2d·7175··rnel·||·rpm·--qu
 0003b1d0:·6965·7420·2d71·206b·6572·6e65·6c2d·7565··iet·-q·kernel-ue
 0003b1e0:·6b3b·2074·6865·6e0a·0a69·6620·2120·7270··k;·then..if·!·rp
 0003b1f0:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 0003b200:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y
 0003b210:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a
 0003b220:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 0003b230:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003b240:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003b250:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003b260:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 0003b270:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 0003b280:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 0003b290:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 0003b2a0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
 0003b2b0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
 0003b2c0:·2d74·6172·6765·743d·2223·6964·6d35·3639··-target="#idm569
 0003b2d0:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·
 0003b2e0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
Max diff block lines reached; 1254571/1283717 bytes (97.73%) of diff not shown.
150 KB
html2text {}
    
Offset 105, 19 lines modifiedOffset 105, 14 lines modified
105 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3105 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
107 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199107 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
108 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359108 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········OL08-00-010359
109 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79109 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
110 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2110 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
111 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule111 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-252654r958944_rule
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
113 [[packages]] 
114 name·=·"aide" 
115 version·=·"*" 
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
121 #·Remediation·is·applicable·only·in·certain·platforms117 #·Remediation·is·applicable·only·in·certain·platforms
122 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then118 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 163, 33 lines modifiedOffset 158, 38 lines modified
163 ··-·PCI-DSSv4-11.5.2158 ··-·PCI-DSSv4-11.5.2
164 ··-·enable_strategy159 ··-·enable_strategy
165 ··-·low_complexity160 ··-·low_complexity
166 ··-·low_disruption161 ··-·low_disruption
167 ··-·medium_severity162 ··-·medium_severity
168 ··-·no_reboot_needed163 ··-·no_reboot_needed
169 ··-·package_aide_installed164 ··-·package_aide_installed
 165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 170 package·--add=aide
 171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 172 [[packages]]
 173 name·=·"aide"
 174 version·=·"*"
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
175 include·install_aide180 include·install_aide
  
176 class·install_aide·{181 class·install_aide·{
177 ··package·{·'aide':182 ··package·{·'aide':
178 ····ensure·=>·'installed',183 ····ensure·=>·'installed',
179 ··}184 ··}
180 }185 }
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
186 package·--add=aide 
187 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*186 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
188 Run·the·following·command·to·generate·a·new·database:187 Run·the·following·command·to·generate·a·new·database:
189 $·sudo·/usr/sbin/aide·--init188 $·sudo·/usr/sbin/aide·--init
190 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:189 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
191 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz190 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
192 To·initiate·a·manual·check,·run·the·following·command:191 To·initiate·a·manual·check,·run·the·following·command:
193 $·sudo·/usr/sbin/aide·--check192 $·sudo·/usr/sbin/aide·--check
Offset 1814, 31 lines modifiedOffset 1814, 31 lines modified
1814 ············_\x8i_\x8s_\x8m······14461814 ············_\x8i_\x8s_\x8m······1446
1815 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11815 ············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1816 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121816 References:·_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1817 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11817 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1818 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761818 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1819 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-0100201819 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···OL08-00-010020
1820 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule1820 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-248524r958408_rule
1821 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1822 [customizations] 
1823 fips·=·true 
1824 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81821 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1825 #·Remediation·is·applicable·only·in·certain·platforms1822 #·Remediation·is·applicable·only·in·certain·platforms
1826 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then1823 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
1827 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1824 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1828 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1825 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1829 kargs·=·["fips=1"]1826 kargs·=·["fips=1"]
1830 EOF1827 EOF
1831 fi1828 fi
  
1832 else1829 else
1833 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1830 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1834 fi1831 fi
 1832 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1833 [customizations]
 1834 fips·=·true
1835 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1835 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1836 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:1836 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:
1837 fips-mode-setup·--enable1837 fips-mode-setup·--enable
1838 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1838 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1839 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1839 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1840 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1840 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1841 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1841 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 5505, 19 lines modifiedOffset 5505, 14 lines modified
5505 Rationale:··rng-tools·provides·hardware·random·number·generator·tools,·such·as·those·used·in·the·formation·of·x509/PKI·certificates.5505 Rationale:··rng-tools·provides·hardware·random·number·generator·tools,·such·as·those·used·in·the·formation·of·x509/PKI·certificates.
5506 Severity: ··low5506 Severity: ··low
5507 Rule·ID:····xccdf_org.ssgproject.content_rule_package_rng-tools_installed5507 Rule·ID:····xccdf_org.ssgproject.content_rule_package_rng-tools_installed
5508 ············_\x8d_\x8i_\x8s_\x8a····CCI-0003665508 ············_\x8d_\x8i_\x8s_\x8a····CCI-000366
5509 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-002275509 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00227
5510 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··OL08-00-0104725510 ············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··OL08-00-010472
5511 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-248600r991589_rule5511 ············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-248600r991589_rule
5512 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5513 [[packages]] 
5514 name·=·"rng-tools" 
5515 version·=·"*" 
5516 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85512 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5517 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5513 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5518 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5514 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5519 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5515 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5520 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5516 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5521 #·Remediation·is·applicable·only·in·certain·platforms5517 #·Remediation·is·applicable·only·in·certain·platforms
5522 if·(·!·(·[·"$(sysctl·-a·|·grep·-c·'fips_enabled.*1')"·-eq·1·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then5518 if·(·!·(·[·"$(sysctl·-a·|·grep·-c·'fips_enabled.*1')"·-eq·1·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
Offset 5556, 33 lines modifiedOffset 5551, 38 lines modified
5556 ··-·DISA-STIG-OL08-00-0104725551 ··-·DISA-STIG-OL08-00-010472
5557 ··-·enable_strategy5552 ··-·enable_strategy
5558 ··-·low_complexity5553 ··-·low_complexity
5559 ··-·low_disruption5554 ··-·low_disruption
5560 ··-·low_severity5555 ··-·low_severity
Max diff block lines reached; 146323/154009 bytes (95.01%) of diff not shown.
717 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_enhanced.html
    
Offset 15037, 218 lines modifiedOffset 15037, 218 lines modified
0003abc0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003abc0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003abd0:·646d·3632·3739·2220·7461·6269·6e64·6578··dm6279"·tabindex0003abd0:·646d·3632·3739·2220·7461·6269·6e64·6578··dm6279"·tabindex
0003abe0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003abe0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003abf0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003abf0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003ac00:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003ac00:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003ac10:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003ac10:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003ac20:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003ac20:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003ac30:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003ac30:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003ac40:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003ac50:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003ac60:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003ac70:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003ac80:·7365·2220·6964·3d22·6964·6d36·3237·3922··se"·id="idm6279" 
0003ac90:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
0003aca0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003acb0:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003acc0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003acd0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003ace0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003acf0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003ad00:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003ad10:·7461·7267·6574·3d22·2369·646d·3632·3830··target="#idm6280 
0003ad20:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003ad30:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003ad40:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003ad50:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003ad60:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003ad70:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003ad80:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003ad90:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003ada0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003adb0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003adc0:·2069·643d·2269·646d·3632·3830·223e·3c74···id="idm6280"><t 
0003add0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003ade0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003adf0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003ae00:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003ae10:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003ae20:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003ae30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003ae40:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003ae50:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003ae60:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003ae70:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003ae80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003ae90:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003aea0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003aeb0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003aec0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003aed0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003aee0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003aef0:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r 
0003af00:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003af10:·726e·656c·207c·7c20·7270·6d20·2d2d·7175··rnel·||·rpm·--qu 
0003af20:·6965·7420·2d71·206b·6572·6e65·6c2d·7565··iet·-q·kernel-ue 
0003af30:·6b3b·2074·6865·6e0a·0a69·6620·2120·7270··k;·then..if·!·rp 
0003af40:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003af50:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y 
0003af60:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a 
0003af70:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003af80:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003af90:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003afa0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003afb0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003afc0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003afd0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003afe0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003aff0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b000:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b010:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm628 
0003b020:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"· 
0003b030:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b040:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b050:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b060:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b070:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b080:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003b090:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>0003ac40:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
0003b0a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003ac50:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b0b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003ac60:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b0c0:·7073·6522·2069·643d·2269·646d·3632·3831··pse"·id="idm62810003ac70:·6c61·7073·6522·2069·643d·2269·646d·3632··lapse"·id="idm62
0003b0d0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003ac80:·3739·223e·3c74·6162·6c65·2063·6c61·7373··79"><table·class
0003b0e0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003ac90:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b0f0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003aca0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b100:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003acb0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b110:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003acc0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b120:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003acd0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b130:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003ace0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b140:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003acf0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b150:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003ad00:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b160:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003ad10:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b170:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003ad20:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003ad30:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003ad40:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003ad50:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003ad60:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003ad70:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
 0003ad80:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003ad90:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003ada0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003adb0:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet
 0003adc0:·202d·7120·6b65·726e·656c·207c·7c20·7270···-q·kernel·||·rp
 0003add0:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
 0003ade0:·6e65·6c2d·7565·6b3b·2074·6865·6e0a·0a69··nel-uek;·then..i
 0003adf0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
 0003ae00:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then
 0003ae10:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install
 0003ae20:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e
 0003ae30:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp
 0003ae40:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia
 0003ae50:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl
 0003ae60:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·
 0003ae70:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c
 0003ae80:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003ae90:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003aea0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 0003aeb0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 0003aec0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
 0003aed0:·6964·6d36·3238·3022·2074·6162·696e·6465··idm6280"·tabinde
 0003aee0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
 0003aef0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
 0003af00:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
 0003af10:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
 0003af20:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003af30:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib
 0003af40:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</
 0003af50:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
Max diff block lines reached; 637200/665932 bytes (95.69%) of diff not shown.
66.1 KB
html2text {}
    
Offset 113, 19 lines modifiedOffset 113, 14 lines modified
113 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3113 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
114 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)114 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3115 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5116 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199117 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79118 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
121 [[packages]] 
122 name·=·"aide" 
123 version·=·"*" 
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
129 #·Remediation·is·applicable·only·in·certain·platforms125 #·Remediation·is·applicable·only·in·certain·platforms
130 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then126 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 169, 33 lines modifiedOffset 164, 38 lines modified
169 ··-·PCI-DSSv4-11.5.2164 ··-·PCI-DSSv4-11.5.2
170 ··-·enable_strategy165 ··-·enable_strategy
171 ··-·low_complexity166 ··-·low_complexity
172 ··-·low_disruption167 ··-·low_disruption
173 ··-·medium_severity168 ··-·medium_severity
174 ··-·no_reboot_needed169 ··-·no_reboot_needed
175 ··-·package_aide_installed170 ··-·package_aide_installed
 171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 176 package·--add=aide
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 178 [[packages]]
 179 name·=·"aide"
 180 version·=·"*"
176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
181 include·install_aide186 include·install_aide
  
182 class·install_aide·{187 class·install_aide·{
183 ··package·{·'aide':188 ··package·{·'aide':
184 ····ensure·=>·'installed',189 ····ensure·=>·'installed',
185 ··}190 ··}
186 }191 }
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
192 package·--add=aide 
193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
194 Run·the·following·command·to·generate·a·new·database:193 Run·the·following·command·to·generate·a·new·database:
195 $·sudo·/usr/sbin/aide·--init194 $·sudo·/usr/sbin/aide·--init
196 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the195 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
197 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these196 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
198 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their197 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
199 integrity.·The·newly-generated·database·can·be·installed·as·follows:198 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 583, 19 lines modifiedOffset 583, 14 lines modified
583 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235583 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
584 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386584 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
585 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)585 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
586 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1586 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
587 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125587 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
588 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33588 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
589 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2589 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
591 [[packages]] 
592 name·=·"sudo" 
593 version·=·"*" 
594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low591 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low592 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false593 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable594 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
599 #·Remediation·is·applicable·only·in·certain·platforms595 #·Remediation·is·applicable·only·in·certain·platforms
600 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then596 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 637, 33 lines modifiedOffset 632, 38 lines modified
637 ··-·PCI-DSSv4-2.2.6632 ··-·PCI-DSSv4-2.2.6
638 ··-·enable_strategy633 ··-·enable_strategy
639 ··-·low_complexity634 ··-·low_complexity
640 ··-·low_disruption635 ··-·low_disruption
641 ··-·medium_severity636 ··-·medium_severity
642 ··-·no_reboot_needed637 ··-·no_reboot_needed
643 ··-·package_sudo_installed638 ··-·package_sudo_installed
 639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 640 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 641 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 642 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 643 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 644 package·--add=sudo
 645 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 646 [[packages]]
 647 name·=·"sudo"
 648 version·=·"*"
644 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8649 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
645 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low650 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
646 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low651 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
647 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false652 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
648 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable653 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
649 include·install_sudo654 include·install_sudo
  
650 class·install_sudo·{655 class·install_sudo·{
651 ··package·{·'sudo':656 ··package·{·'sudo':
652 ····ensure·=>·'installed',657 ····ensure·=>·'installed',
653 ··}658 ··}
654 }659 }
655 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
656 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
657 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
658 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
659 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
660 package·--add=sudo 
661 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*660 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
662 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:661 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
663 $·sudo·chgrp·root·/etc/sudoers.d662 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 62430/67670 bytes (92.26%) of diff not shown.
751 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_high.html
    
Offset 15042, 218 lines modifiedOffset 15042, 218 lines modified
0003ac10:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003ac10:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003ac20:·2223·6964·6d36·3237·3922·2074·6162·696e··"#idm6279"·tabin0003ac20:·2223·6964·6d36·3237·3922·2074·6162·696e··"#idm6279"·tabin
0003ac30:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003ac30:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003ac40:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003ac40:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003ac50:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003ac50:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003ac60:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003ac60:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003ac70:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003ac70:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003ac80:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003ac80:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003ac90:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
0003ac90:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003aca0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003acb0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003acc0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003acd0:·6c61·7073·6522·2069·643d·2269·646d·3632··lapse"·id="idm62 
0003ace0:·3739·223e·3c70·7265·3e3c·636f·6465·3e0a··79"><pre><code>. 
0003acf0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003ad00:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003ad10:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003ad20:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003ad30:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003ad40:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003ad50:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003ad60:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6 
0003ad70:·3238·3022·2074·6162·696e·6465·783d·2230··280"·tabindex="0 
0003ad80:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003ad90:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003ada0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003adb0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003adc0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003add0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003ade0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003adf0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003ae00:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003ae10:·7365·2220·6964·3d22·6964·6d36·3238·3022··se"·id="idm6280" 
0003ae20:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003ae30:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003ae40:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003ae50:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003ae60:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003ae70:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003ae80:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003ae90:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003aea0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003aeb0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003aec0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003aed0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003aee0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003aef0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003af00:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003af10:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003af20:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003af30:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003af40:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003af50:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
0003af60:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·- 
0003af70:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel 
0003af80:·2d75·656b·3b20·7468·656e·0a0a·6966·2021··-uek;·then..if·! 
0003af90:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003afa0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003afb0:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y 
0003afc0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003afd0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003afe0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003aff0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b000:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b010:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b020:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b030:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b040:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b050:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b060:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b070:·3632·3831·2220·7461·6269·6e64·6578·3d22··6281"·tabindex=" 
0003b080:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b090:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b0a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b0b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b0c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b0d0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003b0e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b0f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003aca0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b100:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003acb0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b110:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm60003acc0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b120:·3238·3122·3e3c·7461·626c·6520·636c·6173··281"><table·clas0003acd0:·6d36·3237·3922·3e3c·7461·626c·6520·636c··m6279"><table·cl
0003b130:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003ace0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b140:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003acf0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b150:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003ad00:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b160:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003ad10:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b170:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003ad20:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b180:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003ad30:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b190:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003ad40:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b1a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003ad50:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003b1b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b1c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b1d0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b1e0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b1f0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b200:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b210:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n 
0003b220:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
0003b230:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
0003b240:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
0003b250:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto 
0003b260:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI 
0003b270:·532d·352e·3130·2e31·2e33·0a20·202d·204e··S-5.10.1.3.··-·N 
0003b280:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003b290:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003b2a0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003b2b0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003b2c0:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003b2d0:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003b2e0:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003b2f0:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
0003b300:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n 
0003b310:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed. 
0003b320:·2020·2d20·7061·636b·6167·655f·6169·6465····-·package_aide 
0003b330:·5f69·6e73·7461·6c6c·6564·0a0a·2d20·6e61··_installed..-·na 
0003b340:·6d65·3a20·456e·7375·7265·2061·6964·6520··me:·Ensure·aide· 
0003b350:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p 
0003b360:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name 
0003b370:·3a20·6169·6465·0a20·2020·2073·7461·7465··:·aide.····state 
0003b380:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when 
0003b390:·3a20·2822·6b65·726e·656c·2220·696e·2061··:·("kernel"·in·a 
0003b3a0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
0003b3b0:·6b61·6765·7320·6f72·2022·6b65·726e·656c··kages·or·"kernel 
0003b3c0:·2d75·656b·2220·696e·2061·6e73·6962·6c65··-uek"·in·ansible 
0003b3d0:·5f66·6163·7473·2e70·6163·6b61·6765·7329··_facts.packages) 
0003b3e0:·0a20·2074·6167·733a·0a20·202d·2043·4a49··.··tags:.··-·CJI 
Max diff block lines reached; 667368/696100 bytes (95.87%) of diff not shown.
71.4 KB
html2text {}
    
Offset 114, 19 lines modifiedOffset 114, 14 lines modified
114 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3114 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)115 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3116 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2120 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
122 [[packages]] 
123 name·=·"aide" 
124 version·=·"*" 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
130 #·Remediation·is·applicable·only·in·certain·platforms126 #·Remediation·is·applicable·only·in·certain·platforms
131 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then127 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 170, 33 lines modifiedOffset 165, 38 lines modified
170 ··-·PCI-DSSv4-11.5.2165 ··-·PCI-DSSv4-11.5.2
171 ··-·enable_strategy166 ··-·enable_strategy
172 ··-·low_complexity167 ··-·low_complexity
173 ··-·low_disruption168 ··-·low_disruption
174 ··-·medium_severity169 ··-·medium_severity
175 ··-·no_reboot_needed170 ··-·no_reboot_needed
176 ··-·package_aide_installed171 ··-·package_aide_installed
 172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 177 package·--add=aide
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 179 [[packages]]
 180 name·=·"aide"
 181 version·=·"*"
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
182 include·install_aide187 include·install_aide
  
183 class·install_aide·{188 class·install_aide·{
184 ··package·{·'aide':189 ··package·{·'aide':
185 ····ensure·=>·'installed',190 ····ensure·=>·'installed',
186 ··}191 ··}
187 }192 }
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
193 package·--add=aide 
194 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*193 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
195 Run·the·following·command·to·generate·a·new·database:194 Run·the·following·command·to·generate·a·new·database:
196 $·sudo·/usr/sbin/aide·--init195 $·sudo·/usr/sbin/aide·--init
197 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the196 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
198 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these197 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
199 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their198 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
200 integrity.·The·newly-generated·database·can·be·installed·as·follows:199 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 1121, 19 lines modifiedOffset 1121, 14 lines modified
1121 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351121 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1122 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861122 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1123 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1123 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1124 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11124 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251125 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1126 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331126 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21127 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1129 [[packages]] 
1130 name·=·"sudo" 
1131 version·=·"*" 
1132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1137 #·Remediation·is·applicable·only·in·certain·platforms1133 #·Remediation·is·applicable·only·in·certain·platforms
1138 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1134 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1175, 33 lines modifiedOffset 1170, 38 lines modified
1175 ··-·PCI-DSSv4-2.2.61170 ··-·PCI-DSSv4-2.2.6
1176 ··-·enable_strategy1171 ··-·enable_strategy
1177 ··-·low_complexity1172 ··-·low_complexity
1178 ··-·low_disruption1173 ··-·low_disruption
1179 ··-·medium_severity1174 ··-·medium_severity
1180 ··-·no_reboot_needed1175 ··-·no_reboot_needed
1181 ··-·package_sudo_installed1176 ··-·package_sudo_installed
 1177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1182 package·--add=sudo
 1183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1184 [[packages]]
 1185 name·=·"sudo"
 1186 version·=·"*"
1182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1187 include·install_sudo1192 include·install_sudo
  
1188 class·install_sudo·{1193 class·install_sudo·{
1189 ··package·{·'sudo':1194 ··package·{·'sudo':
1190 ····ensure·=>·'installed',1195 ····ensure·=>·'installed',
1191 ··}1196 ··}
1192 }1197 }
1193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1198 package·--add=sudo 
1199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1200 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:1199 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
1201 $·sudo·chgrp·root·/etc/sudoers.d1200 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 67861/73105 bytes (92.83%) of diff not shown.
602 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_intermediary.html
    
Offset 15033, 218 lines modifiedOffset 15033, 218 lines modified
0003ab80:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm60003ab80:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6
0003ab90:·3237·3922·2074·6162·696e·6465·783d·2230··279"·tabindex="00003ab90:·3237·3922·2074·6162·696e·6465·783d·2230··279"·tabindex="0
0003aba0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003aba0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003abb0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003abb0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003abc0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003abc0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003abd0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003abd0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003abe0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003abe0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003abf0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B0003abf0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
0003ac00:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
0003ac10:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003ac20:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003ac30:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003ac40:·2069·643d·2269·646d·3632·3739·223e·3c70···id="idm6279"><p 
0003ac50:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
0003ac60:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a 
0003ac70:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·" 
0003ac80:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
0003ac90:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003aca0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003acb0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003acc0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003acd0:·6765·743d·2223·6964·6d36·3238·3022·2074··get="#idm6280"·t 
0003ace0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003acf0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003ad00:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003ad10:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003ad20:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003ad30:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003ad40:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003ad50:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003ad60:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003ad70:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003ad80:·3d22·6964·6d36·3238·3022·3e3c·7461·626c··="idm6280"><tabl 
0003ad90:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003ada0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003adb0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003adc0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003add0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003ade0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003adf0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003ae00:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003ae10:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003ae20:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003ae30:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003ae40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003ae50:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003ae60:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003ae70:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003ae80:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003ae90:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003aea0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003aeb0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm· 
0003aec0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003aed0:·6c20·7c7c·2072·706d·202d·2d71·7569·6574··l·||·rpm·--quiet 
0003aee0:·202d·7120·6b65·726e·656c·2d75·656b·3b20···-q·kernel-uek;· 
0003aef0:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003af00:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003af10:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum· 
0003af20:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003af30:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003af40:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003af50:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003af60:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003af70:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003af80:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003af90:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003afa0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003afb0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003afc0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003afd0:·7267·6574·3d22·2369·646d·3632·3831·2220··rget="#idm6281"· 
0003afe0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003aff0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b000:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b010:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b020:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b030:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b040:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003b050:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003ac00:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
0003b060:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003ac10:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003b070:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003ac20:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003b080:·2220·6964·3d22·6964·6d36·3238·3122·3e3c··"·id="idm6281"><0003ac30:·7365·2220·6964·3d22·6964·6d36·3237·3922··se"·id="idm6279"
0003b090:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003ac40:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003b0a0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003ac50:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003b0b0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003ac60:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003b0c0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003ac70:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003b0d0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003ac80:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003b0e0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003ac90:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003b0f0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003aca0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003b100:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003acb0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003b110:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003acc0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003b120:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b130:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b140:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b150:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b160:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b170:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b180:·3e3c·636f·6465·3e2d·206e·616d·653a·2047··><code>-·name:·G 
0003b190:·6174·6865·7220·7468·6520·7061·636b·6167··ather·the·packag 
0003b1a0:·6520·6661·6374·730a·2020·7061·636b·6167··e·facts.··packag 
0003b1b0:·655f·6661·6374·733a·0a20·2020·206d·616e··e_facts:.····man 
0003b1c0:·6167·6572·3a20·6175·746f·0a20·2074·6167··ager:·auto.··tag 
0003b1d0:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10 
0003b1e0:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80 
0003b1f0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
0003b200:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11. 
0003b210:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4- 
0003b220:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl 
0003b230:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l 
0003b240:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.·· 
0003b250:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption 
0003b260:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve 
0003b270:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo 
0003b280:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa 
0003b290:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta 
0003b2a0:·6c6c·6564·0a0a·2d20·6e61·6d65·3a20·456e··lled..-·name:·En 
0003b2b0:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins 
0003b2c0:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package 
0003b2d0:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide 
0003b2e0:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres 
0003b2f0:·656e·740a·2020·7768·656e·3a20·2822·6b65··ent.··when:·("ke 
0003b300:·726e·656c·2220·696e·2061·6e73·6962·6c65··rnel"·in·ansible 
0003b310:·5f66·6163·7473·2e70·6163·6b61·6765·7320··_facts.packages· 
0003b320:·6f72·2022·6b65·726e·656c·2d75·656b·2220··or·"kernel-uek"· 
0003b330:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
0003b340:·2e70·6163·6b61·6765·7329·0a20·2074·6167··.packages).··tag 
0003b350:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10 
0003b360:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80 
Max diff block lines reached; 530136/558868 bytes (94.86%) of diff not shown.
56.1 KB
html2text {}
    
Offset 112, 19 lines modifiedOffset 112, 14 lines modified
112 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3112 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
113 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)113 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
114 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3114 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5115 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199116 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79117 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2118 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
120 [[packages]] 
121 name·=·"aide" 
122 version·=·"*" 
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
128 #·Remediation·is·applicable·only·in·certain·platforms124 #·Remediation·is·applicable·only·in·certain·platforms
129 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then125 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 168, 33 lines modifiedOffset 163, 38 lines modified
168 ··-·PCI-DSSv4-11.5.2163 ··-·PCI-DSSv4-11.5.2
169 ··-·enable_strategy164 ··-·enable_strategy
170 ··-·low_complexity165 ··-·low_complexity
171 ··-·low_disruption166 ··-·low_disruption
172 ··-·medium_severity167 ··-·medium_severity
173 ··-·no_reboot_needed168 ··-·no_reboot_needed
174 ··-·package_aide_installed169 ··-·package_aide_installed
 170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 175 package·--add=aide
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 177 [[packages]]
 178 name·=·"aide"
 179 version·=·"*"
175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
180 include·install_aide185 include·install_aide
  
181 class·install_aide·{186 class·install_aide·{
182 ··package·{·'aide':187 ··package·{·'aide':
183 ····ensure·=>·'installed',188 ····ensure·=>·'installed',
184 ··}189 ··}
185 }190 }
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
191 package·--add=aide 
192 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*191 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
193 Run·the·following·command·to·generate·a·new·database:192 Run·the·following·command·to·generate·a·new·database:
194 $·sudo·/usr/sbin/aide·--init193 $·sudo·/usr/sbin/aide·--init
195 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the194 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
196 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these195 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
197 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their196 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
198 integrity.·The·newly-generated·database·can·be·installed·as·follows:197 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 549, 19 lines modifiedOffset 549, 14 lines modified
549 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235549 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
550 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386550 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
551 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)551 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
552 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1552 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
553 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125553 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
554 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33554 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
555 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2555 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
557 [[packages]] 
558 name·=·"sudo" 
559 version·=·"*" 
560 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8556 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
561 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low557 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
562 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low558 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
563 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false559 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
564 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable560 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
565 #·Remediation·is·applicable·only·in·certain·platforms561 #·Remediation·is·applicable·only·in·certain·platforms
566 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then562 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 603, 33 lines modifiedOffset 598, 38 lines modified
603 ··-·PCI-DSSv4-2.2.6598 ··-·PCI-DSSv4-2.2.6
604 ··-·enable_strategy599 ··-·enable_strategy
605 ··-·low_complexity600 ··-·low_complexity
606 ··-·low_disruption601 ··-·low_disruption
607 ··-·medium_severity602 ··-·medium_severity
608 ··-·no_reboot_needed603 ··-·no_reboot_needed
609 ··-·package_sudo_installed604 ··-·package_sudo_installed
 605 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 606 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 607 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 608 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 609 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 610 package·--add=sudo
 611 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 612 [[packages]]
 613 name·=·"sudo"
 614 version·=·"*"
610 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8615 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
611 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low616 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
612 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low617 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
613 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false618 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
614 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable619 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
615 include·install_sudo620 include·install_sudo
  
616 class·install_sudo·{621 class·install_sudo·{
617 ··package·{·'sudo':622 ··package·{·'sudo':
618 ····ensure·=>·'installed',623 ····ensure·=>·'installed',
619 ··}624 ··}
620 }625 }
621 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
622 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
623 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
624 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
625 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
626 package·--add=sudo 
627 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*626 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·G\x8Gr\x8ro\x8ou\x8up\x8p·W\x8Wh\x8ho\x8o·O\x8Ow\x8wn\x8ns\x8s·/\x8/e\x8et\x8tc\x8c/\x8/s\x8su\x8ud\x8do\x8oe\x8er\x8rs\x8s.\x8.d\x8d·D\x8Di\x8ir\x8re\x8ec\x8ct\x8to\x8or\x8ry\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
628 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:627 To·properly·set·the·group·owner·of·/etc/sudoers.d,·run·the·command:
629 $·sudo·chgrp·root·/etc/sudoers.d628 $·sudo·chgrp·root·/etc/sudoers.d
Max diff block lines reached; 52220/57460 bytes (90.88%) of diff not shown.
141 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-anssi_bp28_minimal.html
    
Offset 14725, 227 lines modifiedOffset 14725, 227 lines modified
00039840:·6172·6765·743d·2223·6964·6d39·3536·3922··arget="#idm9569"00039840:·6172·6765·743d·2223·6964·6d39·3536·3922··arget="#idm9569"
00039850:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro00039850:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
00039860:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria00039860:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
00039870:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false00039870:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
00039880:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat00039880:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
00039890:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre00039890:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
000398a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati000398a0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
000398b0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
000398c0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
000398d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
000398e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
000398f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
00039900:·2269·646d·3935·3639·223e·3c70·7265·3e3c··"idm9569"><pre>< 
00039910:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
00039920:·5d5d·0a6e·616d·6520·3d20·2264·6e66·2d61··]].name·=·"dnf-a 
00039930:·7574·6f6d·6174·6963·220a·7665·7273·696f··utomatic".versio 
00039940:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><000398b0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 000398c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 000398d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 000398e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 000398f0:·6964·3d22·6964·6d39·3536·3922·3e3c·7461··id="idm9569"><ta
 00039900:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 00039910:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 00039920:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 00039930:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 00039940:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 00039950:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 00039960:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00039970:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 00039980:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00039990:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 000399a0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 000399b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 000399c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 000399d0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 000399e0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 000399f0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 00039a00:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 00039a10:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 00039a20:·2070·6c61·7466·6f72·6d73·0a69·6620·2120···platforms.if·!·
 00039a30:·2820·7b20·7270·6d20·2d2d·7175·6965·7420··(·{·rpm·--quiet·
 00039a40:·2d71·206b·6572·6e65·6c20·3b7d·2026·616d··-q·kernel·;}·&am
 00039a50:·703b·2661·6d70·3b20·7b20·7270·6d20·2d2d··p;&amp;·{·rpm·--
 00039a60:·7175·6965·7420·2d71·2072·706d·2d6f·7374··quiet·-q·rpm-ost
 00039a70:·7265·6520·3b7d·2026·616d·703b·2661·6d70··ree·;}·&amp;&amp
 00039a80:·3b20·7b20·7270·6d20·2d2d·7175·6965·7420··;·{·rpm·--quiet·
 00039a90:·2d71·2062·6f6f·7463·203b·7d20·2661·6d70··-q·bootc·;}·&amp
 00039aa0:·3b26·616d·703b·207b·2021·2072·706d·202d··;&amp;·{·!·rpm·-
 00039ab0:·2d71·7569·6574·202d·7120·6f70·656e·7368··-quiet·-q·opensh
 00039ac0:·6966·742d·6b75·6265·6c65·7420·3b7d·2029··ift-kubelet·;}·)
 00039ad0:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 00039ae0:·202d·7120·2d2d·7175·6965·7420·2264·6e66···-q·--quiet·"dnf
 00039af0:·2d61·7574·6f6d·6174·6963·2220·3b20·7468··-automatic"·;·th
 00039b00:·656e·0a20·2020·2079·756d·2069·6e73·7461··en.····yum·insta
 00039b10:·6c6c·202d·7920·2264·6e66·2d61·7574·6f6d··ll·-y·"dnf-autom
 00039b20:·6174·6963·220a·6669·0a0a·656c·7365·0a20··atic".fi..else.·
 00039b30:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 00039b40:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 00039b50:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 00039b60:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 00039b70:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
00039950:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl00039b80:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
00039960:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc00039b90:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
00039970:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl00039ba0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
00039980:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat00039bb0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
00039990:·612d·7461·7267·6574·3d22·2369·646d·3935··a-target="#idm9500039bc0:·612d·7461·7267·6574·3d22·2369·646d·3935··a-target="#idm95
000399a0:·3730·2220·7461·6269·6e64·6578·3d22·3022··70"·tabindex="0"00039bd0:·3730·2220·7461·6269·6e64·6578·3d22·3022··70"·tabindex="0"
000399b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00039be0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
000399c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00039bf0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
000399d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00039c00:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
000399e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00039c10:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
000399f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00039c20:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
00039a00:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
00039a10:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
00039a20:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
00039a30:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
00039a40:·6522·2069·643d·2269·646d·3935·3730·223e··e"·id="idm9570"> 
00039a50:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
00039a60:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe00039c30:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
 00039c40:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 00039c50:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 00039c60:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 00039c70:·6170·7365·2220·6964·3d22·6964·6d39·3537··apse"·id="idm957
 00039c80:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=
 00039c90:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 00039ca0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
00039a70:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered00039cb0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
00039a80:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
00039a90:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple00039cc0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 00039cd0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 00039ce0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00039cf0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
00039aa0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo00039d00:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00039ab0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00039ac0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
00039ad0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00039ae0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
00039af0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
00039b00:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><00039d10:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
00039b10:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00039b20:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00039b30:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00039b40:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
00039b50:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
00039b60:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
00039b70:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
00039b80:·2021·2028·207b·2072·706d·202d·2d71·7569···!·(·{·rpm·--qui 
00039b90:·6574·202d·7120·6b65·726e·656c·203b·7d20··et·-q·kernel·;}· 
00039ba0:·2661·6d70·3b26·616d·703b·207b·2072·706d··&amp;&amp;·{·rpm 
00039bb0:·202d·2d71·7569·6574·202d·7120·7270·6d2d···--quiet·-q·rpm- 
00039bc0:·6f73·7472·6565·203b·7d20·2661·6d70·3b26··ostree·;}·&amp;& 
00039bd0:·616d·703b·207b·2072·706d·202d·2d71·7569··amp;·{·rpm·--qui 
00039be0:·6574·202d·7120·626f·6f74·6320·3b7d·2026··et·-q·bootc·;}·& 
00039bf0:·616d·703b·2661·6d70·3b20·7b20·2120·7270··amp;&amp;·{·!·rp 
00039c00:·6d20·2d2d·7175·6965·7420·2d71·206f·7065··m·--quiet·-q·ope 
00039c10:·6e73·6869·6674·2d6b·7562·656c·6574·203b··nshift-kubelet·; 
00039c20:·7d20·293b·2074·6865·6e0a·0a69·6620·2120··}·);·then..if·!· 
00039c30:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·"00039d20:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 00039d30:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 00039d40:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 00039d50:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 00039d60:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 00039d70:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
 00039d80:·653a·2047·6174·6865·7220·7468·6520·7061··e:·Gather·the·pa
 00039d90:·636b·6167·6520·6661·6374·730a·2020·7061··ckage·facts.··pa
 00039da0:·636b·6167·655f·6661·6374·733a·0a20·2020··ckage_facts:.···
 00039db0:·206d·616e·6167·6572·3a20·6175·746f·0a20···manager:·auto.·
Max diff block lines reached; 95618/125592 bytes (76.13%) of diff not shown.
18.5 KB
html2text {}
    
Offset 81, 19 lines modifiedOffset 81, 14 lines modified
81 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade81 Rationale:··dnf-automatic·is·an·alternative·command·line·interface·(CLI)·to·dnf·upgrade
82 ············suitable·for·automatic,·regular·execution.82 ············suitable·for·automatic,·regular·execution.
83 Severity: ··medium83 Severity: ··medium
84 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed84 Rule·ID:····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
85 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.285 ············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
86 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008086 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
87 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R6187 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
88 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
89 [[packages]] 
90 name·=·"dnf-automatic" 
91 version·=·"*" 
92 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
93 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low89 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
94 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low90 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
95 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false91 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
96 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable92 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
97 #·Remediation·is·applicable·only·in·certain·platforms93 #·Remediation·is·applicable·only·in·certain·platforms
98 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-94 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 133, 33 lines modifiedOffset 128, 38 lines modified
133 ··tags:128 ··tags:
134 ··-·enable_strategy129 ··-·enable_strategy
135 ··-·low_complexity130 ··-·low_complexity
136 ··-·low_disruption131 ··-·low_disruption
137 ··-·medium_severity132 ··-·medium_severity
138 ··-·no_reboot_needed133 ··-·no_reboot_needed
139 ··-·package_dnf-automatic_installed134 ··-·package_dnf-automatic_installed
 135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 140 package·--add=dnf-automatic
 141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 142 [[packages]]
 143 name·=·"dnf-automatic"
 144 version·=·"*"
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
145 include·install_dnf-automatic150 include·install_dnf-automatic
  
146 class·install_dnf-automatic·{151 class·install_dnf-automatic·{
147 ··package·{·'dnf-automatic':152 ··package·{·'dnf-automatic':
148 ····ensure·=>·'installed',153 ····ensure·=>·'installed',
149 ··}154 ··}
150 }155 }
151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
156 package·--add=dnf-automatic 
157 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*156 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
158 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed157 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
159 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/158 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
160 automatic.conf.159 automatic.conf.
161 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation160 ············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
162 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and161 ············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
163 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in162 Rationale:··updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 11301, 33 lines modifiedOffset 11301, 33 lines modified
11301 ··-·PCI-DSSv4-2.2.411301 ··-·PCI-DSSv4-2.2.4
11302 ··-·disable_strategy11302 ··-·disable_strategy
11303 ··-·low_complexity11303 ··-·low_complexity
11304 ··-·low_disruption11304 ··-·low_disruption
11305 ··-·medium_severity11305 ··-·medium_severity
11306 ··-·no_reboot_needed11306 ··-·no_reboot_needed
11307 ··-·package_dhcp_removed11307 ··-·package_dhcp_removed
 11308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11313 package·--remove=dhcp
11308 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811314 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11309 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11315 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11310 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11316 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11311 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11317 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11312 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11318 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11313 include·remove_dhcp11319 include·remove_dhcp
  
11314 class·remove_dhcp·{11320 class·remove_dhcp·{
11315 ··package·{·'dhcp':11321 ··package·{·'dhcp':
11316 ····ensure·=>·'purged',11322 ····ensure·=>·'purged',
11317 ··}11323 ··}
11318 }11324 }
11319 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
11320 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
11321 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
11322 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
11323 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable 
  
11324 package·--remove=dhcp 
11325 Group  ·Mail·Server·Software·  Group·contains·1·rule11325 Group  ·Mail·Server·Software·  Group·contains·1·rule
11326 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very11326 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Mail·servers·are·used·to·send·and·receive·email·over·the·network.·Mail·is·a·very
11327 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure11327 common·service,·and·Mail·Transfer·Agents·(MTAs)·are·obvious·targets·of·network·attack.·Ensure
11328 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as11328 that·systems·are·not·running·MTAs·unnecessarily,·and·configure·needed·MTAs·as·defensively·as
11329 possible.11329 possible.
  
11330 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.11330 Very·few·systems·at·any·site·should·be·configured·to·directly·receive·email·over·the·network.
Offset 11420, 33 lines modifiedOffset 11420, 33 lines modified
11420 ··-·NIST-800-53-CM-7(b)11420 ··-·NIST-800-53-CM-7(b)
11421 ··-·disable_strategy11421 ··-·disable_strategy
11422 ··-·low_complexity11422 ··-·low_complexity
11423 ··-·low_disruption11423 ··-·low_disruption
11424 ··-·medium_severity11424 ··-·medium_severity
11425 ··-·no_reboot_needed11425 ··-·no_reboot_needed
11426 ··-·package_sendmail_removed11426 ··-·package_sendmail_removed
 11427 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 11428 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 11429 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 11430 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 11431 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 11432 package·--remove=sendmail
11427 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811433 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11428 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11434 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11429 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11435 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11430 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11436 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11431 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11437 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11432 include·remove_sendmail11438 include·remove_sendmail
Max diff block lines reached; 13784/18943 bytes (72.77%) of diff not shown.
354 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ccn_advanced.html
    
Offset 21758, 185 lines modifiedOffset 21758, 185 lines modified
00054fd0:·612d·7461·7267·6574·3d22·2369·646d·3933··a-target="#idm9300054fd0:·612d·7461·7267·6574·3d22·2369·646d·3933··a-target="#idm93
00054fe0:·3630·2220·7461·6269·6e64·6578·3d22·3022··60"·tabindex="0"00054fe0:·3630·2220·7461·6269·6e64·6578·3d22·3022··60"·tabindex="0"
00054ff0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00054ff0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
00055000:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00055000:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
00055010:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00055010:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00055020:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00055020:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00055030:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00055030:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
00055040:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
00055050:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
00055060:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00055070:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00055080:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00055090:·6964·3d22·6964·6d39·3336·3022·3e3c·7072··id="idm9360"><pr 
000550a0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
000550b0:·6765·735d·5d0a·6e61·6d65·203d·2022·6372··ges]].name·=·"cr 
000550c0:·7970·7473·6574·7570·220a·7665·7273·696f··yptsetup".versio 
000550d0:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
000550e0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
000550f0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00055100:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00055110:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
00055120:·612d·7461·7267·6574·3d22·2369·646d·3933··a-target="#idm93 
00055130:·3631·2220·7461·6269·6e64·6578·3d22·3022··61"·tabindex="0" 
00055140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00055150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00055160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00055170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
00055180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
00055190:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri00055040:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
000551a0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d00055050:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
000551b0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-00055060:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
000551c0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps00055070:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
000551d0:·6522·2069·643d·2269·646d·3933·3631·223e··e"·id="idm9361">00055080:·6522·2069·643d·2269·646d·3933·3630·223e··e"·id="idm9360">
000551e0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta00055090:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
000551f0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe000550a0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
00055200:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered000550b0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
00055210:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed000550c0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
00055220:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple000550d0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
00055230:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo000550e0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
00055240:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><000550f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
00055250:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</00055100:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
00055260:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><00055110:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00055270:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo00055120:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
00055280:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals00055130:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
00055290:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><00055140:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
000552a0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th00055150:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
000552b0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>00055160:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
000552c0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr00055170:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
000552d0:·653e·3c63·6f64·653e·0a69·6620·2120·7270··e><code>.if·!·rp00055180:·653e·3c63·6f64·653e·0a69·6620·2120·7270··e><code>.if·!·rp
000552e0:·6d20·2d71·202d·2d71·7569·6574·2022·6372··m·-q·--quiet·"cr00055190:·6d20·2d71·202d·2d71·7569·6574·2022·6372··m·-q·--quiet·"cr
000552f0:·7970·7473·6574·7570·2220·3b20·7468·656e··yptsetup"·;·then000551a0:·7970·7473·6574·7570·2220·3b20·7468·656e··yptsetup"·;·then
00055300:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install000551b0:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install
00055310:·202d·7920·2263·7279·7074·7365·7475·7022···-y·"cryptsetup"000551c0:·202d·7920·2263·7279·7074·7365·7475·7022···-y·"cryptsetup"
00055320:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre000551d0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
00055330:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=000551e0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
00055340:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success000551f0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
00055350:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c00055200:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
00055360:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta00055210:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
00055370:·7267·6574·3d22·2369·646d·3933·3632·2220··rget="#idm9362"·00055220:·7267·6574·3d22·2369·646d·3933·3631·2220··rget="#idm9361"·
00055380:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00055230:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00055390:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00055240:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
000553a0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00055250:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
000553b0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00055260:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
000553c0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00055270:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
000553d0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00055280:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
000553e0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe00055290:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe
000553f0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di000552a0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
00055400:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c000552b0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
00055410:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse000552c0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
00055420:·2220·6964·3d22·6964·6d39·3336·3222·3e3c··"·id="idm9362"><000552d0:·2220·6964·3d22·6964·6d39·3336·3122·3e3c··"·id="idm9361"><
00055430:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab000552e0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
00055440:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped000552f0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
00055450:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·00055300:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
00055460:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"00055310:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
00055470:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex00055320:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
00055480:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low00055330:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00055490:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00055340:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
000554a0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t00055350:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
000554b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></00055360:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
000554c0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo00055370:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
000554d0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false00055380:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
000554e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00055390:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
000554f0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>000553a0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
00055500:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><000553b0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
00055510:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre000553c0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
00055520:·3e3c·636f·6465·3e2d·206e·616d·653a·2045··><code>-·name:·E000553d0:·3e3c·636f·6465·3e2d·206e·616d·653a·2045··><code>-·name:·E
00055530:·6e73·7572·6520·6372·7970·7473·6574·7570··nsure·cryptsetup000553e0:·6e73·7572·6520·6372·7970·7473·6574·7570··nsure·cryptsetup
00055540:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.··000553f0:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.··
00055550:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam00055400:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam
00055560:·653a·2063·7279·7074·7365·7475·700a·2020··e:·cryptsetup.··00055410:·653a·2063·7279·7074·7365·7475·700a·2020··e:·cryptsetup.··
00055570:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present00055420:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present
00055580:·0a20·2074·6167·733a·0a20·202d·2050·4349··.··tags:.··-·PCI00055430:·0a20·2074·6167·733a·0a20·202d·2050·4349··.··tags:.··-·PCI
00055590:·2d44·5353·7634·2d33·2e35·0a20·202d·2050··-DSSv4-3.5.··-·P00055440:·2d44·5353·7634·2d33·2e35·0a20·202d·2050··-DSSv4-3.5.··-·P
000555a0:·4349·2d44·5353·7634·2d33·2e35·2e31·0a20··CI-DSSv4-3.5.1.·00055450:·4349·2d44·5353·7634·2d33·2e35·2e31·0a20··CI-DSSv4-3.5.1.·
000555b0:·202d·2050·4349·2d44·5353·7634·2d33·2e35···-·PCI-DSSv4-3.500055460:·202d·2050·4349·2d44·5353·7634·2d33·2e35···-·PCI-DSSv4-3.5
000555c0:·2e31·2e32·0a20·202d·2065·6e61·626c·655f··.1.2.··-·enable_00055470:·2e31·2e32·0a20·202d·2065·6e61·626c·655f··.1.2.··-·enable_
000555d0:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low00055480:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
000555e0:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·00055490:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
000555f0:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·000554a0:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
00055600:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi000554b0:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
00055610:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot000554c0:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
00055620:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack000554d0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack
00055630:·6167·655f·6372·7970·7473·6574·7570·2d6c··age_cryptsetup-l000554e0:·6167·655f·6372·7970·7473·6574·7570·2d6c··age_cryptsetup-l
00055640:·756b·735f·696e·7374·616c·6c65·640a·3c2f··uks_installed.</000554f0:·756b·735f·696e·7374·616c·6c65·640a·3c2f··uks_installed.</
00055650:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div00055500:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
00055660:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b00055510:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
00055670:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data00055520:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
00055680:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps00055530:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
00055690:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="00055540:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
000556a0:·2369·646d·3933·3633·2220·7461·6269·6e64··#idm9363"·tabind00055550:·2369·646d·3933·3632·2220·7461·6269·6e64··#idm9362"·tabind
000556b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but00055560:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
000556c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand00055570:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
000556d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title00055580:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
000556e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re00055590:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
000556f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">000555a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
00055700:·5265·6d65·6469·6174·696f·6e20·5075·7070··Remediation·Pupp000555b0:·5265·6d65·6469·6174·696f·6e20·416e·6163··Remediation·Anac
00055710:·6574·2073·6e69·7070·6574·20e2·87b2·3c2f··et·snippet·...</000555c0:·6f6e·6461·2073·6e69·7070·6574·20e2·87b2··onda·snippet·...
00055720:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class000555d0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
00055730:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse000555e0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
00055740:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i000555f0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
00055750:·646d·3933·3633·223e·3c74·6162·6c65·2063··dm9363"><table·c00055600:·2269·646d·3933·3632·223e·3c74·6162·6c65··"idm9362"><table
00055760:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl00055610:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
00055770:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-00055620:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
00055780:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c00055630:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
00055790:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t00055640:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
000557a0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t00055650:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
000557b0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
Max diff block lines reached; 303452/327630 bytes (92.62%) of diff not shown.
34.3 KB
html2text {}
    
Offset 1789, 19 lines modifiedOffset 1789, 14 lines modified
1789 Rationale:··management·of·multiple·user·passwords.·In·contrast·to·existing·solution,·LUKS·stores·all1789 Rationale:··management·of·multiple·user·passwords.·In·contrast·to·existing·solution,·LUKS·stores·all
1790 ············necessary·setup·information·in·the·partition·header,·enabling·the·user·to·transport·or·migrate1790 ············necessary·setup·information·in·the·partition·header,·enabling·the·user·to·transport·or·migrate
1791 ············their·data·seamlessly.·LUKS·for·dm-crypt·is·implemented·in·cryptsetup.1791 ············their·data·seamlessly.·LUKS·for·dm-crypt·is·implemented·in·cryptsetup.
1792 Severity: ··medium1792 Severity: ··medium
1793 Rule·ID:····xccdf_org.ssgproject.content_rule_package_cryptsetup-luks_installed1793 Rule·ID:····xccdf_org.ssgproject.content_rule_package_cryptsetup-luks_installed
1794 References:·_\x8c_\x8c_\x8n·····A.25.SEC-OL11794 References:·_\x8c_\x8c_\x8n·····A.25.SEC-OL1
1795 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·3.5.1.2,·3.5.1,·3.51795 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·3.5.1.2,·3.5.1,·3.5
1796 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1797 [[packages]] 
1798 name·=·"cryptsetup" 
1799 version·=·"*" 
1800 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81796 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1801 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1797 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1802 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1798 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1803 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1799 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1804 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1800 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1805 if·!·rpm·-q·--quiet·"cryptsetup"·;·then1801 if·!·rpm·-q·--quiet·"cryptsetup"·;·then
Offset 1822, 33 lines modifiedOffset 1817, 38 lines modified
1822 ··-·PCI-DSSv4-3.5.1.21817 ··-·PCI-DSSv4-3.5.1.2
1823 ··-·enable_strategy1818 ··-·enable_strategy
1824 ··-·low_complexity1819 ··-·low_complexity
1825 ··-·low_disruption1820 ··-·low_disruption
1826 ··-·medium_severity1821 ··-·medium_severity
1827 ··-·no_reboot_needed1822 ··-·no_reboot_needed
1828 ··-·package_cryptsetup-luks_installed1823 ··-·package_cryptsetup-luks_installed
 1824 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1825 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1826 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1827 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1828 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1829 package·--add=cryptsetup
 1830 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1831 [[packages]]
 1832 name·=·"cryptsetup"
 1833 version·=·"*"
1829 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81834 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1830 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1835 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1831 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1836 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1832 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1837 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1833 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1838 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1834 include·install_cryptsetup1839 include·install_cryptsetup
  
1835 class·install_cryptsetup·{1840 class·install_cryptsetup·{
1836 ··package·{·'cryptsetup':1841 ··package·{·'cryptsetup':
1837 ····ensure·=>·'installed',1842 ····ensure·=>·'installed',
1838 ··}1843 ··}
1839 }1844 }
1840 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1841 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1842 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1843 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1844 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1845 package·--add=cryptsetup 
1846 Group  ·Account·and·Access·Control·  Group·contains·13·groups·and·29·rules1845 Group  ·Account·and·Access·Control·  Group·contains·13·groups·and·29·rules
1847 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,·they1846 _\x8[_\x8r_\x8e_\x8f_\x8]  ·In·traditional·Unix·security,·if·an·attacker·gains·shell·access·to·a·certain·login·account,·they
1848 can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it·more1847 can·perform·any·action·or·access·any·file·to·which·that·account·has·access.·Therefore,·making·it·more
1849 difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged·accounts,·is1848 difficult·for·unauthorized·people·to·gain·shell·access·to·accounts,·particularly·to·privileged·accounts,·is
1850 a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for·restricting·access·to1849 a·necessary·part·of·securing·a·system.·This·section·introduces·mechanisms·for·restricting·access·to
1851 accounts·under·Oracle·Linux·9.1850 accounts·under·Oracle·Linux·9.
1852 Group  ·Warning·Banners·for·System·Accesses·  Group·contains·1·group·and·5·rules1851 Group  ·Warning·Banners·for·System·Accesses·  Group·contains·1·group·and·5·rules
Offset 9874, 19 lines modifiedOffset 9874, 14 lines modified
9874 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023229874 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
9875 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)9875 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
9876 ············_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.19876 ············_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
9877 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,·SRG-OS-9877 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,·SRG-OS-
9878 ····················000480-GPOS-00227,·SRG-OS-000480-GPOS-002329878 ····················000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
9879 ············_\x8c_\x8c_\x8n·····A.8.SEC-OL39879 ············_\x8c_\x8c_\x8n·····A.8.SEC-OL3
9880 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.29880 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
9881 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9882 [[packages]] 
9883 name·=·"firewalld" 
9884 version·=·"*" 
9885 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89881 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9886 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9882 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9887 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9883 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9888 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9884 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9889 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9885 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9890 #·Remediation·is·applicable·only·in·certain·platforms9886 #·Remediation·is·applicable·only·in·certain·platforms
9891 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then9887 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 9928, 33 lines modifiedOffset 9923, 38 lines modified
9928 ··-·PCI-DSSv4-1.2.19923 ··-·PCI-DSSv4-1.2.1
9929 ··-·enable_strategy9924 ··-·enable_strategy
9930 ··-·low_complexity9925 ··-·low_complexity
9931 ··-·low_disruption9926 ··-·low_disruption
9932 ··-·medium_severity9927 ··-·medium_severity
9933 ··-·no_reboot_needed9928 ··-·no_reboot_needed
9934 ··-·package_firewalld_installed9929 ··-·package_firewalld_installed
 9930 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 9931 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9932 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9933 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9934 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 9935 package·--add=firewalld
 9936 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9937 [[packages]]
 9938 name·=·"firewalld"
 9939 version·=·"*"
9935 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89940 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9936 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9941 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9937 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9942 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9938 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9943 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9939 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9944 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9940 include·install_firewalld9945 include·install_firewalld
  
9941 class·install_firewalld·{9946 class·install_firewalld·{
9942 ··package·{·'firewalld':9947 ··package·{·'firewalld':
9943 ····ensure·=>·'installed',9948 ····ensure·=>·'installed',
9944 ··}9949 ··}
9945 }9950 }
9946 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
9947 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
9948 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
9949 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
9950 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
9951 package·--add=firewalld 
9952 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*9951 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
9953 The·firewalld·service·can·be·enabled·with·the·following·command:9952 The·firewalld·service·can·be·enabled·with·the·following·command:
9954 $·sudo·systemctl·enable·firewalld.service9953 $·sudo·systemctl·enable·firewalld.service
Max diff block lines reached; 29675/35067 bytes (84.62%) of diff not shown.
178 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ccn_basic.html
    
Offset 37335, 218 lines modifiedOffset 37335, 218 lines modified
00091d60:·6574·3d22·2369·646d·3230·3832·3622·2074··et="#idm20826"·t00091d60:·6574·3d22·2369·646d·3230·3832·3622·2074··et="#idm20826"·t
00091d70:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00091d70:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00091d80:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00091d80:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00091d90:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00091d90:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00091da0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00091da0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
00091db0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=00091db0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
00091dc0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation00091dc0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
00091dd0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
00091de0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
00091df0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00091e00:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00091e10:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00091e20:·646d·3230·3832·3622·3e3c·7072·653e·3c63··dm20826"><pre><c 
00091e30:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
00091e40:·5d0a·6e61·6d65·203d·2022·6669·7265·7761··].name·=·"firewa 
00091e50:·6c6c·6422·0a76·6572·7369·6f6e·203d·2022··lld".version·=·" 
00091e60:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
00091e70:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00091e80:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00091e90:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00091ea0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00091eb0:·6765·743d·2223·6964·6d32·3038·3237·2220··get="#idm20827"· 
00091ec0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00091ed0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00091ee0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00091ef0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00091f00:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00091dd0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 00091de0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00091df0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00091e00:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00091e10:·3d22·6964·6d32·3038·3236·223e·3c74·6162··="idm20826"><tab
 00091e20:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 00091e30:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00091e40:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00091e50:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00091e60:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00091e70:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00091e80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00091e90:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00091ea0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00091eb0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00091ec0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 00091ed0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00091ee0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00091ef0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00091f00:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
00091f10:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00091f10:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
00091f20:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
00091f30:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00091f40:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00091f20:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 00091f30:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 00091f40:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 00091f50:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 00091f60:·656c·207c·7c20·7270·6d20·2d2d·7175·6965··el·||·rpm·--quie
 00091f70:·7420·2d71·206b·6572·6e65·6c2d·7565·6b3b··t·-q·kernel-uek;
 00091f80:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 00091f90:·2d71·202d·2d71·7569·6574·2022·6669·7265··-q·--quiet·"fire
 00091fa0:·7761·6c6c·6422·203b·2074·6865·6e0a·2020··walld"·;·then.··
 00091fb0:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 00091fc0:·2022·6669·7265·7761·6c6c·6422·0a66·690a···"firewalld".fi.
 00091fd0:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
 00091fe0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
 00091ff0:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
 00092000:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
 00092010:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
 00092020:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00092030:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00092040:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00092050:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00092060:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 00092070:·2223·6964·6d32·3038·3237·2220·7461·6269··"#idm20827"·tabi
 00092080:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
 00092090:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
 000920a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
 000920b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
 000920c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
 000920d0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
 000920e0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·..
 000920f0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00092100:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00092110:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00092120:·3d22·6964·6d32·3038·3237·223e·3c74·6162··="idm20827"><tab
 00092130:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 00092140:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00092150:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00092160:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00092170:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00092180:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00092190:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 000921a0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 000921b0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000921c0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 000921d0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 000921e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 000921f0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00092200:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00092210:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00092220:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath
 00092230:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f
 00092240:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f
 00092250:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage
 00092260:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:.
 00092270:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
 00092280:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI-
 00092290:·4453·5376·342d·312e·320a·2020·2d20·5043··DSSv4-1.2.··-·PC
 000922a0:·492d·4453·5376·342d·312e·322e·310a·2020··I-DSSv4-1.2.1.··
 000922b0:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg
 000922c0:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple
 000922d0:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis
 000922e0:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi
 000922f0:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-·
 00092300:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed
 00092310:·0a20·202d·2070·6163·6b61·6765·5f66·6972··.··-·package_fir
 00092320:·6577·616c·6c64·5f69·6e73·7461·6c6c·6564··ewalld_installed
 00092330:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure
 00092340:·2066·6972·6577·616c·6c64·2069·7320·696e···firewalld·is·in
 00092350:·7374·616c·6c65·640a·2020·7061·636b·6167··stalled.··packag
 00092360:·653a·0a20·2020·206e·616d·653a·2066·6972··e:.····name:·fir
 00092370:·6577·616c·6c64·0a20·2020·2073·7461·7465··ewalld.····state
 00092380:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when
 00092390:·3a20·2822·6b65·726e·656c·2220·696e·2061··:·("kernel"·in·a
 000923a0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
 000923b0:·6b61·6765·7320·6f72·2022·6b65·726e·656c··kages·or·"kernel
 000923c0:·2d75·656b·2220·696e·2061·6e73·6962·6c65··-uek"·in·ansible
 000923d0:·5f66·6163·7473·2e70·6163·6b61·6765·7329··_facts.packages)
 000923e0:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS
 000923f0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
Max diff block lines reached; 139768/168500 bytes (82.95%) of diff not shown.
12.9 KB
html2text {}
    
Offset 6079, 19 lines modifiedOffset 6079, 14 lines modified
6079 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023226079 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
6080 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)6080 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
6081 ············_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.16081 ············_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
6082 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,6082 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,
6083 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-002326083 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
6084 ············_\x8c_\x8c_\x8n·····A.8.SEC-OL36084 ············_\x8c_\x8c_\x8n·····A.8.SEC-OL3
6085 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.26085 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
6086 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6087 [[packages]] 
6088 name·=·"firewalld" 
6089 version·=·"*" 
6090 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86086 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6091 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6087 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6092 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6088 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6093 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6089 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6094 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6090 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6095 #·Remediation·is·applicable·only·in·certain·platforms6091 #·Remediation·is·applicable·only·in·certain·platforms
6096 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then6092 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 6133, 33 lines modifiedOffset 6128, 38 lines modified
6133 ··-·PCI-DSSv4-1.2.16128 ··-·PCI-DSSv4-1.2.1
6134 ··-·enable_strategy6129 ··-·enable_strategy
6135 ··-·low_complexity6130 ··-·low_complexity
6136 ··-·low_disruption6131 ··-·low_disruption
6137 ··-·medium_severity6132 ··-·medium_severity
6138 ··-·no_reboot_needed6133 ··-·no_reboot_needed
6139 ··-·package_firewalld_installed6134 ··-·package_firewalld_installed
 6135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 6136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 6137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 6138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 6139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 6140 package·--add=firewalld
 6141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 6142 [[packages]]
 6143 name·=·"firewalld"
 6144 version·=·"*"
6140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6145 include·install_firewalld6150 include·install_firewalld
  
6146 class·install_firewalld·{6151 class·install_firewalld·{
6147 ··package·{·'firewalld':6152 ··package·{·'firewalld':
6148 ····ensure·=>·'installed',6153 ····ensure·=>·'installed',
6149 ··}6154 ··}
6150 }6155 }
6151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
6152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
6153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
6154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
6155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
6156 package·--add=firewalld 
6157 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*6156 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
6158 The·firewalld·service·can·be·enabled·with·the·following·command:6157 The·firewalld·service·can·be·enabled·with·the·following·command:
6159 $·sudo·systemctl·enable·firewalld.service6158 $·sudo·systemctl·enable·firewalld.service
6160 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by6159 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by
6161 Rationale:··restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents6160 Rationale:··restricting·services·and·known·good·IP·addresses·and·address·ranges.·This·prevents
6162 ············connections·from·unknown·hosts·and·protocols.6161 ············connections·from·unknown·hosts·and·protocols.
6163 Severity: ··medium6162 Severity: ··medium
Offset 6176, 18 lines modifiedOffset 6176, 14 lines modified
6176 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-16176 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
6177 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.16177 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
6178 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-6178 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-
6179 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-002326179 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
6180 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A216180 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
6181 ············_\x8c_\x8c_\x8n············A.8.SEC-OL36181 ············_\x8c_\x8c_\x8n············A.8.SEC-OL3
6182 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.26182 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
6183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6184 [customizations.services] 
6185 enabled·=·["firewalld"] 
6186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6191 #·Remediation·is·applicable·only·in·certain·platforms6188 #·Remediation·is·applicable·only·in·certain·platforms
6192 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·&&·{·rpm·--quiet·-q·firewalld;·};·then6189 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·&&·{·rpm·--quiet·-q·firewalld;·};·then
Offset 6257, 14 lines modifiedOffset 6253, 18 lines modified
6257 ··-·PCI-DSSv4-1.2.16253 ··-·PCI-DSSv4-1.2.1
6258 ··-·enable_strategy6254 ··-·enable_strategy
6259 ··-·low_complexity6255 ··-·low_complexity
6260 ··-·low_disruption6256 ··-·low_disruption
6261 ··-·medium_severity6257 ··-·medium_severity
6262 ··-·no_reboot_needed6258 ··-·no_reboot_needed
6263 ··-·service_firewalld_enabled6259 ··-·service_firewalld_enabled
 6260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 6261 [customizations.services]
 6262 enabled·=·["firewalld"]
6264 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86263 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6265 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6264 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6266 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6265 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6267 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6266 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6268 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6267 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6269 include·enable_firewalld6268 include·enable_firewalld
  
Offset 11194, 18 lines modifiedOffset 11194, 14 lines modified
11194 systemctl·disable·nftables11194 systemctl·disable·nftables
11195 Rationale:··Running·both·firewalld·and·nftables·may·lead·to·conflict.·nftables·is·actually·one·of·the11195 Rationale:··Running·both·firewalld·and·nftables·may·lead·to·conflict.·nftables·is·actually·one·of·the
11196 ············backends·for·firewalld·management·tools.11196 ············backends·for·firewalld·management·tools.
11197 Severity: ··medium11197 Severity: ··medium
11198 Rule·ID:····xccdf_org.ssgproject.content_rule_service_nftables_disabled11198 Rule·ID:····xccdf_org.ssgproject.content_rule_service_nftables_disabled
11199 References:·_\x8c_\x8c_\x8n·····A.8.SEC-OL311199 References:·_\x8c_\x8c_\x8n·····A.8.SEC-OL3
11200 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.211200 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
11201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
11202 [customizations.services] 
11203 masked·=·["nftables"] 
11204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x811201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
11205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable11205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
11209 #·Remediation·is·applicable·only·in·certain·platforms11206 #·Remediation·is·applicable·only·in·certain·platforms
11210 if·(·rpm·--quiet·-q·firewalld·&&·rpm·--quiet·-q·nftables·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-11207 if·(·rpm·--quiet·-q·firewalld·&&·rpm·--quiet·-q·nftables·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-
Offset 11326, 14 lines modifiedOffset 11322, 18 lines modified
11326 ··-·PCI-DSSv4-1.2.111322 ··-·PCI-DSSv4-1.2.1
11327 ··-·disable_strategy11323 ··-·disable_strategy
11328 ··-·low_complexity11324 ··-·low_complexity
11329 ··-·low_disruption11325 ··-·low_disruption
Max diff block lines reached; 7714/13160 bytes (58.62%) of diff not shown.
327 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ccn_intermediate.html
    
Offset 43176, 219 lines modifiedOffset 43176, 219 lines modified
000a8a70:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id000a8a70:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
000a8a80:·6d32·3038·3236·2220·7461·6269·6e64·6578··m20826"·tabindex000a8a80:·6d32·3038·3236·2220·7461·6269·6e64·6578··m20826"·tabindex
000a8a90:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto000a8a90:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
000a8aa0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded000a8aa0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
000a8ab0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="000a8ab0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
000a8ac0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve000a8ac0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
000a8ad0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re000a8ad0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
000a8ae0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil000a8ae0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 000a8af0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 000a8b00:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 000a8b10:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 000a8b20:·6c61·7073·6522·2069·643d·2269·646d·3230··lapse"·id="idm20
 000a8b30:·3832·3622·3e3c·7461·626c·6520·636c·6173··826"><table·clas
 000a8b40:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
000a8af0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
000a8b00:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
000a8b10:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
000a8b20:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
000a8b30:·7365·2220·6964·3d22·6964·6d32·3038·3236··se"·id="idm20826 
000a8b40:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
000a8b50:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
000a8b60:·3d20·2266·6972·6577·616c·6c64·220a·7665··=·"firewalld".ve 
000a8b70:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
000a8b80:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
000a8b90:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
000a8ba0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
000a8bb0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
000a8bc0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
000a8bd0:·646d·3230·3832·3722·2074·6162·696e·6465··dm20827"·tabinde 
000a8be0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
000a8bf0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
000a8c00:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
000a8c10:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
000a8c20:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
000a8c30:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
000a8c40:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
000a8c50:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
000a8c60:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
000a8c70:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
000a8c80:·3038·3237·223e·3c74·6162·6c65·2063·6c61··0827"><table·cla 
000a8c90:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
000a8ca0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
000a8cb0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con000a8b50:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
000a8cc0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
000a8cd0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
000a8ce0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
000a8cf0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt000a8b60:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 000a8b70:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 000a8b80:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 000a8b90:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000a8ba0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 000a8bb0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 000a8bc0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000a8bd0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 000a8be0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 000a8bf0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 000a8c00:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 000a8c10:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 000a8c20:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
 000a8c30:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 000a8c40:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 000a8c50:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 000a8c60:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 000a8c70:·7420·2d71·206b·6572·6e65·6c20·7c7c·2072··t·-q·kernel·||·r
 000a8c80:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 000a8c90:·726e·656c·2d75·656b·3b20·7468·656e·0a0a··rnel-uek;·then..
 000a8ca0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 000a8cb0:·6965·7420·2266·6972·6577·616c·6c64·2220··iet·"firewalld"·
 000a8cc0:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 000a8cd0:·6e73·7461·6c6c·202d·7920·2266·6972·6577··nstall·-y·"firew
 000a8ce0:·616c·6c64·220a·6669·0a0a·656c·7365·0a20··alld".fi..else.·
 000a8cf0:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 000a8d00:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 000a8d10:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
 000a8d20:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d
 000a8d30:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code><
 000a8d40:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 000a8d50:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 000a8d60:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
 000a8d70:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
 000a8d80:·612d·7461·7267·6574·3d22·2369·646d·3230··a-target="#idm20
 000a8d90:·3832·3722·2074·6162·696e·6465·783d·2230··827"·tabindex="0
 000a8da0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 000a8db0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 000a8dc0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 000a8dd0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 000a8de0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 000a8df0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
 000a8e00:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 000a8e10:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 000a8e20:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 000a8e30:·6c61·7073·6522·2069·643d·2269·646d·3230··lapse"·id="idm20
 000a8e40:·3832·3722·3e3c·7461·626c·6520·636c·6173··827"><table·clas
 000a8e50:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 000a8e60:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 000a8e70:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 000a8e80:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 000a8e90:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 000a8ea0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000a8eb0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 000a8ec0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 000a8ed0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000a8ee0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 000a8ef0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 000a8f00:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 000a8f10:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 000a8f20:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 000a8f30:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n
 000a8f40:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the·
 000a8f50:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.··
 000a8f60:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.·
 000a8f70:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto
 000a8f80:·0a20·2074·6167·733a·0a20·202d·204e·4953··.··tags:.··-·NIS
 000a8f90:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
 000a8fa0:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1
 000a8fb0:·2e32·0a20·202d·2050·4349·2d44·5353·7634··.2.··-·PCI-DSSv4
 000a8fc0:·2d31·2e32·2e31·0a20·202d·2065·6e61·626c··-1.2.1.··-·enabl
 000a8fd0:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l
 000a8fe0:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.··
 000a8ff0:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption
 000a9000:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve
 000a9010:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo
 000a9020:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa
 000a9030:·636b·6167·655f·6669·7265·7761·6c6c·645f··ckage_firewalld_
 000a9040:·696e·7374·616c·6c65·640a·0a2d·206e·616d··installed..-·nam
 000a9050:·653a·2045·6e73·7572·6520·6669·7265·7761··e:·Ensure·firewa
 000a9060:·6c6c·6420·6973·2069·6e73·7461·6c6c·6564··lld·is·installed
Max diff block lines reached; 273892/302762 bytes (90.46%) of diff not shown.
31.5 KB
html2text {}
    
Offset 7450, 19 lines modifiedOffset 7450, 14 lines modified
7450 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023227450 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
7451 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)7451 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
7452 ············_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.17452 ············_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
7453 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,·SRG-OS-7453 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,·SRG-OS-
7454 ····················000480-GPOS-00227,·SRG-OS-000480-GPOS-002327454 ····················000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
7455 ············_\x8c_\x8c_\x8n·····A.8.SEC-OL37455 ············_\x8c_\x8c_\x8n·····A.8.SEC-OL3
7456 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.27456 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
7457 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
7458 [[packages]] 
7459 name·=·"firewalld" 
7460 version·=·"*" 
7461 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87457 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7462 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7458 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7463 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7459 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7464 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7460 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7465 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7461 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7466 #·Remediation·is·applicable·only·in·certain·platforms7462 #·Remediation·is·applicable·only·in·certain·platforms
7467 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then7463 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 7504, 33 lines modifiedOffset 7499, 38 lines modified
7504 ··-·PCI-DSSv4-1.2.17499 ··-·PCI-DSSv4-1.2.1
7505 ··-·enable_strategy7500 ··-·enable_strategy
7506 ··-·low_complexity7501 ··-·low_complexity
7507 ··-·low_disruption7502 ··-·low_disruption
7508 ··-·medium_severity7503 ··-·medium_severity
7509 ··-·no_reboot_needed7504 ··-·no_reboot_needed
7510 ··-·package_firewalld_installed7505 ··-·package_firewalld_installed
 7506 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 7507 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 7508 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 7509 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 7510 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 7511 package·--add=firewalld
 7512 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 7513 [[packages]]
 7514 name·=·"firewalld"
 7515 version·=·"*"
7511 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87516 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7512 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7517 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7513 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7518 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7514 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7519 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7515 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7520 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7516 include·install_firewalld7521 include·install_firewalld
  
7517 class·install_firewalld·{7522 class·install_firewalld·{
7518 ··package·{·'firewalld':7523 ··package·{·'firewalld':
7519 ····ensure·=>·'installed',7524 ····ensure·=>·'installed',
7520 ··}7525 ··}
7521 }7526 }
7522 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
7523 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7524 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
7525 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
7526 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
7527 package·--add=firewalld 
7528 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*7527 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·f\x8fi\x8ir\x8re\x8ew\x8wa\x8al\x8ll\x8ld\x8d·E\x8En\x8na\x8ab\x8bl\x8le\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
7529 The·firewalld·service·can·be·enabled·with·the·following·command:7528 The·firewalld·service·can·be·enabled·with·the·following·command:
7530 $·sudo·systemctl·enable·firewalld.service7529 $·sudo·systemctl·enable·firewalld.service
7531 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting7530 ············Access·control·methods·provide·the·ability·to·enhance·system·security·posture·by·restricting
7532 Rationale:··services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown7531 Rationale:··services·and·known·good·IP·addresses·and·address·ranges.·This·prevents·connections·from·unknown
7533 ············hosts·and·protocols.7532 ············hosts·and·protocols.
7534 Severity: ··medium7533 Severity: ··medium
Offset 7547, 18 lines modifiedOffset 7547, 14 lines modified
7547 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-17547 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
7548 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.17548 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
7549 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-00227,7549 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-00227,
7550 ···························SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-002327550 ···························SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
7551 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A217551 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
7552 ············_\x8c_\x8c_\x8n············A.8.SEC-OL37552 ············_\x8c_\x8c_\x8n············A.8.SEC-OL3
7553 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.27553 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
7554 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
7555 [customizations.services] 
7556 enabled·=·["firewalld"] 
7557 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87554 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7558 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7555 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7559 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7556 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7560 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7557 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7561 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7558 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7562 #·Remediation·is·applicable·only·in·certain·platforms7559 #·Remediation·is·applicable·only·in·certain·platforms
7563 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·&&·{·rpm·--quiet·-q·firewalld;·};·then7560 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·&&·{·rpm·--quiet·-q·firewalld;·};·then
Offset 7628, 14 lines modifiedOffset 7624, 18 lines modified
7628 ··-·PCI-DSSv4-1.2.17624 ··-·PCI-DSSv4-1.2.1
7629 ··-·enable_strategy7625 ··-·enable_strategy
7630 ··-·low_complexity7626 ··-·low_complexity
7631 ··-·low_disruption7627 ··-·low_disruption
7632 ··-·medium_severity7628 ··-·medium_severity
7633 ··-·no_reboot_needed7629 ··-·no_reboot_needed
7634 ··-·service_firewalld_enabled7630 ··-·service_firewalld_enabled
 7631 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 7632 [customizations.services]
 7633 enabled·=·["firewalld"]
7635 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87634 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7636 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7635 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7637 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7636 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7638 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7637 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7639 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7638 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7640 include·enable_firewalld7639 include·enable_firewalld
  
Offset 12498, 18 lines modifiedOffset 12498, 14 lines modified
12498 systemctl·disable·nftables12498 systemctl·disable·nftables
12499 Rationale:··Running·both·firewalld·and·nftables·may·lead·to·conflict.·nftables·is·actually·one·of·the12499 Rationale:··Running·both·firewalld·and·nftables·may·lead·to·conflict.·nftables·is·actually·one·of·the
12500 ············backends·for·firewalld·management·tools.12500 ············backends·for·firewalld·management·tools.
12501 Severity: ··medium12501 Severity: ··medium
12502 Rule·ID:····xccdf_org.ssgproject.content_rule_service_nftables_disabled12502 Rule·ID:····xccdf_org.ssgproject.content_rule_service_nftables_disabled
12503 References:·_\x8c_\x8c_\x8n·····A.8.SEC-OL312503 References:·_\x8c_\x8c_\x8n·····A.8.SEC-OL3
12504 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.212504 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
12505 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
12506 [customizations.services] 
12507 masked·=·["nftables"] 
12508 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x812505 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
12509 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12506 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12510 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12507 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12511 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12508 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12512 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable12509 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
12513 #·Remediation·is·applicable·only·in·certain·platforms12510 #·Remediation·is·applicable·only·in·certain·platforms
12514 if·(·rpm·--quiet·-q·firewalld·&&·rpm·--quiet·-q·nftables·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-12511 if·(·rpm·--quiet·-q·firewalld·&&·rpm·--quiet·-q·nftables·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-
Offset 12630, 14 lines modifiedOffset 12626, 18 lines modified
12630 ··-·PCI-DSSv4-1.2.112626 ··-·PCI-DSSv4-1.2.1
12631 ··-·disable_strategy12627 ··-·disable_strategy
12632 ··-·low_complexity12628 ··-·low_complexity
12633 ··-·low_disruption12629 ··-·low_disruption
Max diff block lines reached; 26788/32234 bytes (83.10%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-cui.html
    
Offset 15579, 64 lines modifiedOffset 15579, 64 lines modified
0003cda0:·6172·6765·743d·2223·6964·6d36·3832·3322··arget="#idm6823"0003cda0:·6172·6765·743d·2223·6964·6d36·3832·3322··arget="#idm6823"
0003cdb0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003cdb0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003cdc0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003cdc0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003cdd0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003cdd0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003cde0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003cde0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003cdf0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003cdf0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003ce00:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003ce00:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003ce10:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003ce20:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003ce30:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003ce40:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003ce50:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003ce60:·2269·646d·3638·3233·223e·3c70·7265·3e3c··"idm6823"><pre>< 
0003ce70:·636f·6465·3e0a·5b63·7573·746f·6d69·7a61··code>.[customiza 
0003ce80:·7469·6f6e·735d·0a66·6970·7320·3d20·7472··tions].fips·=·tr 
0003ce90:·7565·0a3c·2f63·6f64·653e·3c2f·7072·653e··ue.</code></pre> 
0003cea0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003ceb0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003cec0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003ced0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003cee0:·6765·743d·2223·6964·6d36·3832·3422·2074··get="#idm6824"·t 
0003cef0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003cf00:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003cf10:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003cf20:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003cf30:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003cf40:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003cf50:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..0003ce10:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
0003cf60:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003ce20:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003cf70:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003ce30:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003cf80:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003ce40:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003cf90:·3d22·6964·6d36·3832·3422·3e3c·7072·653e··="idm6824"><pre>0003ce50:·6964·3d22·6964·6d36·3832·3322·3e3c·7072··id="idm6823"><pr
0003cfa0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat0003ce60:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
0003cfb0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl0003ce70:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
0003cfc0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai0003ce80:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
0003cfd0:·6e20·706c·6174·666f·726d·730a·6966·2028··n·platforms.if·(0003ce90:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
0003cfe0:·2021·2028·205b·2022·247b·636f·6e74·6169···!·(·[·"${contai0003cea0:·2028·2021·2028·205b·2022·247b·636f·6e74···(·!·(·[·"${cont
0003cff0:·6e65·723a·2d7d·2220·3d3d·2022·6277·7261··ner:-}"·==·"bwra0003ceb0:·6169·6e65·723a·2d7d·2220·3d3d·2022·6277··ainer:-}"·==·"bw
0003d000:·702d·6f73·6275·696c·6422·205d·2029·2026··p-osbuild"·]·)·&0003cec0:·7261·702d·6f73·6275·696c·6422·205d·2029··rap-osbuild"·]·)
0003d010:·616d·703b·2661·6d70·3b20·7270·6d20·2d2d··amp;&amp;·rpm·--0003ced0:·2026·616d·703b·2661·6d70·3b20·7270·6d20···&amp;&amp;·rpm·
0003d020:·7175·6965·7420·2d71·206b·6572·6e65·6c20··quiet·-q·kernel·0003cee0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
0003d030:·7c7c·2072·706d·202d·2d71·7569·6574·202d··||·rpm·--quiet·-0003cef0:·6c20·7c7c·2072·706d·202d·2d71·7569·6574··l·||·rpm·--quiet
0003d040:·7120·6b65·726e·656c·2d75·656b·2029·3b20··q·kernel-uek·);·0003cf00:·202d·7120·6b65·726e·656c·2d75·656b·2029···-q·kernel-uek·)
0003d050:·7468·656e·0a0a·6966·205b·5b20·2224·4f53··then..if·[[·"$OS0003cf10:·3b20·7468·656e·0a0a·6966·205b·5b20·2224··;·then..if·[[·"$
0003d060:·4341·505f·424f·4f54·435f·4255·494c·4422··CAP_BOOTC_BUILD"0003cf20:·4f53·4341·505f·424f·4f54·435f·4255·494c··OSCAP_BOOTC_BUIL
0003d070:·203d·3d20·2259·4553·2220·5d5d·3b20·7468···==·"YES"·]];·th0003cf30:·4422·203d·3d20·2259·4553·2220·5d5d·3b20··D"·==·"YES"·]];·
0003d080:·656e·0a09·6361·7420·2667·743b·202f·7573··en..cat·&gt;·/us0003cf40:·7468·656e·0a09·6361·7420·2667·743b·202f··then..cat·&gt;·/
0003d090:·722f·6c69·622f·626f·6f74·632f·6b61·7267··r/lib/bootc/karg0003cf50:·7573·722f·6c69·622f·626f·6f74·632f·6b61··usr/lib/bootc/ka
0003d0a0:·732e·642f·3031·2d66·6970·732e·746f·6d6c··s.d/01-fips.toml0003cf60:·7267·732e·642f·3031·2d66·6970·732e·746f··rgs.d/01-fips.to
0003d0b0:·2026·6c74·3b26·6c74·3b20·454f·460a·6b61···&lt;&lt;·EOF.ka0003cf70:·6d6c·2026·6c74·3b26·6c74·3b20·454f·460a··ml·&lt;&lt;·EOF.
0003d0c0:·7267·7320·3d20·5b22·6669·7073·3d31·225d··rgs·=·["fips=1"]0003cf80:·6b61·7267·7320·3d20·5b22·6669·7073·3d31··kargs·=·["fips=1
0003d0d0:·0a45·4f46·0a66·690a·0a65·6c73·650a·2020··.EOF.fi..else.··0003cf90:·225d·0a45·4f46·0a66·690a·0a65·6c73·650a··"].EOF.fi..else.
0003d0e0:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech0003cfa0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
0003d0f0:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i0003cfb0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
0003d100:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable0003cfc0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
0003d110:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do0003cfd0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
0003d120:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></0003cfe0:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
 0003cff0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003d000:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003d010:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003d020:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 0003d030:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6
 0003d040:·3832·3422·2074·6162·696e·6465·783d·2230··824"·tabindex="0
 0003d050:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 0003d060:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 0003d070:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 0003d080:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 0003d090:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003d0a0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B
 0003d0b0:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet
 0003d0c0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003d0d0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003d0e0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003d0f0:·2069·643d·2269·646d·3638·3234·223e·3c70···id="idm6824"><p
 0003d100:·7265·3e3c·636f·6465·3e0a·5b63·7573·746f··re><code>.[custo
 0003d110:·6d69·7a61·7469·6f6e·735d·0a66·6970·7320··mizations].fips·
 0003d120:·3d20·7472·7565·0a3c·2f63·6f64·653e·3c2f··=·true.</code></
0003d130:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>0003d130:·7072·653e·3c2f·6469·763e·3c2f·6469·763e··pre></div></div>
0003d140:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod0003d140:·3c2f·7464·3e3c·2f74·723e·3c2f·7462·6f64··</td></tr></tbod
0003d150:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><0003d150:·793e·3c2f·7461·626c·653e·3c2f·7464·3e3c··y></table></td><
0003d160:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-0003d160:·2f74·723e·3c74·7220·6461·7461·2d74·742d··/tr><tr·data-tt-
0003d170:·6964·3d22·6368·696c·6472·656e·2d78·6363··id="children-xcc0003d170:·6964·3d22·6368·696c·6472·656e·2d78·6363··id="children-xcc
0003d180:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec0003d180:·6466·5f6f·7267·2e73·7367·7072·6f6a·6563··df_org.ssgprojec
0003d190:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_0003d190:·742e·636f·6e74·656e·745f·6772·6f75·705f··t.content_group_
Offset 15901, 184 lines modifiedOffset 15901, 184 lines modified
0003e1c0:·2d74·6172·6765·743d·2223·6964·6d36·3936··-target="#idm6960003e1c0:·2d74·6172·6765·743d·2223·6964·6d36·3936··-target="#idm696
0003e1d0:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·0003e1d0:·3422·2074·6162·696e·6465·783d·2230·2220··4"·tabindex="0"·
0003e1e0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003e1e0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003e1f0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003e1f0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003e200:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003e200:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003e210:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003e210:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003e220:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003e220:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003e230:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0003e240:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003e250:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003e260:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003e270:·2220·6964·3d22·6964·6d36·3936·3422·3e3c··"·id="idm6964"><
 0003e280:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003e290:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003e2a0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003e2b0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003e2c0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003e230:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003e240:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003e250:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003e260:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003e270:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003e280:·643d·2269·646d·3639·3634·223e·3c70·7265··d="idm6964"><pre 
0003e290:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003e2a0:·6573·5d5d·0a6e·616d·6520·3d20·2263·7279··es]].name·=·"cry 
0003e2b0:·7074·6f2d·706f·6c69·6369·6573·220a·7665··pto-policies".ve 
0003e2c0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003e2d0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003e2e0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003e2f0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003e300:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003e310:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003e320:·646d·3639·3635·2220·7461·6269·6e64·6578··dm6965"·tabindex 
0003e330:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003e340:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003e350:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003e360:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003e370:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003e380:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003e390:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003e3a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003e3b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
Max diff block lines reached; 935844/967776 bytes (96.70%) of diff not shown.
120 KB
html2text {}
    
Offset 223, 31 lines modifiedOffset 223, 31 lines modified
223 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode223 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
224 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877224 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
225 ············_\x8i_\x8s_\x8m······1446225 ············_\x8i_\x8s_\x8m······1446
226 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1226 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
227 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12227 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
228 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1228 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
229 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176229 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
231 [customizations] 
232 fips·=·true 
233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
234 #·Remediation·is·applicable·only·in·certain·platforms231 #·Remediation·is·applicable·only·in·certain·platforms
235 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then232 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
236 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then233 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
237 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF234 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
238 kargs·=·["fips=1"]235 kargs·=·["fips=1"]
239 EOF236 EOF
240 fi237 fi
  
241 else238 else
242 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'239 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
243 fi240 fi
 241 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 242 [customizations]
 243 fips·=·true
244 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules244 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules
245 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:245 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
246 ····*·GnuTLS·library246 ····*·GnuTLS·library
247 ····*·OpenSSL·library247 ····*·OpenSSL·library
248 ····*·NSS·library248 ····*·NSS·library
249 ····*·OpenJDK249 ····*·OpenJDK
250 ····*·Libkrb5250 ····*·Libkrb5
Offset 259, 19 lines modifiedOffset 259, 14 lines modified
259 $·sudo·yum·install·crypto-policies259 $·sudo·yum·install·crypto-policies
260 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.260 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
261 Severity: ··medium261 Severity: ··medium
262 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed262 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
263 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123263 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
264 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1264 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
265 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174265 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
266 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
267 [[packages]] 
268 name·=·"crypto-policies" 
269 version·=·"*" 
270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8266 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
271 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low267 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
272 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low268 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
273 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false269 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
274 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable270 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
275 if·!·rpm·-q·--quiet·"crypto-policies"·;·then271 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 289, 33 lines modifiedOffset 284, 38 lines modified
289 ··tags:284 ··tags:
290 ··-·enable_strategy285 ··-·enable_strategy
291 ··-·low_complexity286 ··-·low_complexity
292 ··-·low_disruption287 ··-·low_disruption
293 ··-·medium_severity288 ··-·medium_severity
294 ··-·no_reboot_needed289 ··-·no_reboot_needed
295 ··-·package_crypto-policies_installed290 ··-·package_crypto-policies_installed
 291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 292 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 293 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 294 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 295 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 296 package·--add=crypto-policies
 297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 298 [[packages]]
 299 name·=·"crypto-policies"
 300 version·=·"*"
296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8301 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low302 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low303 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false304 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable305 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
301 include·install_crypto-policies306 include·install_crypto-policies
  
302 class·install_crypto-policies·{307 class·install_crypto-policies·{
303 ··package·{·'crypto-policies':308 ··package·{·'crypto-policies':
304 ····ensure·=>·'installed',309 ····ensure·=>·'installed',
305 ··}310 ··}
306 }311 }
307 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
308 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
309 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
310 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
311 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
312 package·--add=crypto-policies 
313 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*312 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
314 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:313 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
315 $·sudo·update-crypto-policies·--set·FIPS:OSPP314 $·sudo·update-crypto-policies·--set·FIPS:OSPP
316 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.315 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
317 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.316 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
318 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.317 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
319 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.318 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 632, 19 lines modifiedOffset 632, 14 lines modified
632 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235632 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
633 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386633 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
634 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)634 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
635 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1635 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
636 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125636 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
637 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33637 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
638 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2638 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
640 [[packages]] 
641 name·=·"sudo" 
642 version·=·"*" 
643 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
644 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low640 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
645 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low641 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
646 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false642 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
647 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable643 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
648 #·Remediation·is·applicable·only·in·certain·platforms644 #·Remediation·is·applicable·only·in·certain·platforms
649 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then645 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 686, 49 lines modifiedOffset 681, 49 lines modified
686 ··-·PCI-DSSv4-2.2.6681 ··-·PCI-DSSv4-2.2.6
687 ··-·enable_strategy682 ··-·enable_strategy
688 ··-·low_complexity683 ··-·low_complexity
689 ··-·low_disruption684 ··-·low_disruption
690 ··-·medium_severity685 ··-·medium_severity
Max diff block lines reached; 114523/122433 bytes (93.54%) of diff not shown.
595 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-e8.html
    
Offset 19334, 284 lines modifiedOffset 19334, 284 lines modified
0004b850:·6765·743d·2223·6964·6d39·3433·3722·2074··get="#idm9437"·t0004b850:·6765·743d·2223·6964·6d39·3433·3722·2074··get="#idm9437"·t
0004b860:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0004b860:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0004b870:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0004b870:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0004b880:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0004b880:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0004b890:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0004b890:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0004b8a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0004b8a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0004b8b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0004b8b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0004b8c0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0004b8d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0004b8e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0004b8f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0004b900:·3d22·6964·6d39·3433·3722·3e3c·7461·626c··="idm9437"><tabl
 0004b910:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0004b920:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0004b930:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0004b940:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0004b950:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0004b960:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0004b970:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0004b980:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0004b990:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0004b9a0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0004b9b0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0004b9c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0004b9d0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
0004b8c0:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0004b8d0:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0004b8e0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0004b8f0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0004b900:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0004b910:·646d·3934·3337·223e·3c70·7265·3e3c·636f··dm9437"><pre><co 
0004b920:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0004b930:·0a6e·616d·6520·3d20·2272·6561·7222·0a76··.name·=·"rear".v 
0004b940:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0004b950:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0004b960:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0004b970:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0004b980:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0004b990:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0004b9a0:·6964·6d39·3433·3822·2074·6162·696e·6465··idm9438"·tabinde 
0004b9b0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0004b9c0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0004b9d0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0004b9e0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0004b9f0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0004ba00:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0004ba10:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a>< 
0004ba20:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0004ba30:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0004ba40:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9 
0004ba50:·3433·3822·3e3c·7461·626c·6520·636c·6173··438"><table·clas 
0004ba60:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0004ba70:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0004ba80:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0004ba90:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0004baa0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0004bab0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0004bac0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0004bad0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0004bae0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0004baf0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0004bb00:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0004b9e0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0004b9f0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0004ba00:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0004ba10:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0004ba20:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0004ba30:·6c61·7466·6f72·6d73·0a69·6620·2120·2820··latforms.if·!·(·
0004bb10:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0004bb20:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0004bb30:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0004bb40:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0004bb50:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0004bb60:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0004bb70:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0004bb80:·6d73·0a69·6620·2120·2820·2820·2820·2820··ms.if·!·(·(·(·(· 
0004bb90:·6772·6570·202d·7371·4520·225e·2e2a·5c2e··grep·-sqE·"^.*\. 
0004bba0:·6161·7263·6836·3424·2220·2f70·726f·632f··aarch64$"·/proc/ 
0004bbb0:·7379·732f·6b65·726e·656c·2f6f·7372·656c··sys/kernel/osrel 
0004bbc0:·6561·7365·207c·7c20·6772·6570·202d·7371··ease·||·grep·-sq 
0004bbd0:·4520·225e·6161·7263·6836·3424·2220·2f70··E·"^aarch64$"·/p 
0004bbe0:·726f·632f·7379·732f·6b65·726e·656c·2f61··roc/sys/kernel/a 
0004bbf0:·7263·683b·2029·2026·616d·703b·2661·6d70··rch;·)·&amp;&amp 
0004bc00:·3b20·6772·6570·202d·7150·2022·5e49·443d··;·grep·-qP·"^ID= 
0004bc10:·5b5c·2227·5d3f·6f6c·5b5c·2227·5d3f·2422··[\"']?ol[\"']?$" 
0004bc20:·2022·2f65·7463·2f6f·732d·7265·6c65·6173···"/etc/os-releas 
0004bc30:·6522·2026·616d·703b·2661·6d70·3b20·7b20··e"·&amp;&amp;·{· 
0004bc40:·7265·616c·3d22·2428·6772·6570·202d·5020··real="$(grep·-P· 
0004bc50:·225e·5645·5253·494f·4e5f·4944·3d5b·5c22··"^VERSION_ID=[\" 
0004bc60:·275d·3f5b·5c77·2e5d·2b5b·5c22·275d·3f24··']?[\w.]+[\"']?$ 
0004bc70:·2220·2f65·7463·2f6f·732d·7265·6c65·6173··"·/etc/os-releas 
0004bc80:·6520·7c20·7365·6420·2273·2f5e·5645·5253··e·|·sed·"s/^VERS 
0004bc90:·494f·4e5f·4944·3d5b·5c22·275d·5c3f·5c28··ION_ID=[\"']\?\( 
0004bca0:·5b5e·5c22·275d·5c2b·5c29·5b5c·2227·5d5c··[^\"']\+\)[\"']\ 
0004bcb0:·3f24·2f5c·312f·2229·223b·2065·7870·6563··?$/\1/")";·expec 
0004bcc0:·7465·643d·2239·2e30·223b·2070·7269·6e74··ted="9.0";·print 
0004bcd0:·6620·2225·735c·6e25·7322·2022·2465·7870··f·"%s\n%s"·"$exp 
0004bce0:·6563·7465·6422·2022·2472·6561·6c22·207c··ected"·"$real"·| 
0004bcf0:·2073·6f72·7420·2d56·433b·207d·2029·207c···sort·-VC;·}·)·| 
0004bd00:·7c20·2820·2820·6772·6570·202d·7371·4520··|·(·(·grep·-sqE·0004ba40:·2820·2820·2820·6772·6570·202d·7371·4520··(·(·(·grep·-sqE·
0004bd10:·225e·2e2a·5c2e·6161·7263·6836·3424·2220··"^.*\.aarch64$"·0004ba50:·225e·2e2a·5c2e·6161·7263·6836·3424·2220··"^.*\.aarch64$"·
0004bd20:·2f70·726f·632f·7379·732f·6b65·726e·656c··/proc/sys/kernel0004ba60:·2f70·726f·632f·7379·732f·6b65·726e·656c··/proc/sys/kernel
0004bd30:·2f6f·7372·656c·6561·7365·207c·7c20·6772··/osrelease·||·gr0004ba70:·2f6f·7372·656c·6561·7365·207c·7c20·6772··/osrelease·||·gr
0004bd40:·6570·202d·7371·4520·225e·6161·7263·6836··ep·-sqE·"^aarch60004ba80:·6570·202d·7371·4520·225e·6161·7263·6836··ep·-sqE·"^aarch6
0004bd50:·3424·2220·2f70·726f·632f·7379·732f·6b65··4$"·/proc/sys/ke0004ba90:·3424·2220·2f70·726f·632f·7379·732f·6b65··4$"·/proc/sys/ke
0004bd60:·726e·656c·2f61·7263·683b·2029·2026·616d··rnel/arch;·)·&am0004baa0:·726e·656c·2f61·7263·683b·2029·2026·616d··rnel/arch;·)·&am
0004bd70:·703b·2661·6d70·3b20·6772·6570·202d·7150··p;&amp;·grep·-qP0004bab0:·703b·2661·6d70·3b20·6772·6570·202d·7150··p;&amp;·grep·-qP
0004bd80:·2022·5e49·443d·5b5c·2227·5d3f·7268·656c···"^ID=[\"']?rhel0004bac0:·2022·5e49·443d·5b5c·2227·5d3f·6f6c·5b5c···"^ID=[\"']?ol[\
0004bd90:·5b5c·2227·5d3f·2422·2022·2f65·7463·2f6f··[\"']?$"·"/etc/o0004bad0:·2227·5d3f·2422·2022·2f65·7463·2f6f·732d··"']?$"·"/etc/os-
0004bda0:·732d·7265·6c65·6173·6522·2026·616d·703b··s-release"·&amp;0004bae0:·7265·6c65·6173·6522·2026·616d·703b·2661··release"·&amp;&a
0004bdb0:·2661·6d70·3b20·7b20·7265·616c·3d22·2428··&amp;·{·real="$(0004baf0:·6d70·3b20·7b20·7265·616c·3d22·2428·6772··mp;·{·real="$(gr
0004bdc0:·6772·6570·202d·5020·225e·5645·5253·494f··grep·-P·"^VERSIO0004bb00:·6570·202d·5020·225e·5645·5253·494f·4e5f··ep·-P·"^VERSION_
0004bdd0:·4e5f·4944·3d5b·5c22·275d·3f5b·5c77·2e5d··N_ID=[\"']?[\w.]0004bb10:·4944·3d5b·5c22·275d·3f5b·5c77·2e5d·2b5b··ID=[\"']?[\w.]+[
0004bde0:·2b5b·5c22·275d·3f24·2220·2f65·7463·2f6f··+[\"']?$"·/etc/o0004bb20:·5c22·275d·3f24·2220·2f65·7463·2f6f·732d··\"']?$"·/etc/os-
0004bdf0:·732d·7265·6c65·6173·6520·7c20·7365·6420··s-release·|·sed·0004bb30:·7265·6c65·6173·6520·7c20·7365·6420·2273··release·|·sed·"s
0004be00:·2273·2f5e·5645·5253·494f·4e5f·4944·3d5b··"s/^VERSION_ID=[0004bb40:·2f5e·5645·5253·494f·4e5f·4944·3d5b·5c22··/^VERSION_ID=[\"
0004be10:·5c22·275d·5c3f·5c28·5b5e·5c22·275d·5c2b··\"']\?\([^\"']\+0004bb50:·275d·5c3f·5c28·5b5e·5c22·275d·5c2b·5c29··']\?\([^\"']\+\)
0004be20:·5c29·5b5c·2227·5d5c·3f24·2f5c·312f·2229··\)[\"']\?$/\1/")0004bb60:·5b5c·2227·5d5c·3f24·2f5c·312f·2229·223b··[\"']\?$/\1/")";
0004be30:·223b·2065·7870·6563·7465·643d·2239·2e30··";·expected="9.00004bb70:·2065·7870·6563·7465·643d·2239·2e30·223b···expected="9.0";
0004be40:·223b·2070·7269·6e74·6620·2225·735c·6e25··";·printf·"%s\n%0004bb80:·2070·7269·6e74·6620·2225·735c·6e25·7322···printf·"%s\n%s"
0004be50:·7322·2022·2465·7870·6563·7465·6422·2022··s"·"$expected"·"0004bb90:·2022·2465·7870·6563·7465·6422·2022·2472···"$expected"·"$r
0004be60:·2472·6561·6c22·207c·2073·6f72·7420·2d56··$real"·|·sort·-V0004bba0:·6561·6c22·207c·2073·6f72·7420·2d56·433b··eal"·|·sort·-VC;
0004be70:·433b·207d·2029·207c·7c20·2820·6772·6570··C;·}·)·||·(·grep0004bbb0:·207d·2029·207c·7c20·2820·2820·6772·6570···}·)·||·(·(·grep
 0004bbc0:·202d·7371·4520·225e·2e2a·5c2e·6161·7263···-sqE·"^.*\.aarc
 0004bbd0:·6836·3424·2220·2f70·726f·632f·7379·732f··h64$"·/proc/sys/
 0004bbe0:·6b65·726e·656c·2f6f·7372·656c·6561·7365··kernel/osrelease
 0004bbf0:·207c·7c20·6772·6570·202d·7371·4520·225e···||·grep·-sqE·"^
 0004bc00:·6161·7263·6836·3424·2220·2f70·726f·632f··aarch64$"·/proc/
Max diff block lines reached; 510262/548102 bytes (93.10%) of diff not shown.
59.3 KB
html2text {}
    
Offset 1086, 19 lines modifiedOffset 1086, 14 lines modified
1086 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.1086 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·following·checks·evaluate·the·system·for·recommended·base·packages·--·both·for·installation·and·removal.
1087 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1087 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1088 The·rear·package·can·be·installed·with·the·following·command:1088 The·rear·package·can·be·installed·with·the·following·command:
1089 $·sudo·yum·install·rear1089 $·sudo·yum·install·rear
1090 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.1090 Rationale:·rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.
1091 Severity: ·medium1091 Severity: ·medium
1092 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed1092 Rule·ID:···xccdf_org.ssgproject.content_rule_package_rear_installed
1093 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1094 [[packages]] 
1095 name·=·"rear" 
1096 version·=·"*" 
1097 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81093 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1098 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1094 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1099 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1095 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1100 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1096 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1101 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1097 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1102 #·Remediation·is·applicable·only·in·certain·platforms1098 #·Remediation·is·applicable·only·in·certain·platforms
1103 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1099 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1127, 33 lines modifiedOffset 1122, 38 lines modified
1127 ··tags:1122 ··tags:
1128 ··-·enable_strategy1123 ··-·enable_strategy
1129 ··-·low_complexity1124 ··-·low_complexity
1130 ··-·low_disruption1125 ··-·low_disruption
1131 ··-·medium_severity1126 ··-·medium_severity
1132 ··-·no_reboot_needed1127 ··-·no_reboot_needed
1133 ··-·package_rear_installed1128 ··-·package_rear_installed
 1129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1134 package·--add=rear
 1135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1136 [[packages]]
 1137 name·=·"rear"
 1138 version·=·"*"
1134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1139 include·install_rear1144 include·install_rear
  
1140 class·install_rear·{1145 class·install_rear·{
1141 ··package·{·'rear':1146 ··package·{·'rear':
1142 ····ensure·=>·'installed',1147 ····ensure·=>·'installed',
1143 ··}1148 ··}
1144 }1149 }
1145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
1147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
1148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
1149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
1150 package·--add=rear 
1151 Group  ·Updating·Software·  Group·contains·6·rules1150 Group  ·Updating·Software·  Group·contains·6·rules
1152 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.1151 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·yum·command·line·tool·is·used·to·install·and·update·software·packages.·The·system·also·provides·a·graphical·software·update·tool·in·the·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·menu,·in·the·A\x8Ad\x8dm\x8mi\x8in\x8ni\x8is\x8st\x8tr\x8ra\x8at\x8ti\x8io\x8on\x8n·submenu,·called·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e.
  
1153 Oracle·Linux·9·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.1152 Oracle·Linux·9·systems·contain·an·installed·software·catalog·called·the·RPM·database,·which·records·metadata·of·installed·packages.·Consistently·using·yum·or·the·graphical·S\x8So\x8of\x8ft\x8tw\x8wa\x8ar\x8re\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8e·for·all·software·installation·allows·for·insight·into·the·current·inventory·of·installed·software·on·the·system.
  
1154 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1153 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·O\x8On\x8nl\x8ly\x8y·S\x8Se\x8ec\x8cu\x8ur\x8ri\x8it\x8ty\x8y·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1155 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.1154 To·configure·dnf-automatic·to·install·only·security·updates·automatically,·set·upgrade_type·to·security·under·[commands]·section·in·/etc/dnf/automatic.conf.
Offset 1801, 14 lines modifiedOffset 1801, 38 lines modified
1801 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"1801 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
1802 fi1802 fi
1803 fi1803 fi
  
1804 else1804 else
1805 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1805 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1806 fi1806 fi
 1807 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1808 ---
 1809 apiVersion:·machineconfiguration.openshift.io/v1
 1810 kind:·MachineConfig
 1811 spec:
 1812 ··config:
 1813 ····ignition:
 1814 ······version:·3.1.0
 1815 ····storage:
 1816 ······files:
 1817 ······-·contents:
 1818 ··········source:
 1819 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1820 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1821 ········mode:·0644
 1822 ········path:·/etc/pam.d/password-auth
 1823 ········overwrite:·true
 1824 ······-·contents:
 1825 ··········source:
 1826 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1827 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1828 ········mode:·0644
 1829 ········path:·/etc/pam.d/system-auth
 1830 ········overwrite:·true
1807 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81831 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1808 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1832 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1809 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1833 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1810 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1834 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1811 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure1835 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
1812 -·name:·Gather·the·package·facts1836 -·name:·Gather·the·package·facts
1813 ··package_facts:1837 ··package_facts:
Offset 1947, 38 lines modifiedOffset 1971, 14 lines modified
1947 ··-·PCI-DSSv4-8.3.11971 ··-·PCI-DSSv4-8.3.1
1948 ··-·configure_strategy1972 ··-·configure_strategy
1949 ··-·high_severity1973 ··-·high_severity
1950 ··-·low_complexity1974 ··-·low_complexity
1951 ··-·medium_disruption1975 ··-·medium_disruption
1952 ··-·no_empty_passwords1976 ··-·no_empty_passwords
1953 ··-·no_reboot_needed1977 ··-·no_reboot_needed
1954 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1955 --- 
1956 apiVersion:·machineconfiguration.openshift.io/v1 
1957 kind:·MachineConfig 
1958 spec: 
1959 ··config: 
1960 ····ignition: 
1961 ······version:·3.1.0 
1962 ····storage: 
1963 ······files: 
1964 ······-·contents: 
1965 ··········source: 
1966 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1967 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1968 ········mode:·0644 
Max diff block lines reached; 38276/60715 bytes (63.04%) of diff not shown.
511 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-hipaa.html
    
Offset 21630, 302 lines modifiedOffset 21630, 302 lines modified
000547d0:·743d·2223·6964·6d31·3238·3630·2220·7461··t="#idm12860"·ta000547d0:·743d·2223·6964·6d31·3238·3630·2220·7461··t="#idm12860"·ta
000547e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=000547e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
000547f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex000547f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00054800:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00054800:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00054810:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00054810:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00054820:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00054820:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00054830:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00054830:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00054840:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 00054850:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00054860:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00054870:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00054880:·2269·646d·3132·3836·3022·3e3c·7461·626c··"idm12860"><tabl
 00054890:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 000548a0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 000548b0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 000548c0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 000548d0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 000548e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 000548f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00054900:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00054910:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00054920:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 00054930:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 00054940:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00054950:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00054960:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr
 00054970:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00054980:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 00054990:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 000549a0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 000549b0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 000549c0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 000549d0:·656c·207c·7c20·7270·6d20·2d2d·7175·6965··el·||·rpm·--quie
 000549e0:·7420·2d71·206b·6572·6e65·6c2d·7565·6b3b··t·-q·kernel-uek;
 000549f0:·2074·6865·6e0a·0a53·5953·5445·4d43·544c···then..SYSTEMCTL
 00054a00:·5f45·5845·433d·272f·7573·722f·6269·6e2f··_EXEC='/usr/bin/
 00054a10:·7379·7374·656d·6374·6c27·0a69·6620·5b5b··systemctl'.if·[[
 00054a20:·2024·2822·2453·5953·5445·4d43·544c·5f45···$("$SYSTEMCTL_E
 00054a30:·5845·4322·2069·732d·7379·7374·656d·2d72··XEC"·is-system-r
 00054a40:·756e·6e69·6e67·2920·213d·2022·6f66·666c··unning)·!=·"offl
 00054a50:·696e·6522·205d·5d3b·2074·6865·6e0a·2020··ine"·]];·then.··
 00054a60:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC
 00054a70:·2220·7374·6f70·2027·6465·6275·672d·7368··"·stop·'debug-sh
 00054a80:·656c·6c2e·7365·7276·6963·6527·0a66·690a··ell.service'.fi.
 00054a90:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC
 00054aa0:·2220·6469·7361·626c·6520·2764·6562·7567··"·disable·'debug
 00054ab0:·2d73·6865·6c6c·2e73·6572·7669·6365·270a··-shell.service'.
00054840:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
00054850:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
00054860:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00054870:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00054880:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00054890:·6d31·3238·3630·223e·3c70·7265·3e3c·636f··m12860"><pre><co 
000548a0:·6465·3e0a·5b63·7573·746f·6d69·7a61·7469··de>.[customizati 
000548b0:·6f6e·732e·7365·7276·6963·6573·5d0a·6d61··ons.services].ma 
000548c0:·736b·6564·203d·205b·2264·6562·7567·2d73··sked·=·["debug-s 
000548d0:·6865·6c6c·225d·0a3c·2f63·6f64·653e·3c2f··hell"].</code></ 
000548e0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
000548f0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00054900:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00054910:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00054920:·2d74·6172·6765·743d·2223·6964·6d31·3238··-target="#idm128 
00054930:·3631·2220·7461·6269·6e64·6578·3d22·3022··61"·tabindex="0" 
00054940:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
00054950:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
00054960:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
00054970:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
00054980:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
00054990:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
000549a0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d 
000549b0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
000549c0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
000549d0:·6522·2069·643d·2269·646d·3132·3836·3122··e"·id="idm12861" 
000549e0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
000549f0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00054a00:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00054a10:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00054a20:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00054a30:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00054a40:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00054a50:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00054a60:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00054a70:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00054a80:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
00054a90:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
00054aa0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00054ab0:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t 
00054ac0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
00054ad0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
00054ae0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
00054af0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
00054b00:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
00054b10:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
00054b20:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm· 
00054b30:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
00054b40:·6c2d·7565·6b3b·2074·6865·6e0a·0a53·5953··l-uek;·then..SYS 
00054b50:·5445·4d43·544c·5f45·5845·433d·272f·7573··TEMCTL_EXEC='/us 
00054b60:·722f·6269·6e2f·7379·7374·656d·6374·6c27··r/bin/systemctl' 
00054b70:·0a69·6620·5b5b·2024·2822·2453·5953·5445··.if·[[·$("$SYSTE 
00054b80:·4d43·544c·5f45·5845·4322·2069·732d·7379··MCTL_EXEC"·is-sy 
00054b90:·7374·656d·2d72·756e·6e69·6e67·2920·213d··stem-running)·!= 
00054ba0:·2022·6f66·666c·696e·6522·205d·5d3b·2074···"offline"·]];·t 
00054bb0:·6865·6e0a·2020·2224·5359·5354·454d·4354··hen.··"$SYSTEMCT 
00054bc0:·4c5f·4558·4543·2220·7374·6f70·2027·6465··L_EXEC"·stop·'de 
00054bd0:·6275·672d·7368·656c·6c2e·7365·7276·6963··bug-shell.servic 
00054be0:·6527·0a66·690a·2224·5359·5354·454d·4354··e'.fi."$SYSTEMCT 
00054bf0:·4c5f·4558·4543·2220·6469·7361·626c·6520··L_EXEC"·disable· 
00054c00:·2764·6562·7567·2d73·6865·6c6c·2e73·6572··'debug-shell.ser 
00054c10:·7669·6365·270a·2224·5359·5354·454d·4354··vice'."$SYSTEMCT 
00054c20:·4c5f·4558·4543·2220·6d61·736b·2027·6465··L_EXEC"·mask·'de 
00054c30:·6275·672d·7368·656c·6c2e·7365·7276·6963··bug-shell.servic 
00054c40:·6527·0a23·2044·6973·6162·6c65·2073·6f63··e'.#·Disable·soc 
00054c50:·6b65·7420·6163·7469·7661·7469·6f6e·2069··ket·activation·i 
00054c60:·6620·7765·2068·6176·6520·6120·756e·6974··f·we·have·a·unit 
00054c70:·2066·696c·6520·666f·7220·6974·0a69·6620···file·for·it.if· 
00054c80:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC00054ac0:·2224·5359·5354·454d·4354·4c5f·4558·4543··"$SYSTEMCTL_EXEC
00054c90:·2220·2d71·206c·6973·742d·756e·6974·2d66··"·-q·list-unit-f 
00054ca0:·696c·6573·2064·6562·7567·2d73·6865·6c6c··iles·debug-shell 
00054cb0:·2e73·6f63·6b65·743b·2074·6865·6e0a·2020··.socket;·then.·· 
00054cc0:·2020·6966·205b·5b20·2428·2224·5359·5354····if·[[·$("$SYST 
00054cd0:·454d·4354·4c5f·4558·4543·2220·6973·2d73··EMCTL_EXEC"·is-s 
00054ce0:·7973·7465·6d2d·7275·6e6e·696e·6729·2021··ystem-running)·! 
00054cf0:·3d20·226f·6666·6c69·6e65·2220·5d5d·3b20··=·"offline"·]];· 
00054d00:·7468·656e·0a20·2020·2020·2022·2453·5953··then.······"$SYS 
00054d10:·5445·4d43·544c·5f45·5845·4322·2073·746f··TEMCTL_EXEC"·sto 
00054d20:·7020·2764·6562·7567·2d73·6865·6c6c·2e73··p·'debug-shell.s 
00054d30:·6f63·6b65·7427·0a20·2020·2066·690a·2020··ocket'.····fi.·· 
Max diff block lines reached; 431194/471518 bytes (91.45%) of diff not shown.
50.3 KB
html2text {}
    
Offset 1529, 18 lines modifiedOffset 1529, 14 lines modified
1529 Rule·ID:····xccdf_org.ssgproject.content_rule_service_debug-shell_disabled1529 Rule·ID:····xccdf_org.ssgproject.content_rule_service_debug-shell_disabled
1530 ············_\x8c_\x8u_\x8i····3.4.51530 ············_\x8c_\x8u_\x8i····3.4.5
1531 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-0022351531 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
1532 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1532 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1533 ············_\x8n_\x8i_\x8s_\x8t···CM-61533 ············_\x8n_\x8i_\x8s_\x8t···CM-6
1534 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.11534 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
1535 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271535 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1536 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1537 [customizations.services] 
1538 masked·=·["debug-shell"] 
1539 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81536 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1540 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1537 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1541 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1538 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1542 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1539 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1543 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1540 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1544 #·Remediation·is·applicable·only·in·certain·platforms1541 #·Remediation·is·applicable·only·in·certain·platforms
1545 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1542 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1652, 14 lines modifiedOffset 1648, 18 lines modified
1652 ··-·NIST-800-53-CM-61648 ··-·NIST-800-53-CM-6
1653 ··-·disable_strategy1649 ··-·disable_strategy
1654 ··-·low_complexity1650 ··-·low_complexity
1655 ··-·low_disruption1651 ··-·low_disruption
1656 ··-·medium_severity1652 ··-·medium_severity
1657 ··-·no_reboot_needed1653 ··-·no_reboot_needed
1658 ··-·service_debug-shell_disabled1654 ··-·service_debug-shell_disabled
 1655 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1656 [customizations.services]
 1657 masked·=·["debug-shell"]
1659 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81658 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1660 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1659 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1661 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1660 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1662 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1661 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1663 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1662 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1664 include·disable_debug-shell1663 include·disable_debug-shell
  
Offset 2152, 14 lines modifiedOffset 2152, 38 lines modified
2152 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"2152 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
2153 fi2153 fi
2154 fi2154 fi
  
2155 else2155 else
2156 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2156 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2157 fi2157 fi
 2158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2159 ---
 2160 apiVersion:·machineconfiguration.openshift.io/v1
 2161 kind:·MachineConfig
 2162 spec:
 2163 ··config:
 2164 ····ignition:
 2165 ······version:·3.1.0
 2166 ····storage:
 2167 ······files:
 2168 ······-·contents:
 2169 ··········source:
 2170 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 2171 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 2172 ········mode:·0644
 2173 ········path:·/etc/pam.d/password-auth
 2174 ········overwrite:·true
 2175 ······-·contents:
 2176 ··········source:
 2177 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 2178 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 2179 ········mode:·0644
 2180 ········path:·/etc/pam.d/system-auth
 2181 ········overwrite:·true
2158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure2186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
2163 -·name:·Gather·the·package·facts2187 -·name:·Gather·the·package·facts
2164 ··package_facts:2188 ··package_facts:
Offset 2298, 38 lines modifiedOffset 2322, 14 lines modified
2298 ··-·PCI-DSSv4-8.3.12322 ··-·PCI-DSSv4-8.3.1
2299 ··-·configure_strategy2323 ··-·configure_strategy
2300 ··-·high_severity2324 ··-·high_severity
2301 ··-·low_complexity2325 ··-·low_complexity
2302 ··-·medium_disruption2326 ··-·medium_disruption
2303 ··-·no_empty_passwords2327 ··-·no_empty_passwords
2304 ··-·no_reboot_needed2328 ··-·no_reboot_needed
2305 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2306 --- 
2307 apiVersion:·machineconfiguration.openshift.io/v1 
2308 kind:·MachineConfig 
2309 spec: 
2310 ··config: 
2311 ····ignition: 
2312 ······version:·3.1.0 
2313 ····storage: 
2314 ······files: 
2315 ······-·contents: 
2316 ··········source: 
2317 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
2318 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
2319 ········mode:·0644 
2320 ········path:·/etc/pam.d/password-auth 
2321 ········overwrite:·true 
2322 ······-·contents: 
2323 ··········source: 
2324 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
2325 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
2326 ········mode:·0644 
2327 ········path:·/etc/pam.d/system-auth 
2328 ········overwrite:·true 
2329 Group  ·Restrict·Root·Logins·  Group·contains·3·rules2329 Group  ·Restrict·Root·Logins·  Group·contains·3·rules
2330 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.2330 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Direct·root·logins·should·be·allowed·only·for·emergency·use.·In·normal·situations,·the·administrator·should·access·the·system·via·a·unique·unprivileged·account,·and·then·use·su·or·sudo·to·execute·privileged·commands.·Discouraging·administrators·from·accessing·the·root·account·directly·ensures·an·audit·trail·in·organizations·with·multiple·administrators.·Locking·down·the·channels·through·which·root·can·connect·directly·also·reduces·opportunities·for·password-guessing·against·the·root·account.·The·login·program·uses·the·file·/etc/securetty·to·determine·which·interfaces·should·allow·root·logins.·The·virtual·devices·/dev/console·and·/dev/tty*·represent·the·system·consoles·(accessible·via·the·Ctrl-Alt-F1·through·Ctrl-Alt-F6·keyboard·sequences·on·a·default·installation).·The·default·securetty·file·also·contains·/dev/vc/*.·These·are·likely·to·be·deprecated·in·most·environments,·but·may·be·retained·for·compatibility.·Root·should·also·be·prohibited·from·connecting·via·network·protocols.·Other·sections·of·this·document·include·guidance·describing·how·to·prevent·root·from·logging·in·via·SSH.
2331 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8ir\x8re\x8ec\x8ct\x8t·r\x8ro\x8oo\x8ot\x8t·L\x8Lo\x8og\x8gi\x8in\x8ns\x8s·N\x8No\x8ot\x8t·A\x8Al\x8ll\x8lo\x8ow\x8we\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2331 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·D\x8Di\x8ir\x8re\x8ec\x8ct\x8t·r\x8ro\x8oo\x8ot\x8t·L\x8Lo\x8og\x8gi\x8in\x8ns\x8s·N\x8No\x8ot\x8t·A\x8Al\x8ll\x8lo\x8ow\x8we\x8ed\x8d·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2332 To·further·limit·access·to·the·root·account,·administrators·can·disable·root·logins·at·the·console·by·editing·the·/etc/securetty·file.·This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does·not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the·system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous·as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in·plain·text·over·the·network.·By·default,·Oracle·Linux·9's·/etc/securetty·file·only·allows·the·root·user·to·login·at·the·console·physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the·contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this·file·by·typing·the·following·command:2332 To·further·limit·access·to·the·root·account,·administrators·can·disable·root·logins·at·the·console·by·editing·the·/etc/securetty·file.·This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does·not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the·system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous·as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in·plain·text·over·the·network.·By·default,·Oracle·Linux·9's·/etc/securetty·file·only·allows·the·root·user·to·login·at·the·console·physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the·contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this·file·by·typing·the·following·command:
2333 $·sudo·echo·>·/etc/securetty2333 $·sudo·echo·>·/etc/securetty
2334 Warning: ·This·rule·only·checks·the·/etc/securetty·file·existence·and·its·content.·If·you·need·to·restrict·user·access·using·the·/etc/securetty·file,·make·sure·the·pam_securetty.so·PAM·module·is·properly·enabled·in·relevant·PAM·files.2334 Warning: ·This·rule·only·checks·the·/etc/securetty·file·existence·and·its·content.·If·you·need·to·restrict·user·access·using·the·/etc/securetty·file,·make·sure·the·pam_securetty.so·PAM·module·is·properly·enabled·in·relevant·PAM·files.
2335 Rationale:··Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor·authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate·to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low·and·FISMA·Moderate·systems.2335 Rationale:··Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor·authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate·to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low·and·FISMA·Moderate·systems.
Offset 3059, 18 lines modifiedOffset 3059, 14 lines modified
3059 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)3059 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
3060 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.43060 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
3061 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.63061 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
3062 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.33062 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
3063 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-73063 ············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
3064 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-73064 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
3065 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002273065 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
3066 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3067 [customizations.services] 
3068 masked·=·["autofs"] 
Max diff block lines reached; 27928/51502 bytes (54.23%) of diff not shown.
992 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ism_o.html
    
Offset 17314, 217 lines modifiedOffset 17314, 217 lines modified
00043a10:·7461·7267·6574·3d22·2369·646d·3632·3739··target="#idm627900043a10:·7461·7267·6574·3d22·2369·646d·3632·3739··target="#idm6279
00043a20:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00043a20:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00043a30:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00043a30:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00043a40:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00043a40:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00043a50:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00043a50:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00043a60:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00043a60:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00043a70:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00043a70:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
00043a80:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
00043a90:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
00043aa0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00043ab0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla00043a80:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 00043a90:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 00043aa0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 00043ab0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 00043ac0:·2069·643d·2269·646d·3632·3739·223e·3c74···id="idm6279"><t
 00043ad0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 00043ae0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 00043af0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 00043b00:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 00043b10:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 00043b20:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 00043b30:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00043b40:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 00043b50:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00043b60:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00043b70:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 00043b80:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00043b90:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 00043ba0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 00043bb0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00043bc0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 00043bd0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 00043be0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 00043bf0:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 00043c00:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 00043c10:·726e·656c·207c·7c20·7270·6d20·2d2d·7175··rnel·||·rpm·--qu
 00043c20:·6965·7420·2d71·206b·6572·6e65·6c2d·7565··iet·-q·kernel-ue
 00043c30:·6b3b·2074·6865·6e0a·0a69·6620·2120·7270··k;·then..if·!·rp
 00043c40:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai
 00043c50:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y
 00043c60:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a
 00043c70:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.··
 00043c80:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 00043c90:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 00043ca0:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 00043cb0:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 00043cc0:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
 00043cd0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
 00043ce0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
 00043cf0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
00043ac0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id00043d00:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
00043ad0:·3d22·6964·6d36·3237·3922·3e3c·7072·653e··="idm6279"><pre> 
00043ae0:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
00043af0:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
00043b00:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*".00043d10:·2d74·6172·6765·743d·2223·6964·6d36·3238··-target="#idm628
 00043d20:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·
 00043d30:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 00043d40:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 00043d50:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 00043d60:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 00043d70:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 00043d80:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
 00043d90:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 00043da0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00043db0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00043dc0:·7073·6522·2069·643d·2269·646d·3632·3830··pse"·id="idm6280
 00043dd0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00043de0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 00043df0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00043e00:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00043e10:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00043e20:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00043e30:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00043e40:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00043e50:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00043e60:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00043e70:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00043e80:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00043e90:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00043ea0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00043eb0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00043ec0:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
 00043ed0:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac
 00043ee0:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac
 00043ef0:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.····
 00043f00:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.··
 00043f10:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
 00043f20:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST
 00043f30:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a).
 00043f40:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
 00043f50:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS
 00043f60:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en
 00043f70:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.··
 00043f80:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity
 00043f90:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt
 00043fa0:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s
 00043fb0:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r
 00043fc0:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··-
 00043fd0:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in
 00043fe0:·7374·616c·6c65·640a·0a2d·206e·616d·653a··stalled..-·name:
 00043ff0:·2045·6e73·7572·6520·6169·6465·2069·7320···Ensure·aide·is·
 00044000:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack
 00044010:·6167·653a·0a20·2020·206e·616d·653a·2061··age:.····name:·a
 00044020:·6964·650a·2020·2020·7374·6174·653a·2070··ide.····state:·p
 00044030:·7265·7365·6e74·0a20·2077·6865·6e3a·2028··resent.··when:·(
 00044040:·226b·6572·6e65·6c22·2069·6e20·616e·7369··"kernel"·in·ansi
 00044050:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
 00044060:·6573·206f·7220·226b·6572·6e65·6c2d·7565··es·or·"kernel-ue
 00044070:·6b22·2069·6e20·616e·7369·626c·655f·6661··k"·in·ansible_fa
 00044080:·6374·732e·7061·636b·6167·6573·290a·2020··cts.packages).··
 00044090:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
 000440a0:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST
 000440b0:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a).
 000440c0:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
 000440d0:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS
 000440e0:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en
 000440f0:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.··
 00044100:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity
 00044110:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt
 00044120:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s
 00044130:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r
 00044140:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··-
 00044150:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in
 00044160:·7374·616c·6c65·640a·3c2f·636f·6465·3e3c··stalled.</code><
 00044170:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
 00044180:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
 00044190:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
Max diff block lines reached; 888683/917277 bytes (96.88%) of diff not shown.
96.3 KB
html2text {}
    
Offset 680, 19 lines modifiedOffset 680, 14 lines modified
680 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3680 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
681 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)681 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
682 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3682 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
683 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5683 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
684 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199684 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
685 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79685 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
686 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2686 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
687 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
688 [[packages]] 
689 name·=·"aide" 
690 version·=·"*" 
691 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8687 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
692 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low688 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
693 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low689 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
694 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false690 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
695 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable691 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
696 #·Remediation·is·applicable·only·in·certain·platforms692 #·Remediation·is·applicable·only·in·certain·platforms
697 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then693 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 736, 33 lines modifiedOffset 731, 38 lines modified
736 ··-·PCI-DSSv4-11.5.2731 ··-·PCI-DSSv4-11.5.2
737 ··-·enable_strategy732 ··-·enable_strategy
738 ··-·low_complexity733 ··-·low_complexity
739 ··-·low_disruption734 ··-·low_disruption
740 ··-·medium_severity735 ··-·medium_severity
741 ··-·no_reboot_needed736 ··-·no_reboot_needed
742 ··-·package_aide_installed737 ··-·package_aide_installed
 738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 739 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 740 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 741 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 742 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 743 package·--add=aide
 744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 745 [[packages]]
 746 name·=·"aide"
 747 version·=·"*"
743 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8748 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
744 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low749 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
745 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low750 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
746 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false751 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
747 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable752 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
748 include·install_aide753 include·install_aide
  
749 class·install_aide·{754 class·install_aide·{
750 ··package·{·'aide':755 ··package·{·'aide':
751 ····ensure·=>·'installed',756 ····ensure·=>·'installed',
752 ··}757 ··}
753 }758 }
754 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
755 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
756 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
757 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
758 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
759 package·--add=aide 
760 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·3·rules759 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·3·rules
761 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.760 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
762 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·9.761 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Oracle·Linux·9.
  
763 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.762 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
764 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*763 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 902, 31 lines modifiedOffset 902, 31 lines modified
902 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode902 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
903 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877903 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
904 ············_\x8i_\x8s_\x8m······1446904 ············_\x8i_\x8s_\x8m······1446
905 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1905 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
906 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12906 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
907 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1907 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
908 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176908 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
909 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
910 [customizations] 
911 fips·=·true 
912 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8909 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
913 #·Remediation·is·applicable·only·in·certain·platforms910 #·Remediation·is·applicable·only·in·certain·platforms
914 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then911 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
915 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then912 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
916 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF913 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
917 kargs·=·["fips=1"]914 kargs·=·["fips=1"]
918 EOF915 EOF
919 fi916 fi
  
920 else917 else
921 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'918 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
922 fi919 fi
 920 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 921 [customizations]
 922 fips·=·true
923 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*923 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
924 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:924 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
925 #·cat·/proc/sys/crypto/fips_enabled925 #·cat·/proc/sys/crypto/fips_enabled
926 1926 1
927 Warning: ·To·configure·Oracle·Linux·9·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Oracle·Linux·9·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.927 Warning: ·To·configure·Oracle·Linux·9·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Oracle·Linux·9·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
928 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.928 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
929 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.929 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 1129, 19 lines modifiedOffset 1129, 14 lines modified
1129 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022351129 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
1130 ············_\x8i_\x8s_\x8m·····1382,·1384,·13861130 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1131 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1131 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1132 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11132 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1133 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251133 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1134 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R331134 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1135 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21135 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1137 [[packages]] 
1138 name·=·"sudo" 
1139 version·=·"*" 
1140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1145 #·Remediation·is·applicable·only·in·certain·platforms1141 #·Remediation·is·applicable·only·in·certain·platforms
1146 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1142 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1183, 33 lines modifiedOffset 1178, 38 lines modified
1183 ··-·PCI-DSSv4-2.2.61178 ··-·PCI-DSSv4-2.2.6
1184 ··-·enable_strategy1179 ··-·enable_strategy
1185 ··-·low_complexity1180 ··-·low_complexity
1186 ··-·low_disruption1181 ··-·low_disruption
1187 ··-·medium_severity1182 ··-·medium_severity
Max diff block lines reached; 90323/98544 bytes (91.66%) of diff not shown.
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-ospp.html
    
Offset 15547, 64 lines modifiedOffset 15547, 64 lines modified
0003cba0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003cba0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003cbb0:·2369·646d·3638·3233·2220·7461·6269·6e64··#idm6823"·tabind0003cbb0:·2369·646d·3638·3233·2220·7461·6269·6e64··#idm6823"·tabind
0003cbc0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003cbc0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003cbd0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003cbd0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003cbe0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003cbe0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003cbf0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003cbf0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003cc00:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003cc00:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003cc10:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0003cc10:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
0003cc20:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003cc30:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003cc40:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003cc50:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003cc60:·6170·7365·2220·6964·3d22·6964·6d36·3832··apse"·id="idm682 
0003cc70:·3322·3e3c·7072·653e·3c63·6f64·653e·0a5b··3"><pre><code>.[ 
0003cc80:·6375·7374·6f6d·697a·6174·696f·6e73·5d0a··customizations]. 
0003cc90:·6669·7073·203d·2074·7275·650a·3c2f·636f··fips·=·true.</co 
0003cca0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003ccb0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003ccc0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003ccd0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003cce0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003ccf0:·646d·3638·3234·2220·7461·6269·6e64·6578··dm6824"·tabindex 
0003cd00:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003cd10:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003cd20:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003cd30:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003cd40:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003cd50:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003cd60:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b0003cc20:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
0003cd70:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003cc30:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003cd80:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003cc40:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003cd90:·6c61·7073·6522·2069·643d·2269·646d·3638··lapse"·id="idm680003cc50:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003cda0:·3234·223e·3c70·7265·3e3c·636f·6465·3e23··24"><pre><code>#0003cc60:·3638·3233·223e·3c70·7265·3e3c·636f·6465··6823"><pre><code
0003cdb0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·0003cc70:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
0003cdc0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·0003cc80:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
0003cdd0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf0003cc90:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
0003cde0:·6f72·6d73·0a69·6620·2820·2120·2820·5b20··orms.if·(·!·(·[·0003cca0:·7466·6f72·6d73·0a69·6620·2820·2120·2820··tforms.if·(·!·(·
0003cdf0:·2224·7b63·6f6e·7461·696e·6572·3a2d·7d22··"${container:-}"0003ccb0:·5b20·2224·7b63·6f6e·7461·696e·6572·3a2d··[·"${container:-
0003ce00:·203d·3d20·2262·7772·6170·2d6f·7362·7569···==·"bwrap-osbui0003ccc0:·7d22·203d·3d20·2262·7772·6170·2d6f·7362··}"·==·"bwrap-osb
0003ce10:·6c64·2220·5d20·2920·2661·6d70·3b26·616d··ld"·]·)·&amp;&am0003ccd0:·7569·6c64·2220·5d20·2920·2661·6d70·3b26··uild"·]·)·&amp;&
0003ce20:·703b·2072·706d·202d·2d71·7569·6574·202d··p;·rpm·--quiet·-0003cce0:·616d·703b·2072·706d·202d·2d71·7569·6574··amp;·rpm·--quiet
0003ce30:·7120·6b65·726e·656c·207c·7c20·7270·6d20··q·kernel·||·rpm·0003ccf0:·202d·7120·6b65·726e·656c·207c·7c20·7270···-q·kernel·||·rp
0003ce40:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne0003cd00:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
0003ce50:·6c2d·7565·6b20·293b·2074·6865·6e0a·0a69··l-uek·);·then..i0003cd10:·6e65·6c2d·7565·6b20·293b·2074·6865·6e0a··nel-uek·);·then.
0003ce60:·6620·5b5b·2022·244f·5343·4150·5f42·4f4f··f·[[·"$OSCAP_BOO0003cd20:·0a69·6620·5b5b·2022·244f·5343·4150·5f42··.if·[[·"$OSCAP_B
0003ce70:·5443·5f42·5549·4c44·2220·3d3d·2022·5945··TC_BUILD"·==·"YE0003cd30:·4f4f·5443·5f42·5549·4c44·2220·3d3d·2022··OOTC_BUILD"·==·"
0003ce80:·5322·205d·5d3b·2074·6865·6e0a·0963·6174··S"·]];·then..cat0003cd40:·5945·5322·205d·5d3b·2074·6865·6e0a·0963··YES"·]];·then..c
0003ce90:·2026·6774·3b20·2f75·7372·2f6c·6962·2f62···&gt;·/usr/lib/b0003cd50:·6174·2026·6774·3b20·2f75·7372·2f6c·6962··at·&gt;·/usr/lib
0003cea0:·6f6f·7463·2f6b·6172·6773·2e64·2f30·312d··ootc/kargs.d/01-0003cd60:·2f62·6f6f·7463·2f6b·6172·6773·2e64·2f30··/bootc/kargs.d/0
0003ceb0:·6669·7073·2e74·6f6d·6c20·266c·743b·266c··fips.toml·&lt;&l0003cd70:·312d·6669·7073·2e74·6f6d·6c20·266c·743b··1-fips.toml·&lt;
0003cec0:·743b·2045·4f46·0a6b·6172·6773·203d·205b··t;·EOF.kargs·=·[0003cd80:·266c·743b·2045·4f46·0a6b·6172·6773·203d··&lt;·EOF.kargs·=
0003ced0:·2266·6970·733d·3122·5d0a·454f·460a·6669··"fips=1"].EOF.fi0003cd90:·205b·2266·6970·733d·3122·5d0a·454f·460a···["fips=1"].EOF.
0003cee0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&0003cda0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt
0003cef0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme0003cdb0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
0003cf00:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a0003cdc0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
0003cf10:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi0003cdd0:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
0003cf20:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.0003cde0:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
 0003cdf0:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
 0003ce00:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 0003ce10:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 0003ce20:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
 0003ce30:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
 0003ce40:·6574·3d22·2369·646d·3638·3234·2220·7461··et="#idm6824"·ta
 0003ce50:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0003ce60:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0003ce70:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0003ce80:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0003ce90:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0003cea0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003ceb0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin
 0003cec0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a
 0003ced0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003cee0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003cef0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003cf00:·6d36·3832·3422·3e3c·7072·653e·3c63·6f64··m6824"><pre><cod
 0003cf10:·653e·0a5b·6375·7374·6f6d·697a·6174·696f··e>.[customizatio
 0003cf20:·6e73·5d0a·6669·7073·203d·2074·7275·650a··ns].fips·=·true.
0003cf30:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003cf30:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003cf40:·6976·3e3c·2f64·6976·3e3c·2f74·643e·3c2f··iv></div></td></0003cf40:·6976·3e3c·2f64·6976·3e3c·2f74·643e·3c2f··iv></div></td></
0003cf50:·7472·3e3c·2f74·626f·6479·3e3c·2f74·6162··tr></tbody></tab0003cf50:·7472·3e3c·2f74·626f·6479·3e3c·2f74·6162··tr></tbody></tab
0003cf60:·6c65·3e3c·2f74·643e·3c2f·7472·3e3c·7472··le></td></tr><tr0003cf60:·6c65·3e3c·2f74·643e·3c2f·7472·3e3c·7472··le></td></tr><tr
0003cf70:·2064·6174·612d·7474·2d69·643d·2263·6869···data-tt-id="chi0003cf70:·2064·6174·612d·7474·2d69·643d·2263·6869···data-tt-id="chi
0003cf80:·6c64·7265·6e2d·7863·6364·665f·6f72·672e··ldren-xccdf_org.0003cf80:·6c64·7265·6e2d·7863·6364·665f·6f72·672e··ldren-xccdf_org.
0003cf90:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte0003cf90:·7373·6770·726f·6a65·6374·2e63·6f6e·7465··ssgproject.conte
Offset 15869, 184 lines modifiedOffset 15869, 184 lines modified
0003dfc0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003dfc0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003dfd0:·3d22·2369·646d·3639·3634·2220·7461·6269··="#idm6964"·tabi0003dfd0:·3d22·2369·646d·3639·3634·2220·7461·6269··="#idm6964"·tabi
0003dfe0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003dfe0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003dff0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003dff0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003e000:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003e000:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003e010:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003e010:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003e020:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003e020:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003e030:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003e030:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003e040:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003e050:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003e060:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003e070:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003e080:·646d·3639·3634·223e·3c74·6162·6c65·2063··dm6964"><table·c
 0003e090:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003e0a0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003e0b0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003e0c0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003e0d0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003e040:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003e050:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003e060:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003e070:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003e080:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6 
0003e090:·3936·3422·3e3c·7072·653e·3c63·6f64·653e··964"><pre><code> 
0003e0a0:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003e0b0:·6d65·203d·2022·6372·7970·746f·2d70·6f6c··me·=·"crypto-pol 
0003e0c0:·6963·6965·7322·0a76·6572·7369·6f6e·203d··icies".version·= 
0003e0d0:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003e0e0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003e0f0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003e100:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003e110:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003e120:·6172·6765·743d·2223·6964·6d36·3936·3522··arget="#idm6965" 
0003e130:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003e140:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003e150:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003e160:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003e170:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003e180:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003e190:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003e1a0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003e1b0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
Max diff block lines reached; 935499/967431 bytes (96.70%) of diff not shown.
120 KB
html2text {}
    
Offset 215, 31 lines modifiedOffset 215, 31 lines modified
215 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode215 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
216 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877216 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
217 ············_\x8i_\x8s_\x8m······1446217 ············_\x8i_\x8s_\x8m······1446
218 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1218 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
219 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12219 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
220 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1220 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
221 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176221 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
223 [customizations] 
224 fips·=·true 
225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
226 #·Remediation·is·applicable·only·in·certain·platforms223 #·Remediation·is·applicable·only·in·certain·platforms
227 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then224 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
228 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then225 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
229 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF226 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
230 kargs·=·["fips=1"]227 kargs·=·["fips=1"]
231 EOF228 EOF
232 fi229 fi
  
233 else230 else
234 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'231 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
235 fi232 fi
 233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 234 [customizations]
 235 fips·=·true
236 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules236 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules
237 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:237 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
238 ····*·GnuTLS·library238 ····*·GnuTLS·library
239 ····*·OpenSSL·library239 ····*·OpenSSL·library
240 ····*·NSS·library240 ····*·NSS·library
241 ····*·OpenJDK241 ····*·OpenJDK
242 ····*·Libkrb5242 ····*·Libkrb5
Offset 251, 19 lines modifiedOffset 251, 14 lines modified
251 $·sudo·yum·install·crypto-policies251 $·sudo·yum·install·crypto-policies
252 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.252 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
253 Severity: ··medium253 Severity: ··medium
254 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed254 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
255 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123255 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
256 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1256 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
257 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174257 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
258 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
259 [[packages]] 
260 name·=·"crypto-policies" 
261 version·=·"*" 
262 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8258 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
263 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low259 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
264 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low260 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
265 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false261 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
266 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable262 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
267 if·!·rpm·-q·--quiet·"crypto-policies"·;·then263 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 281, 33 lines modifiedOffset 276, 38 lines modified
281 ··tags:276 ··tags:
282 ··-·enable_strategy277 ··-·enable_strategy
283 ··-·low_complexity278 ··-·low_complexity
284 ··-·low_disruption279 ··-·low_disruption
285 ··-·medium_severity280 ··-·medium_severity
286 ··-·no_reboot_needed281 ··-·no_reboot_needed
287 ··-·package_crypto-policies_installed282 ··-·package_crypto-policies_installed
 283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 284 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 285 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 286 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 287 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 288 package·--add=crypto-policies
 289 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 290 [[packages]]
 291 name·=·"crypto-policies"
 292 version·=·"*"
288 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8293 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
289 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low294 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
290 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low295 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
291 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false296 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
292 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable297 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
293 include·install_crypto-policies298 include·install_crypto-policies
  
294 class·install_crypto-policies·{299 class·install_crypto-policies·{
295 ··package·{·'crypto-policies':300 ··package·{·'crypto-policies':
296 ····ensure·=>·'installed',301 ····ensure·=>·'installed',
297 ··}302 ··}
298 }303 }
299 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
300 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
301 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
302 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
303 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
304 package·--add=crypto-policies 
305 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*304 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
306 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:305 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
307 $·sudo·update-crypto-policies·--set·FIPS:OSPP306 $·sudo·update-crypto-policies·--set·FIPS:OSPP
308 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.307 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
309 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.308 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
310 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.309 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
311 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.310 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 624, 19 lines modifiedOffset 624, 14 lines modified
624 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235624 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
625 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386625 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
626 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)626 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
627 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1627 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
628 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125628 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
629 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33629 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
630 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2630 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
631 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
632 [[packages]] 
633 name·=·"sudo" 
634 version·=·"*" 
635 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8631 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
636 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low632 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
637 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low633 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
638 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false634 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
639 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable635 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
640 #·Remediation·is·applicable·only·in·certain·platforms636 #·Remediation·is·applicable·only·in·certain·platforms
641 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then637 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 678, 49 lines modifiedOffset 673, 49 lines modified
678 ··-·PCI-DSSv4-2.2.6673 ··-·PCI-DSSv4-2.2.6
679 ··-·enable_strategy674 ··-·enable_strategy
680 ··-·low_complexity675 ··-·low_complexity
681 ··-·low_disruption676 ··-·low_disruption
682 ··-·medium_severity677 ··-·medium_severity
Max diff block lines reached; 114523/122433 bytes (93.54%) of diff not shown.
778 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-pci-dss.html
    
Offset 16568, 218 lines modifiedOffset 16568, 218 lines modified
00040b70:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm600040b70:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm6
00040b80:·3237·3922·2074·6162·696e·6465·783d·2230··279"·tabindex="000040b80:·3237·3922·2074·6162·696e·6465·783d·2230··279"·tabindex="0
00040b90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00040b90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00040ba0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00040ba0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00040bb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00040bb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00040bc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00040bc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00040bd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00040bd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00040be0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B00040be0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
00040bf0:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
00040c00:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00040c10:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00040c20:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00040c30:·2069·643d·2269·646d·3632·3739·223e·3c70···id="idm6279"><p 
00040c40:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
00040c50:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a 
00040c60:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·" 
00040c70:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
00040c80:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00040c90:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00040ca0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00040cb0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00040cc0:·6765·743d·2223·6964·6d36·3238·3022·2074··get="#idm6280"·t 
00040cd0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00040ce0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
00040cf0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
00040d00:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
00040d10:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
00040d20:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
00040d30:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
00040d40:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00040d50:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
00040d60:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
00040d70:·3d22·6964·6d36·3238·3022·3e3c·7461·626c··="idm6280"><tabl 
00040d80:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00040d90:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00040da0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00040db0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00040dc0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00040dd0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00040de0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00040df0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00040e00:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00040e10:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00040e20:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00040e30:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00040e40:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00040e50:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00040e60:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00040e70:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
00040e80:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
00040e90:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
00040ea0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm· 
00040eb0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
00040ec0:·6c20·7c7c·2072·706d·202d·2d71·7569·6574··l·||·rpm·--quiet 
00040ed0:·202d·7120·6b65·726e·656c·2d75·656b·3b20···-q·kernel-uek;· 
00040ee0:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
00040ef0:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
00040f00:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum· 
00040f10:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
00040f20:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
00040f30:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
00040f40:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
00040f50:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
00040f60:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
00040f70:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
00040f80:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
00040f90:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
00040fa0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00040fb0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00040fc0:·7267·6574·3d22·2369·646d·3632·3831·2220··rget="#idm6281"· 
00040fd0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00040fe0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00040ff0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00041000:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00041010:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
00041020:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
00041030:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
00041040:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di00040bf0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
00041050:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c00040c00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00041060:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse00040c10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00041070:·2220·6964·3d22·6964·6d36·3238·3122·3e3c··"·id="idm6281"><00040c20:·7365·2220·6964·3d22·6964·6d36·3237·3922··se"·id="idm6279"
00041080:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab00040c30:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00041090:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped00040c40:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
000410a0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·00040c50:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
000410b0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"00040c60:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
000410c0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex00040c70:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
000410d0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low00040c80:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 00040c90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00040ca0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 00040cb0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00040cc0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 00040cd0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
000410e0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00040ce0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
000410f0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
00041100:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00041110:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
00041120:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
00041130:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
00041140:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>00040cf0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
00041150:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><00040d00:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
00041160:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre00040d10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00040d20:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 00040d30:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 00040d40:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 00040d50:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 00040d60:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q
 00040d70:·206b·6572·6e65·6c20·7c7c·2072·706d·202d···kernel·||·rpm·-
 00040d80:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel
 00040d90:·2d75·656b·3b20·7468·656e·0a0a·6966·2021··-uek;·then..if·!
 00040da0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 00040db0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 00040dc0:·2020·7975·6d20·696e·7374·616c·6c20·2d79····yum·install·-y
 00040dd0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 00040de0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 00040df0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 00040e00:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 00040e10:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 00040e20:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
00041170:·3e3c·636f·6465·3e2d·206e·616d·653a·2047··><code>-·name:·G 
00041180:·6174·6865·7220·7468·6520·7061·636b·6167··ather·the·packag 
00041190:·6520·6661·6374·730a·2020·7061·636b·6167··e·facts.··packag 
000411a0:·655f·6661·6374·733a·0a20·2020·206d·616e··e_facts:.····man 
000411b0:·6167·6572·3a20·6175·746f·0a20·2074·6167··ager:·auto.··tag 
000411c0:·733a·0a20·202d·2043·4a49·532d·352e·3130··s:.··-·CJIS-5.10 
000411d0:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80 
000411e0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
000411f0:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11. 
Max diff block lines reached; 687240/715972 bytes (95.99%) of diff not shown.
78.4 KB
html2text {}
    
Offset 494, 19 lines modifiedOffset 494, 14 lines modified
494 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3494 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
495 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)495 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
496 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3496 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
497 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5497 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
498 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199498 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
499 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79499 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
500 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2500 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
501 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
502 [[packages]] 
503 name·=·"aide" 
504 version·=·"*" 
505 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8501 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
506 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low502 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
507 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low503 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
508 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false504 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
509 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable505 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
510 #·Remediation·is·applicable·only·in·certain·platforms506 #·Remediation·is·applicable·only·in·certain·platforms
511 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then507 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 550, 33 lines modifiedOffset 545, 38 lines modified
550 ··-·PCI-DSSv4-11.5.2545 ··-·PCI-DSSv4-11.5.2
551 ··-·enable_strategy546 ··-·enable_strategy
552 ··-·low_complexity547 ··-·low_complexity
553 ··-·low_disruption548 ··-·low_disruption
554 ··-·medium_severity549 ··-·medium_severity
555 ··-·no_reboot_needed550 ··-·no_reboot_needed
556 ··-·package_aide_installed551 ··-·package_aide_installed
 552 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 553 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 554 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 555 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 556 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 557 package·--add=aide
 558 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 559 [[packages]]
 560 name·=·"aide"
 561 version·=·"*"
557 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8562 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
558 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low563 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
559 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low564 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
560 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false565 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
561 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable566 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
562 include·install_aide567 include·install_aide
  
563 class·install_aide·{568 class·install_aide·{
564 ··package·{·'aide':569 ··package·{·'aide':
565 ····ensure·=>·'installed',570 ····ensure·=>·'installed',
566 ··}571 ··}
567 }572 }
568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
573 package·--add=aide 
574 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*573 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
575 Run·the·following·command·to·generate·a·new·database:574 Run·the·following·command·to·generate·a·new·database:
576 $·sudo·/usr/sbin/aide·--init575 $·sudo·/usr/sbin/aide·--init
577 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:576 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
578 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz577 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
579 To·initiate·a·manual·check,·run·the·following·command:578 To·initiate·a·manual·check,·run·the·following·command:
580 $·sudo·/usr/sbin/aide·--check579 $·sudo·/usr/sbin/aide·--check
Offset 2552, 19 lines modifiedOffset 2552, 14 lines modified
2552 ············_\x8d_\x8i_\x8s_\x8a····CCI-0022352552 ············_\x8d_\x8i_\x8s_\x8a····CCI-002235
2553 ············_\x8i_\x8s_\x8m·····1382,·1384,·13862553 ············_\x8i_\x8s_\x8m·····1382,·1384,·1386
2554 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)2554 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
2555 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.12555 References:·_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
2556 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001252556 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
2557 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R332557 ············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
2558 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.22558 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
2559 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2560 [[packages]] 
2561 name·=·"sudo" 
2562 version·=·"*" 
2563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82559 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2564 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2560 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2565 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2561 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2566 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2562 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2567 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2563 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2568 #·Remediation·is·applicable·only·in·certain·platforms2564 #·Remediation·is·applicable·only·in·certain·platforms
2569 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then2565 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 2606, 33 lines modifiedOffset 2601, 38 lines modified
2606 ··-·PCI-DSSv4-2.2.62601 ··-·PCI-DSSv4-2.2.6
2607 ··-·enable_strategy2602 ··-·enable_strategy
2608 ··-·low_complexity2603 ··-·low_complexity
2609 ··-·low_disruption2604 ··-·low_disruption
2610 ··-·medium_severity2605 ··-·medium_severity
2611 ··-·no_reboot_needed2606 ··-·no_reboot_needed
2612 ··-·package_sudo_installed2607 ··-·package_sudo_installed
 2608 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2609 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2610 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2611 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2612 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 2613 package·--add=sudo
 2614 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2615 [[packages]]
 2616 name·=·"sudo"
 2617 version·=·"*"
2613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82618 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2619 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2620 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2621 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2622 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2618 include·install_sudo2623 include·install_sudo
  
2619 class·install_sudo·{2624 class·install_sudo·{
2620 ··package·{·'sudo':2625 ··package·{·'sudo':
2621 ····ensure·=>·'installed',2626 ····ensure·=>·'installed',
2622 ··}2627 ··}
2623 }2628 }
2624 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2625 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
2626 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
2627 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
2628 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
2629 package·--add=sudo 
2630 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2629 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·O\x8On\x8nl\x8ly\x8y·U\x8Us\x8se\x8er\x8rs\x8s·L\x8Lo\x8og\x8gg\x8ge\x8ed\x8d·I\x8In\x8n·T\x8To\x8o·R\x8Re\x8ea\x8al\x8l·t\x8tt\x8ty\x8y·C\x8Ca\x8an\x8n·E\x8Ex\x8xe\x8ec\x8cu\x8ut\x8te\x8e·S\x8Su\x8ud\x8do\x8o·-\x8-·s\x8su\x8ud\x8do\x8o·u\x8us\x8se\x8e_\x8_p\x8pt\x8ty\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2631 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.2630 The·sudo·use_pty·tag,·when·specified,·will·only·execute·sudo·commands·from·users·logged·in·to·a·real·tty.·This·should·be·enabled·by·making·sure·that·the·use_pty·tag·exists·in·/etc/sudoers·configuration·file·or·any·sudo·configuration·snippets·in·/etc/sudoers.d/.
2632 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.2631 Rationale:··Requiring·that·sudo·commands·be·run·in·a·pseudo-terminal·can·prevent·an·attacker·from·retaining·access·to·the·user's·terminal·after·the·main·program·has·finished·executing.
Max diff block lines reached; 74423/80234 bytes (92.76%) of diff not shown.
359 KB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-standard.html
    
Offset 21783, 849 lines modifiedOffset 21783, 849 lines modified
00055160:·743d·2223·6964·6d31·3533·3239·2220·7461··t="#idm15329"·ta00055160:·743d·2223·6964·6d31·3533·3239·2220·7461··t="#idm15329"·ta
00055170:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00055170:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00055180:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00055180:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00055190:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00055190:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
000551a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t000551a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
000551b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="000551b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
Diff chunk too large, falling back to line-by-line diff (397 lines added, 397 lines removed)
000551c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·000551c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
000551d0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·000551d0:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp
000551e0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·000551e0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
000551f0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col000551f0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
00055200:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·00055200:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
00055210:·6964·3d22·6964·6d31·3533·3239·223e·3c74··id="idm15329"><t00055210:·6522·2069·643d·2269·646d·3135·3332·3922··e"·id="idm15329"
00055220:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl00055220:·3e3c·7072·653e·3c63·6f64·653e·2d2d·2d0a··><pre><code>---.
00055230:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·00055230:·6170·6956·6572·7369·6f6e·3a20·6d61·6368··apiVersion:·mach
00055240:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t00055240:·696e·6563·6f6e·6669·6775·7261·7469·6f6e··ineconfiguration
00055250:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">00055250:·2e6f·7065·6e73·6869·6674·2e69·6f2f·7631··.openshift.io/v1
00055260:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi00055260:·0a6b·696e·643a·204d·6163·6869·6e65·436f··.kind:·MachineCo
00055270:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<00055270:·6e66·6967·0a73·7065·633a·0a20·2063·6f6e··nfig.spec:.··con
00055280:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th00055280:·6669·673a·0a20·2020·2069·676e·6974·696f··fig:.····ignitio
00055290:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th00055290:·6e3a·0a20·2020·2020·2076·6572·7369·6f6e··n:.······version
000552a0:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>000552a0:·3a20·332e·312e·300a·2020·2020·7374·6f72··:·3.1.0.····stor
000552b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb000552b0:·6167·653a·0a20·2020·2020·2066·696c·6573··age:.······files
000552c0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal000552c0:·3a0a·2020·2020·2020·2d20·636f·6e74·656e··:.······-·conten
000552d0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>000552d0:·7473·3a0a·2020·2020·2020·2020·2020·736f··ts:.··········so
000552e0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t000552e0:·7572·6365·3a20·6461·7461·3a2c·2532·3325··urce:·data:,%23%
000552f0:·683e·3c74·643e·636f·6e66·6967·7572·653c··h><td>configure<000552f0:·3230·4765·6e65·7261·7465·6425·3230·6279··20Generated%20by
00055300:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table00055300:·2532·3061·7574·6873·656c·6563·7425·3230··%20authselect%20
00055310:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na00055310:·6f6e·2532·3053·6174·2532·304f·6374·2532··on%20Sat%20Oct%2
00055320:·6d65·3a20·4761·7468·6572·2074·6865·2070··me:·Gather·the·p00055320:·3032·3725·3230·3134·2533·4135·3925·3341··027%2014%3A59%3A
00055330:·6163·6b61·6765·2066·6163·7473·0a20·2070··ackage·facts.··p00055330:·3336·2532·3032·3031·3825·3041·2532·3325··36%202018%0A%23%
00055340:·6163·6b61·6765·5f66·6163·7473·3a0a·2020··ackage_facts:.··00055340:·3230·446f·2532·306e·6f74·2532·306d·6f64··20Do%20not%20mod
00055350:·2020·6d61·6e61·6765·723a·2061·7574·6f0a····manager:·auto.00055350:·6966·7925·3230·7468·6973·2532·3066·696c··ify%20this%20fil
00055360:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS00055360:·6525·3230·6d61·6e75·616c·6c79·2e25·3041··e%20manually.%0A
00055370:·2d35·2e35·2e32·0a20·202d·204e·4953·542d··-5.5.2.··-·NIST-00055370:·2530·4161·7574·6825·3230·2532·3025·3230··%0Aauth%20%20%20
00055380:·3830·302d·3137·312d·332e·312e·310a·2020··800-171-3.1.1.··00055380:·2532·3025·3230·2532·3025·3230·2532·3072··%20%20%20%20%20r
00055390:·2d20·4e49·5354·2d38·3030·2d31·3731·2d33··-·NIST-800-171-300055390:·6571·7569·7265·6425·3230·2532·3025·3230··equired%20%20%20
000553a0:·2e31·2e35·0a20·202d·204e·4953·542d·3830··.1.5.··-·NIST-80000553a0:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
000553b0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-000553b0:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
000553c0:·204e·4953·542d·3830·302d·3533·2d49·412d···NIST-800-53-IA-000553c0:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
000553d0:·3528·3129·2861·290a·2020·2d20·4e49·5354··5(1)(a).··-·NIST000553d0:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
000553e0:·2d38·3030·2d35·332d·4941·2d35·2863·290a··-800-53-IA-5(c).000553e0:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
000553f0:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-000553f0:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
00055400:·382e·322e·330a·2020·2d20·5043·492d·4453··8.2.3.··-·PCI-DS00055400:·2532·3025·3230·7061·6d5f·656e·762e·736f··%20%20pam_env.so
00055410:·5376·342d·382e·330a·2020·2d20·5043·492d··Sv4-8.3.··-·PCI-00055410:·2530·4161·7574·6825·3230·2532·3025·3230··%0Aauth%20%20%20
00055420:·4453·5376·342d·382e·332e·310a·2020·2d20··DSSv4-8.3.1.··-·00055420:·2532·3025·3230·2532·3025·3230·2532·3072··%20%20%20%20%20r
00055430:·636f·6e66·6967·7572·655f·7374·7261·7465··configure_strate00055430:·6571·7569·7265·6425·3230·2532·3025·3230··equired%20%20%20
00055440:·6779·0a20·202d·2068·6967·685f·7365·7665··gy.··-·high_seve00055440:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055450:·7269·7479·0a20·202d·206c·6f77·5f63·6f6d··rity.··-·low_com00055450:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055460:·706c·6578·6974·790a·2020·2d20·6d65·6469··plexity.··-·medi00055460:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
00055470:·756d·5f64·6973·7275·7074·696f·6e0a·2020··um_disruption.··00055470:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055480:·2d20·6e6f·5f65·6d70·7479·5f70·6173·7377··-·no_empty_passw00055480:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055490:·6f72·6473·0a20·202d·206e·6f5f·7265·626f··ords.··-·no_rebo00055490:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
000554a0:·6f74·5f6e·6565·6465·640a·0a2d·206e·616d··ot_needed..-·nam000554a0:·2532·3025·3230·7061·6d5f·6661·696c·6465··%20%20pam_failde
000554b0:·653a·2050·7265·7665·6e74·204c·6f67·696e··e:·Prevent·Login000554b0:·6c61·792e·736f·2532·3064·656c·6179·2533··lay.so%20delay%3
000554c0:·2074·6f20·4163·636f·756e·7473·2057·6974···to·Accounts·Wit000554c0:·4432·3030·3030·3030·2530·4161·7574·6825··D2000000%0Aauth%
000554d0:·6820·456d·7074·7920·5061·7373·776f·7264··h·Empty·Password000554d0:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
000554e0:·202d·2043·6865·636b·2069·6620·7379·7374···-·Check·if·syst000554e0:·3025·3230·2532·3073·7566·6669·6369·656e··0%20%20sufficien
000554f0:·656d·2072·656c·6965·7320·6f6e·0a20·2020··em·relies·on.···000554f0:·7425·3230·2532·3025·3230·2532·3025·3230··t%20%20%20%20%20
00055500:·2061·7574·6873·656c·6563·740a·2020·616e···authselect.··an00055500:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055510:·7369·626c·652e·6275·696c·7469·6e2e·7374··sible.builtin.st00055510:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055520:·6174·3a0a·2020·2020·7061·7468·3a20·2f75··at:.····path:·/u00055520:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
00055530:·7372·2f62·696e·2f61·7574·6873·656c·6563··sr/bin/authselec00055530:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055540:·740a·2020·7265·6769·7374·6572·3a20·7265··t.··register:·re00055540:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055550:·7375·6c74·5f61·7574·6873·656c·6563·745f··sult_authselect_00055550:·3025·3230·2532·3025·3230·7061·6d5f·6670··0%20%20%20pam_fp
00055560:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:·00055560:·7269·6e74·642e·736f·2530·4161·7574·6825··rintd.so%0Aauth%
00055570:·2822·6b65·726e·656c·2220·696e·2061·6e73··("kernel"·in·ans00055570:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055580:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa00055580:·3025·3230·2532·3025·3542·6465·6661·756c··0%20%20%5Bdefaul
00055590:·6765·7320·6f72·2022·6b65·726e·656c·2d75··ges·or·"kernel-u00055590:·7425·3344·3125·3230·6967·6e6f·7265·2533··t%3D1%20ignore%3
000555a0:·656b·2220·696e·2061·6e73·6962·6c65·5f66··ek"·in·ansible_f000555a0:·4469·676e·6f72·6525·3230·7375·6363·6573··Dignore%20succes
000555b0:·6163·7473·2e70·6163·6b61·6765·7329·0a20··acts.packages).·000555b0:·7325·3344·6f6b·2535·4425·3230·2532·3025··s%3Dok%5D%20%20%
000555c0:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-000555c0:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
000555d0:·352e·352e·320a·2020·2d20·4e49·5354·2d38··5.5.2.··-·NIST-8000555d0:·3025·3230·7061·6d5f·7375·6363·6565·645f··0%20pam_succeed_
000555e0:·3030·2d31·3731·2d33·2e31·2e31·0a20·202d··00-171-3.1.1.··-000555e0:·6966·2e73·6f25·3230·7569·6425·3230·2533··if.so%20uid%20%3
000555f0:·204e·4953·542d·3830·302d·3137·312d·332e···NIST-800-171-3.000555f0:·4525·3344·2532·3031·3030·3025·3230·7175··E%3D%201000%20qu
00055600:·312e·350a·2020·2d20·4e49·5354·2d38·3030··1.5.··-·NIST-80000055600:·6965·7425·3041·6175·7468·2532·3025·3230··iet%0Aauth%20%20
00055610:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-·00055610:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055620:·4e49·5354·2d38·3030·2d35·332d·4941·2d35··NIST-800-53-IA-500055620:·3230·2535·4264·6566·6175·6c74·2533·4431··20%5Bdefault%3D1
00055630:·2831·2928·6129·0a20·202d·204e·4953·542d··(1)(a).··-·NIST-00055630:·2532·3069·676e·6f72·6525·3344·6967·6e6f··%20ignore%3Digno
00055640:·3830·302d·3533·2d49·412d·3528·6329·0a20··800-53-IA-5(c).·00055640:·7265·2532·3073·7563·6365·7373·2533·446f··re%20success%3Do
00055650:·202d·2050·4349·2d44·5353·2d52·6571·2d38···-·PCI-DSS-Req-800055650:·6b25·3544·2532·3025·3230·2532·3025·3230··k%5D%20%20%20%20
00055660:·2e32·2e33·0a20·202d·2050·4349·2d44·5353··.2.3.··-·PCI-DSS00055660:·2532·3025·3230·2532·3025·3230·2532·3070··%20%20%20%20%20p
00055670:·7634·2d38·2e33·0a20·202d·2050·4349·2d44··v4-8.3.··-·PCI-D00055670:·616d·5f6c·6f63·616c·7573·6572·2e73·6f25··am_localuser.so%
00055680:·5353·7634·2d38·2e33·2e31·0a20·202d·2063··SSv4-8.3.1.··-·c00055680:·3041·6175·7468·2532·3025·3230·2532·3025··0Aauth%20%20%20%
00055690:·6f6e·6669·6775·7265·5f73·7472·6174·6567··onfigure_strateg00055690:·3230·2532·3025·3230·2532·3025·3230·7375··20%20%20%20%20su
000556a0:·790a·2020·2d20·6869·6768·5f73·6576·6572··y.··-·high_sever000556a0:·6666·6963·6965·6e74·2532·3025·3230·2532··fficient%20%20%2
000556b0:·6974·790a·2020·2d20·6c6f·775f·636f·6d70··ity.··-·low_comp000556b0:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
000556c0:·6c65·7869·7479·0a20·202d·206d·6564·6975··lexity.··-·mediu000556c0:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
000556d0:·6d5f·6469·7372·7570·7469·6f6e·0a20·202d··m_disruption.··-000556d0:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
000556e0:·206e·6f5f·656d·7074·795f·7061·7373·776f···no_empty_passwo000556e0:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
000556f0:·7264·730a·2020·2d20·6e6f·5f72·6562·6f6f··rds.··-·no_reboo000556f0:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055700:·745f·6e65·6564·6564·0a0a·2d20·6e61·6d65··t_needed..-·name00055700:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055710:·3a20·5072·6576·656e·7420·4c6f·6769·6e20··:·Prevent·Login·00055710:·3070·616d·5f75·6e69·782e·736f·2532·3074··0pam_unix.so%20t
00055720:·746f·2041·6363·6f75·6e74·7320·5769·7468··to·Accounts·With00055720:·7279·5f66·6972·7374·5f70·6173·7325·3041··ry_first_pass%0A
00055730:·2045·6d70·7479·2050·6173·7377·6f72·6420···Empty·Password·00055730:·6175·7468·2532·3025·3230·2532·3025·3230··auth%20%20%20%20
00055740:·2d20·5265·6d65·6469·6174·6520·7573·696e··-·Remediate·usin00055740:·2532·3025·3230·2532·3025·3230·7265·7175··%20%20%20%20requ
00055750:·6720·6175·7468·7365·6c65·6374·0a20·2062··g·authselect.··b00055750:·6973·6974·6525·3230·2532·3025·3230·2532··isite%20%20%20%2
00055760:·6c6f·636b·3a0a·0a20·202d·206e·616d·653a··lock:..··-·name:00055760:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
00055770:·2050·7265·7665·6e74·204c·6f67·696e·2074···Prevent·Login·t00055770:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055780:·6f20·4163·636f·756e·7473·2057·6974·6820··o·Accounts·With·00055780:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055790:·456d·7074·7920·5061·7373·776f·7264·202d··Empty·Password·-00055790:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
000557a0:·2043·6865·636b·2069·6e74·6567·7269·7479···Check·integrity000557a0:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
000557b0:·206f·6620·6175·7468·7365·6c65·6374·0a20···of·authselect.·000557b0:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
000557c0:·2020·2020·2063·7572·7265·6e74·2070·726f·······current·pro000557c0:·3070·616d·5f73·7563·6365·6564·5f69·662e··0pam_succeed_if.
000557d0:·6669·6c65·0a20·2020·2061·6e73·6962·6c65··file.····ansible000557d0:·736f·2532·3075·6964·2532·3025·3345·2533··so%20uid%20%3E%3
000557e0:·2e62·7569·6c74·696e·2e63·6f6d·6d61·6e64··.builtin.command000557e0:·4425·3230·3130·3030·2532·3071·7569·6574··D%201000%20quiet
000557f0:·3a0a·2020·2020·2020·636d·643a·2061·7574··:.······cmd:·aut000557f0:·5f73·7563·6365·7373·2530·4161·7574·6825··_success%0Aauth%
00055800:·6873·656c·6563·7420·6368·6563·6b0a·2020··hselect·check.··00055800:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055810:·2020·7265·6769·7374·6572·3a20·7265·7375····register:·resu00055810:·3025·3230·2532·3073·7566·6669·6369·656e··0%20%20sufficien
00055820:·6c74·5f61·7574·6873·656c·6563·745f·6368··lt_authselect_ch00055820:·7425·3230·2532·3025·3230·2532·3025·3230··t%20%20%20%20%20
00055830:·6563·6b5f·636d·640a·2020·2020·6368·616e··eck_cmd.····chan00055830:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055840:·6765·645f·7768·656e·3a20·6661·6c73·650a··ged_when:·false.00055840:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055850:·2020·2020·6661·696c·6564·5f77·6865·6e3a······failed_when:00055850:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
00055860:·2066·616c·7365·0a0a·2020·2d20·6e61·6d65···false..··-·name00055860:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055870:·3a20·5072·6576·656e·7420·4c6f·6769·6e20··:·Prevent·Login·00055870:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055880:·746f·2041·6363·6f75·6e74·7320·5769·7468··to·Accounts·With00055880:·3025·3230·2532·3025·3230·7061·6d5f·7373··0%20%20%20pam_ss
00055890:·2045·6d70·7479·2050·6173·7377·6f72·6420···Empty·Password·00055890:·732e·736f·2532·3066·6f72·7761·7264·5f70··s.so%20forward_p
000558a0:·2d20·496e·666f·726d·6174·6976·6520·6d65··-·Informative·me000558a0:·6173·7325·3041·6175·7468·2532·3025·3230··ass%0Aauth%20%20
000558b0:·7373·6167·6520·6261·7365·640a·2020·2020··ssage·based.····000558b0:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
000558c0:·2020·6f6e·2074·6865·2061·7574·6873·656c····on·the·authsel000558c0:·3230·7265·7175·6972·6564·2532·3025·3230··20required%20%20
000558d0:·6563·7420·696e·7465·6772·6974·7920·6368··ect·integrity·ch000558d0:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
000558e0:·6563·6b20·7265·7375·6c74·0a20·2020·2061··eck·result.····a000558e0:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
000558f0:·6e73·6962·6c65·2e62·7569·6c74·696e·2e61··nsible.builtin.a000558f0:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
00055900:·7373·6572·743a·0a20·2020·2020·2074·6861··ssert:.······tha00055900:·2532·3025·3230·2532·3025·3230·2532·3025··%20%20%20%20%20%
00055910:·743a·0a20·2020·2020·202d·2072·6573·756c··t:.······-·resul00055910:·3230·2532·3025·3230·2532·3025·3230·2532··20%20%20%20%20%2
00055920:·745f·6175·7468·7365·6c65·6374·5f63·6865··t_authselect_che00055920:·3025·3230·2532·3025·3230·2532·3025·3230··0%20%20%20%20%20
00055930:·636b·5f63·6d64·2e72·6320·3d3d·2030·0a20··ck_cmd.rc·==·0.·00055930:·2532·3025·3230·2532·3070·616d·5f64·656e··%20%20%20pam_den
Max diff block lines reached; 279411/334777 bytes (83.46%) of diff not shown.
32.0 KB
html2text {}
    
Offset 1422, 14 lines modifiedOffset 1422, 38 lines modified
1422 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"1422 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
1423 fi1423 fi
1424 fi1424 fi
  
1425 else1425 else
1426 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1426 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1427 fi1427 fi
 1428 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1429 ---
 1430 apiVersion:·machineconfiguration.openshift.io/v1
 1431 kind:·MachineConfig
 1432 spec:
 1433 ··config:
 1434 ····ignition:
 1435 ······version:·3.1.0
 1436 ····storage:
 1437 ······files:
 1438 ······-·contents:
 1439 ··········source:
 1440 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1441 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1442 ········mode:·0644
 1443 ········path:·/etc/pam.d/password-auth
 1444 ········overwrite:·true
 1445 ······-·contents:
 1446 ··········source:
 1447 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1448 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1449 ········mode:·0644
 1450 ········path:·/etc/pam.d/system-auth
 1451 ········overwrite:·true
1428 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81452 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1429 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1453 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1430 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1454 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1431 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1455 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1432 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure1456 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
1433 -·name:·Gather·the·package·facts1457 -·name:·Gather·the·package·facts
1434 ··package_facts:1458 ··package_facts:
Offset 1568, 38 lines modifiedOffset 1592, 14 lines modified
1568 ··-·PCI-DSSv4-8.3.11592 ··-·PCI-DSSv4-8.3.1
1569 ··-·configure_strategy1593 ··-·configure_strategy
1570 ··-·high_severity1594 ··-·high_severity
1571 ··-·low_complexity1595 ··-·low_complexity
1572 ··-·medium_disruption1596 ··-·medium_disruption
1573 ··-·no_empty_passwords1597 ··-·no_empty_passwords
1574 ··-·no_reboot_needed1598 ··-·no_reboot_needed
1575 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1576 --- 
1577 apiVersion:·machineconfiguration.openshift.io/v1 
1578 kind:·MachineConfig 
1579 spec: 
1580 ··config: 
1581 ····ignition: 
1582 ······version:·3.1.0 
1583 ····storage: 
1584 ······files: 
1585 ······-·contents: 
1586 ··········source: 
1587 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1588 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1589 ········mode:·0644 
1590 ········path:·/etc/pam.d/password-auth 
1591 ········overwrite:·true 
1592 ······-·contents: 
1593 ··········source: 
1594 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A- 
1595 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A 
1596 ········mode:·0644 
1597 ········path:·/etc/pam.d/system-auth 
1598 ········overwrite:·true 
1599 Group  ·Secure·Session·Configuration·Files·for·Login·Accounts·  Group·contains·1·group·and·2·rules1599 Group  ·Secure·Session·Configuration·Files·for·Login·Accounts·  Group·contains·1·group·and·2·rules
1600 _\x8[_\x8r_\x8e_\x8f_\x8]  ·When·a·user·logs·into·a·Unix·account,·the·system·configures·the·user's·session·by·reading·a·number·of·files.·Many·of·these·files·are·located·in·the·user's·home·directory,·and·may·have·weak·permissions·as·a·result·of·user·error·or·misconfiguration.·If·an·attacker·can·modify·or·even·read·certain·types·of·account·configuration·information,·they·can·often·gain·full·access·to·the·affected·user's·account.·Therefore,·it·is·important·to·test·and·correct·configuration·file·permissions·for·interactive·accounts,·particularly·those·of·privileged·users·such·as·root·or·system·administrators.1600 _\x8[_\x8r_\x8e_\x8f_\x8]  ·When·a·user·logs·into·a·Unix·account,·the·system·configures·the·user's·session·by·reading·a·number·of·files.·Many·of·these·files·are·located·in·the·user's·home·directory,·and·may·have·weak·permissions·as·a·result·of·user·error·or·misconfiguration.·If·an·attacker·can·modify·or·even·read·certain·types·of·account·configuration·information,·they·can·often·gain·full·access·to·the·affected·user's·account.·Therefore,·it·is·important·to·test·and·correct·configuration·file·permissions·for·interactive·accounts,·particularly·those·of·privileged·users·such·as·root·or·system·administrators.
1601 Group  ·Ensure·that·No·Dangerous·Directories·Exist·in·Root's·Path·  Group·contains·2·rules1601 Group  ·Ensure·that·No·Dangerous·Directories·Exist·in·Root's·Path·  Group·contains·2·rules
1602 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·active·path·of·the·root·account·can·be·obtained·by·starting·a·new·root·shell·and·running:1602 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·active·path·of·the·root·account·can·be·obtained·by·starting·a·new·root·shell·and·running:
1603 #·echo·$PATH1603 #·echo·$PATH
1604 This·will·produce·a·colon-separated·list·of·directories·in·the·path.1604 This·will·produce·a·colon-separated·list·of·directories·in·the·path.
  
Offset 1694, 19 lines modifiedOffset 1694, 14 lines modified
1694 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.312(a)(2)(ii)1694 ············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.312(a)(2)(ii)
1695 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.41695 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4
1696 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.91696 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
1697 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.11697 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
1698 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)1698 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
1699 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-11699 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
1700 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-002271700 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
1701 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1702 [[packages]] 
1703 name·=·"rsyslog" 
1704 version·=·"*" 
1705 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81701 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1706 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1702 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1707 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1703 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1708 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1704 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1709 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1705 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1710 #·Remediation·is·applicable·only·in·certain·platforms1706 #·Remediation·is·applicable·only·in·certain·platforms
1711 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then1707 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 1744, 33 lines modifiedOffset 1739, 38 lines modified
1744 ··-·NIST-800-53-CM-6(a)1739 ··-·NIST-800-53-CM-6(a)
1745 ··-·enable_strategy1740 ··-·enable_strategy
1746 ··-·low_complexity1741 ··-·low_complexity
1747 ··-·low_disruption1742 ··-·low_disruption
1748 ··-·medium_severity1743 ··-·medium_severity
1749 ··-·no_reboot_needed1744 ··-·no_reboot_needed
1750 ··-·package_rsyslog_installed1745 ··-·package_rsyslog_installed
 1746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1747 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1748 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1749 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1750 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1751 package·--add=rsyslog
 1752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1753 [[packages]]
 1754 name·=·"rsyslog"
 1755 version·=·"*"
1751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81756 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1752 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1757 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1753 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1758 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1754 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1759 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1755 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1760 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1756 include·install_rsyslog1761 include·install_rsyslog
  
1757 class·install_rsyslog·{1762 class·install_rsyslog·{
1758 ··package·{·'rsyslog':1763 ··package·{·'rsyslog':
1759 ····ensure·=>·'installed',1764 ····ensure·=>·'installed',
Max diff block lines reached; 11649/32704 bytes (35.62%) of diff not shown.
1.61 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-stig.html
    
Offset 15067, 218 lines modifiedOffset 15067, 218 lines modified
0003ada0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003ada0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003adb0:·6d36·3237·3922·2074·6162·696e·6465·783d··m6279"·tabindex=0003adb0:·6d36·3237·3922·2074·6162·696e·6465·783d··m6279"·tabindex=
0003adc0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003adc0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003add0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003add0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003ade0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003ade0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003adf0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003adf0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003ae00:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003ae00:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003ae10:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild0003ae10:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
0003ae20:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003ae30:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003ae40:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003ae50:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003ae60:·6522·2069·643d·2269·646d·3632·3739·223e··e"·id="idm6279"> 
0003ae70:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003ae80:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003ae90:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·= 
0003aea0:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003aeb0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003aec0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003aed0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003aee0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003aef0:·6172·6765·743d·2223·6964·6d36·3238·3022··arget="#idm6280" 
0003af00:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003af10:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003af20:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003af30:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003af40:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003af50:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003af60:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003af70:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003af80:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003af90:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003afa0:·6964·3d22·6964·6d36·3238·3022·3e3c·7461··id="idm6280"><ta 
0003afb0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003afc0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003afd0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003afe0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003aff0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b000:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b010:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b020:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b030:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b040:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b050:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b060:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b070:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b080:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b090:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b0a0:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0003b0b0:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0003b0c0:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0003b0d0:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp 
0003b0e0:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker 
0003b0f0:·6e65·6c20·7c7c·2072·706d·202d·2d71·7569··nel·||·rpm·--qui 
0003b100:·6574·202d·7120·6b65·726e·656c·2d75·656b··et·-q·kernel-uek 
0003b110:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm 
0003b120:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid 
0003b130:·6522·203b·2074·6865·6e0a·2020·2020·7975··e"·;·then.····yu 
0003b140:·6d20·696e·7374·616c·6c20·2d79·2022·6169··m·install·-y·"ai 
0003b150:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.··· 
0003b160:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003b170:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003b180:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003b190:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003b1a0:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003b1b0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b1c0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b1d0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b1e0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b1f0:·7461·7267·6574·3d22·2369·646d·3632·3831··target="#idm6281 
0003b200:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b210:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b220:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b230:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b240:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b250:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b260:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003b270:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0003ae20:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
0003b280:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003ae30:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b290:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003ae40:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003b2a0:·7365·2220·6964·3d22·6964·6d36·3238·3122··se"·id="idm6281"0003ae50:·6170·7365·2220·6964·3d22·6964·6d36·3237··apse"·id="idm627
0003b2b0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003ae60:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=
0003b2c0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003b2d0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003b2e0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003b2f0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b300:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b310:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b320:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b330:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b340:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b350:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b360:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b370:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b380:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b390:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b3a0:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name: 
0003b3b0:·2047·6174·6865·7220·7468·6520·7061·636b···Gather·the·pack 
0003b3c0:·6167·6520·6661·6374·730a·2020·7061·636b··age·facts.··pack 
0003b3d0:·6167·655f·6661·6374·733a·0a20·2020·206d··age_facts:.····m 
0003b3e0:·616e·6167·6572·3a20·6175·746f·0a20·2074··anager:·auto.··t 
0003b3f0:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5. 
0003b400:·3130·2e31·2e33·0a20·202d·204e·4953·542d··10.1.3.··-·NIST- 
0003b410:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
0003b420:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
0003b430:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
0003b440:·342d·3131·2e35·2e32·0a20·202d·2065·6e61··4-11.5.2.··-·ena 
0003b450:·626c·655f·7374·7261·7465·6779·0a20·202d··ble_strategy.··- 
0003b460:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity. 
0003b470:·2020·2d20·6c6f·775f·6469·7372·7570·7469····-·low_disrupti 
0003b480:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se 
0003b490:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re 
0003b4a0:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-· 
0003b4b0:·7061·636b·6167·655f·6169·6465·5f69·6e73··package_aide_ins 
0003b4c0:·7461·6c6c·6564·0a0a·2d20·6e61·6d65·3a20··talled..-·name:· 
0003b4d0:·456e·7375·7265·2061·6964·6520·6973·2069··Ensure·aide·is·i 
0003b4e0:·6e73·7461·6c6c·6564·0a20·2070·6163·6b61··nstalled.··packa 
0003b4f0:·6765·3a0a·2020·2020·6e61·6d65·3a20·6169··ge:.····name:·ai 
0003b500:·6465·0a20·2020·2073·7461·7465·3a20·7072··de.····state:·pr 
0003b510:·6573·656e·740a·2020·7768·656e·3a20·2822··esent.··when:·(" 
0003b520:·6b65·726e·656c·2220·696e·2061·6e73·6962··kernel"·in·ansib 
0003b530:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
0003b540:·7320·6f72·2022·6b65·726e·656c·2d75·656b··s·or·"kernel-uek 
0003b550:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
0003b560:·7473·2e70·6163·6b61·6765·7329·0a20·2074··ts.packages).··t 
0003b570:·6167·733a·0a20·202d·2043·4a49·532d·352e··ags:.··-·CJIS-5. 
0003b580:·3130·2e31·2e33·0a20·202d·204e·4953·542d··10.1.3.··-·NIST- 
Max diff block lines reached; 1484559/1513291 bytes (98.10%) of diff not shown.
174 KB
html2text {}
    
Offset 99, 19 lines modifiedOffset 99, 14 lines modified
99 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.399 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
100 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)100 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3101 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5102 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199103 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
104 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79104 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
105 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2105 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
107 [[packages]] 
108 name·=·"aide" 
109 version·=·"*" 
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
115 #·Remediation·is·applicable·only·in·certain·platforms111 #·Remediation·is·applicable·only·in·certain·platforms
116 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then112 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 155, 33 lines modifiedOffset 150, 38 lines modified
155 ··-·PCI-DSSv4-11.5.2150 ··-·PCI-DSSv4-11.5.2
156 ··-·enable_strategy151 ··-·enable_strategy
157 ··-·low_complexity152 ··-·low_complexity
158 ··-·low_disruption153 ··-·low_disruption
159 ··-·medium_severity154 ··-·medium_severity
160 ··-·no_reboot_needed155 ··-·no_reboot_needed
161 ··-·package_aide_installed156 ··-·package_aide_installed
 157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 162 package·--add=aide
 163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 164 [[packages]]
 165 name·=·"aide"
 166 version·=·"*"
162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
167 include·install_aide172 include·install_aide
  
168 class·install_aide·{173 class·install_aide·{
169 ··package·{·'aide':174 ··package·{·'aide':
170 ····ensure·=>·'installed',175 ····ensure·=>·'installed',
171 ··}176 ··}
172 }177 }
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
178 package·--add=aide 
179 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*178 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
180 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.179 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.
181 Rationale:··Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward·ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,·audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information·system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source·audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and·records.·Audit·tools·include·custom·queries·and·report·generators.·It·is·not·uncommon·for·attackers·to·replace·the·audit·tools·or·inject·code·into·the·existing·tools·to·provide·the·capability·to·hide·or·erase·system·activity·from·the·audit·logs.·To·address·this·risk,·audit·tools·must·be·cryptographically·signed·to·provide·the·capability·to·identify·when·the·audit·tools·have·been·modified,·manipulated,·or·replaced.·An·example·is·a·checksum·hash·of·the·file·or·files.180 Rationale:··Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward·ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,·audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information·system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source·audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and·records.·Audit·tools·include·custom·queries·and·report·generators.·It·is·not·uncommon·for·attackers·to·replace·the·audit·tools·or·inject·code·into·the·existing·tools·to·provide·the·capability·to·hide·or·erase·system·activity·from·the·audit·logs.·To·address·this·risk,·audit·tools·must·be·cryptographically·signed·to·provide·the·capability·to·identify·when·the·audit·tools·have·been·modified,·manipulated,·or·replaced.·An·example·is·a·checksum·hash·of·the·file·or·files.
182 Severity: ··medium181 Severity: ··medium
183 Rule·ID:····xccdf_org.ssgproject.content_rule_aide_check_audit_tools182 Rule·ID:····xccdf_org.ssgproject.content_rule_aide_check_audit_tools
184 ············_\x8d_\x8i_\x8s_\x8a···CCI-001496,·CCI-001494,·CCI-001495,·CCI-001493183 ············_\x8d_\x8i_\x8s_\x8a···CCI-001496,·CCI-001494,·CCI-001495,·CCI-001493
185 References:·_\x8n_\x8i_\x8s_\x8t···AU-9(3),·AU-9(3).1184 References:·_\x8n_\x8i_\x8s_\x8t···AU-9(3),·AU-9(3).1
Offset 1910, 31 lines modifiedOffset 1910, 31 lines modified
1910 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode1910 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
1911 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008771911 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
1912 ············_\x8i_\x8s_\x8m······14461912 ············_\x8i_\x8s_\x8m······1446
1913 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11913 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1914 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121914 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1915 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11915 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1916 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761916 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1917 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1918 [customizations] 
1919 fips·=·true 
1920 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81917 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1921 #·Remediation·is·applicable·only·in·certain·platforms1918 #·Remediation·is·applicable·only·in·certain·platforms
1922 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then1919 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
1923 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1920 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1924 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1921 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1925 kargs·=·["fips=1"]1922 kargs·=·["fips=1"]
1926 EOF1923 EOF
1927 fi1924 fi
  
1928 else1925 else
1929 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1926 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1930 fi1927 fi
 1928 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1929 [customizations]
 1930 fips·=·true
1931 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1931 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1932 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:1932 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:
1933 fips-mode-setup·--enable1933 fips-mode-setup·--enable
1934 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1934 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1935 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1935 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1936 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1936 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1937 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1937 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 1959, 19 lines modifiedOffset 1959, 14 lines modified
1959 $·sudo·yum·install·crypto-policies1959 $·sudo·yum·install·crypto-policies
1960 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.1960 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
1961 Severity: ··medium1961 Severity: ··medium
1962 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed1962 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
1963 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-0031231963 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
1964 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.11964 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
1965 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001741965 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
1966 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1967 [[packages]] 
1968 name·=·"crypto-policies" 
1969 version·=·"*" 
1970 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81966 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1971 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1967 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1972 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1968 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1973 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1969 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1974 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1970 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1975 if·!·rpm·-q·--quiet·"crypto-policies"·;·then1971 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 1989, 33 lines modifiedOffset 1984, 38 lines modified
1989 ··tags:1984 ··tags:
1990 ··-·enable_strategy1985 ··-·enable_strategy
1991 ··-·low_complexity1986 ··-·low_complexity
1992 ··-·low_disruption1987 ··-·low_disruption
1993 ··-·medium_severity1988 ··-·medium_severity
Max diff block lines reached; 169736/178395 bytes (95.15%) of diff not shown.
1.6 MB
./usr/share/doc/ssg-nondebian/ssg-ol9-guide-stig_gui.html
    
Offset 15085, 217 lines modifiedOffset 15085, 217 lines modified
0003aec0:·2d74·6172·6765·743d·2223·6964·6d36·3237··-target="#idm6270003aec0:·2d74·6172·6765·743d·2223·6964·6d36·3237··-target="#idm627
0003aed0:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·0003aed0:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·
0003aee0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003aee0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003aef0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003aef0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003af00:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003af00:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003af10:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003af10:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003af20:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003af20:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003af30:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
0003af30:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003af40:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003af50:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003af60:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003af70:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003af80:·643d·2269·646d·3632·3739·223e·3c70·7265··d="idm6279"><pre 
0003af90:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003afa0:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003afb0:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003afc0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003afd0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003afe0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003aff0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b000:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b010:·743d·2223·6964·6d36·3238·3022·2074·6162··t="#idm6280"·tab 
0003b020:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b030:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b040:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b050:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b060:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b070:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003b080:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...< 
0003b090:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b0a0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b0b0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b0c0:·6964·6d36·3238·3022·3e3c·7461·626c·6520··idm6280"><table· 
0003b0d0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b0e0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b0f0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b100:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b110:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b120:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b130:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003b140:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003b150:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b160:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003b170:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003b180:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b190:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003b1a0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003b1b0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003b1c0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003b1d0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003b1e0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003b1f0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·-- 
0003b200:·7175·6965·7420·2d71·206b·6572·6e65·6c20··quiet·-q·kernel· 
0003b210:·7c7c·2072·706d·202d·2d71·7569·6574·202d··||·rpm·--quiet·- 
0003b220:·7120·6b65·726e·656c·2d75·656b·3b20·7468··q·kernel-uek;·th 
0003b230:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
0003b240:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
0003b250:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in 
0003b260:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003b270:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003b280:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003b290:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003b2a0:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003b2b0:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003b2c0:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003b2d0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b2e0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b2f0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b300:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b310:·6574·3d22·2369·646d·3632·3831·2220·7461··et="#idm6281"·ta 
0003b320:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b330:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b340:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b350:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b360:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b370:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b380:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003b390:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003af40:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003b3a0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003af50:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003b3b0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003af60:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003b3c0:·6964·3d22·6964·6d36·3238·3122·3e3c·7461··id="idm6281"><ta0003af70:·2220·6964·3d22·6964·6d36·3237·3922·3e3c··"·id="idm6279"><
0003b3d0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003af80:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003b3e0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003af90:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003b3f0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003afa0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003b400:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003afb0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003b410:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003afc0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b420:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003afd0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003b430:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003afe0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b440:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003aff0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003b450:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b000:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b460:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b470:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b480:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b490:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b4a0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b4b0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b4c0:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat 
0003b4d0:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package· 
0003b4e0:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_ 
0003b4f0:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag 
0003b500:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags: 
0003b510:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1 
0003b520:·2e33·0a20·202d·204e·4953·542d·3830·302d··.3.··-·NIST-800- 
0003b530:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
0003b540:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
0003b550:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
0003b560:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
0003b570:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
0003b580:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
0003b590:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
0003b5a0:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
0003b5b0:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
0003b5c0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
0003b5d0:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
0003b5e0:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu 
0003b5f0:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
0003b600:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
0003b610:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
0003b620:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
0003b630:·740a·2020·7768·656e·3a20·2822·6b65·726e··t.··when:·("kern 
0003b640:·656c·2220·696e·2061·6e73·6962·6c65·5f66··el"·in·ansible_f 
0003b650:·6163·7473·2e70·6163·6b61·6765·7320·6f72··acts.packages·or 
0003b660:·2022·6b65·726e·656c·2d75·656b·2220·696e···"kernel-uek"·in 
0003b670:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p 
0003b680:·6163·6b61·6765·7329·0a20·2074·6167·733a··ackages).··tags: 
0003b690:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1 
Max diff block lines reached; 1474733/1503327 bytes (98.10%) of diff not shown.
172 KB
html2text {}
    
Offset 103, 19 lines modifiedOffset 103, 14 lines modified
103 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3103 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
104 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)104 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
105 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3105 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5106 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
107 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199107 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
108 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79108 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2109 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
111 [[packages]] 
112 name·=·"aide" 
113 version·=·"*" 
114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
119 #·Remediation·is·applicable·only·in·certain·platforms115 #·Remediation·is·applicable·only·in·certain·platforms
120 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then116 if·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek;·then
Offset 159, 33 lines modifiedOffset 154, 38 lines modified
159 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy155 ··-·enable_strategy
161 ··-·low_complexity156 ··-·low_complexity
162 ··-·low_disruption157 ··-·low_disruption
163 ··-·medium_severity158 ··-·medium_severity
164 ··-·no_reboot_needed159 ··-·no_reboot_needed
165 ··-·package_aide_installed160 ··-·package_aide_installed
 161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 162 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 163 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 164 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 165 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 166 package·--add=aide
 167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 168 [[packages]]
 169 name·=·"aide"
 170 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
171 include·install_aide176 include·install_aide
  
172 class·install_aide·{177 class·install_aide·{
173 ··package·{·'aide':178 ··package·{·'aide':
174 ····ensure·=>·'installed',179 ····ensure·=>·'installed',
175 ··}180 ··}
176 }181 }
177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
182 package·--add=aide 
183 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*182 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·A\x8AI\x8ID\x8DE\x8E·t\x8to\x8o·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8he\x8e·A\x8Au\x8ud\x8di\x8it\x8t·T\x8To\x8oo\x8ol\x8ls\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
184 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.183 The·operating·system·file·integrity·tool·must·be·configured·to·protect·the·integrity·of·the·audit·tools.
185 Rationale:··Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward·ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,·audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information·system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source·audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and·records.·Audit·tools·include·custom·queries·and·report·generators.·It·is·not·uncommon·for·attackers·to·replace·the·audit·tools·or·inject·code·into·the·existing·tools·to·provide·the·capability·to·hide·or·erase·system·activity·from·the·audit·logs.·To·address·this·risk,·audit·tools·must·be·cryptographically·signed·to·provide·the·capability·to·identify·when·the·audit·tools·have·been·modified,·manipulated,·or·replaced.·An·example·is·a·checksum·hash·of·the·file·or·files.184 Rationale:··Protecting·the·integrity·of·the·tools·used·for·auditing·purposes·is·a·critical·step·toward·ensuring·the·integrity·of·audit·information.·Audit·information·includes·all·information·(e.g.,·audit·records,·audit·settings,·and·audit·reports)·needed·to·successfully·audit·information·system·activity.·Audit·tools·include·but·are·not·limited·to·vendor-provided·and·open-source·audit·tools·needed·to·successfully·view·and·manipulate·audit·information·system·activity·and·records.·Audit·tools·include·custom·queries·and·report·generators.·It·is·not·uncommon·for·attackers·to·replace·the·audit·tools·or·inject·code·into·the·existing·tools·to·provide·the·capability·to·hide·or·erase·system·activity·from·the·audit·logs.·To·address·this·risk,·audit·tools·must·be·cryptographically·signed·to·provide·the·capability·to·identify·when·the·audit·tools·have·been·modified,·manipulated,·or·replaced.·An·example·is·a·checksum·hash·of·the·file·or·files.
186 Severity: ··medium185 Severity: ··medium
187 Rule·ID:····xccdf_org.ssgproject.content_rule_aide_check_audit_tools186 Rule·ID:····xccdf_org.ssgproject.content_rule_aide_check_audit_tools
188 ············_\x8d_\x8i_\x8s_\x8a···CCI-001496,·CCI-001494,·CCI-001495,·CCI-001493187 ············_\x8d_\x8i_\x8s_\x8a···CCI-001496,·CCI-001494,·CCI-001495,·CCI-001493
189 References:·_\x8n_\x8i_\x8s_\x8t···AU-9(3),·AU-9(3).1188 References:·_\x8n_\x8i_\x8s_\x8t···AU-9(3),·AU-9(3).1
Offset 1914, 31 lines modifiedOffset 1914, 31 lines modified
1914 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode1914 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
1915 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008771915 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
1916 ············_\x8i_\x8s_\x8m······14461916 ············_\x8i_\x8s_\x8m······1446
1917 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11917 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1918 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121918 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1919 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11919 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1920 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761920 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1922 [customizations] 
1923 fips·=·true 
1924 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81921 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1925 #·Remediation·is·applicable·only·in·certain·platforms1922 #·Remediation·is·applicable·only·in·certain·platforms
1926 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then1923 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·||·rpm·--quiet·-q·kernel-uek·);·then
  
1927 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1924 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1928 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1925 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1929 kargs·=·["fips=1"]1926 kargs·=·["fips=1"]
1930 EOF1927 EOF
1931 fi1928 fi
  
1932 else1929 else
1933 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1930 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1934 fi1931 fi
 1932 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1933 [customizations]
 1934 fips·=·true
1935 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1935 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1936 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:1936 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·To·enable·FIPS·mode,·run·the·following·command:
1937 fips-mode-setup·--enable1937 fips-mode-setup·--enable
1938 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1938 To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1939 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1939 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1940 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1940 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1941 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1941 Rationale:··Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 1963, 19 lines modifiedOffset 1963, 14 lines modified
1963 $·sudo·yum·install·crypto-policies1963 $·sudo·yum·install·crypto-policies
1964 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.1964 Rationale:··Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
1965 Severity: ··medium1965 Severity: ··medium
1966 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed1966 Rule·ID:····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
1967 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-0031231967 ············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
1968 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.11968 References:·_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
1969 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001741969 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
1970 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1971 [[packages]] 
1972 name·=·"crypto-policies" 
1973 version·=·"*" 
1974 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81970 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1975 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1971 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1976 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1972 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1977 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1973 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1978 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1974 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1979 if·!·rpm·-q·--quiet·"crypto-policies"·;·then1975 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 1993, 33 lines modifiedOffset 1988, 38 lines modified
1993 ··tags:1988 ··tags:
1994 ··-·enable_strategy1989 ··-·enable_strategy
1995 ··-·low_complexity1990 ··-·low_complexity
1996 ··-·low_disruption1991 ··-·low_disruption
1997 ··-·medium_severity1992 ··-·medium_severity
Max diff block lines reached; 167507/176168 bytes (95.08%) of diff not shown.
492 KB
./usr/share/doc/ssg-nondebian/ssg-openembedded-guide-expanded.html
    
Offset 15092, 95 lines modifiedOffset 15092, 95 lines modified
0003af30:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm100003af30:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm10
0003af40:·3839·2220·7461·6269·6e64·6578·3d22·3022··89"·tabindex="0"0003af40:·3839·2220·7461·6269·6e64·6578·3d22·3022··89"·tabindex="0"
0003af50:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003af50:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003af60:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003af60:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003af70:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003af70:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003af80:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003af80:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003af90:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003af90:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0003afa0:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn
 0003afb0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br
 0003afc0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003afd0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003afe0:·6170·7365·2220·6964·3d22·6964·6d31·3038··apse"·id="idm108
 0003aff0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class=
 0003b000:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b010:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003b020:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003b030:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003b040:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003b050:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b060:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b070:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b080:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003b090:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003b0a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003b0b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b0c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003b0d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003b0e0:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam
 0003b0f0:·653a·2047·6174·6865·7220·7468·6520·7061··e:·Gather·the·pa
 0003b100:·636b·6167·6520·6661·6374·730a·2020·7061··ckage·facts.··pa
 0003b110:·636b·6167·655f·6661·6374·733a·0a20·2020··ckage_facts:.···
 0003b120:·206d·616e·6167·6572·3a20·6175·746f·0a20···manager:·auto.·
0003afa0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003afb0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003afc0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003afd0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003afe0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003aff0:·6964·3d22·6964·6d31·3038·3922·3e3c·7072··id="idm1089"><pr 
0003b000:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003b010:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003b020:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003b030:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003b040:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b050:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b060:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b070:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b080:·6574·3d22·2369·646d·3130·3930·2220·7461··et="#idm1090"·ta 
0003b090:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b0a0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b0b0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b0c0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b0d0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b0e0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b0f0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003b100:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b110:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b120:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b130:·6964·3d22·6964·6d31·3039·3022·3e3c·7461··id="idm1090"><ta 
0003b140:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b150:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b160:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b170:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b180:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b190:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b1a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b1b0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b1c0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b1d0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b1e0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b1f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b200:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b210:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b220:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b230:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat 
0003b240:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package· 
0003b250:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_ 
0003b260:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag 
0003b270:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags: 
0003b280:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1 
0003b290:·2e33·0a20·202d·204e·4953·542d·3830·302d··.3.··-·NIST-800- 
0003b2a0:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
0003b2b0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
0003b2c0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
0003b2d0:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
0003b2e0:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
0003b2f0:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
0003b300:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
0003b310:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
0003b320:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
0003b330:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
0003b340:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
0003b350:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu 
0003b360:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
0003b370:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
0003b380:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
0003b390:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
0003b3a0:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern 
0003b3b0:·656c·2220·696e·2061·6e73·6962·6c65·5f66··el"·in·ansible_f 
0003b3c0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
0003b3d0:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-0003b130:·2074·6167·733a·0a20·202d·2043·4a49·532d···tags:.··-·CJIS-
0003b3e0:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS0003b140:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS
0003b3f0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)0003b150:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
0003b400:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req0003b160:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
0003b410:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS0003b170:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
0003b420:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e0003b180:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e
0003b430:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.·0003b190:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.·
0003b440:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit0003b1a0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
0003b450:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup0003b1b0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup
0003b460:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_0003b1c0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
0003b470:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_0003b1d0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
0003b480:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··0003b1e0:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
0003b490:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i0003b1f0:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i
0003b4a0:·6e73·7461·6c6c·6564·0a3c·2f63·6f64·653e··nstalled.</code>0003b200:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name
 0003b210:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is
 0003b220:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac
 0003b230:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:·
 0003b240:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:·
 0003b250:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:·
 0003b260:·2722·6b65·726e·656c·2220·696e·2061·6e73··'"kernel"·in·ans
 0003b270:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
 0003b280:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-
 0003b290:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.·
 0003b2a0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
 0003b2b0:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D
 0003b2c0:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·
 0003b2d0:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2
 0003b2e0:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra
Max diff block lines reached; 457888/469644 bytes (97.50%) of diff not shown.
32.8 KB
html2text {}
    
Offset 120, 19 lines modifiedOffset 120, 14 lines modified
120 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3120 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
121 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)121 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3122 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79125 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2126 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
128 [[packages]] 
129 name·=·"aide" 
130 version·=·"*" 
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
136 -·name:·Gather·the·package·facts132 -·name:·Gather·the·package·facts
137 ··package_facts:133 ··package_facts:
Offset 161, 14 lines modifiedOffset 156, 19 lines modified
161 ··-·PCI-DSSv4-11.5.2156 ··-·PCI-DSSv4-11.5.2
162 ··-·enable_strategy157 ··-·enable_strategy
163 ··-·low_complexity158 ··-·low_complexity
164 ··-·low_disruption159 ··-·low_disruption
165 ··-·medium_severity160 ··-·medium_severity
166 ··-·no_reboot_needed161 ··-·no_reboot_needed
167 ··-·package_aide_installed162 ··-·package_aide_installed
 163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 164 [[packages]]
 165 name·=·"aide"
 166 version·=·"*"
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
173 include·install_aide172 include·install_aide
  
Offset 4493, 19 lines modifiedOffset 4493, 14 lines modified
4493 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed4493 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed
4494 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023224494 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
4495 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)4495 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
4496 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.14496 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
4497 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,4497 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,
4498 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-002324498 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
4499 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.24499 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
4500 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4501 [[packages]] 
4502 name·=·"firewalld" 
4503 version·=·"*" 
4504 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84500 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4505 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4501 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4506 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4502 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4507 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4503 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4508 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4504 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4509 -·name:·Gather·the·package·facts4505 -·name:·Gather·the·package·facts
4510 ··package_facts:4506 ··package_facts:
Offset 4532, 14 lines modifiedOffset 4527, 19 lines modified
4532 ··-·PCI-DSSv4-1.2.14527 ··-·PCI-DSSv4-1.2.1
4533 ··-·enable_strategy4528 ··-·enable_strategy
4534 ··-·low_complexity4529 ··-·low_complexity
4535 ··-·low_disruption4530 ··-·low_disruption
4536 ··-·medium_severity4531 ··-·medium_severity
4537 ··-·no_reboot_needed4532 ··-·no_reboot_needed
4538 ··-·package_firewalld_installed4533 ··-·package_firewalld_installed
 4534 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4535 [[packages]]
 4536 name·=·"firewalld"
 4537 version·=·"*"
4539 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84538 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4540 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4539 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4541 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4540 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4542 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4541 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4543 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4542 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4544 include·install_firewalld4543 include·install_firewalld
  
Offset 4567, 18 lines modifiedOffset 4567, 14 lines modified
4567 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)4567 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)
4568 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-14568 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
4569 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.14569 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
4570 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-4570 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-
4571 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-002324571 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
4572 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A214572 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
4573 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.24573 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
4574 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4575 [customizations.services] 
4576 enabled·=·["firewalld"] 
4577 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84574 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4578 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4575 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4579 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4576 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4580 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4577 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4581 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4578 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4582 -·name:·Gather·the·package·facts4579 -·name:·Gather·the·package·facts
4583 ··package_facts:4580 ··package_facts:
Offset 4630, 14 lines modifiedOffset 4626, 18 lines modified
4630 ··-·PCI-DSSv4-1.2.14626 ··-·PCI-DSSv4-1.2.1
4631 ··-·enable_strategy4627 ··-·enable_strategy
4632 ··-·low_complexity4628 ··-·low_complexity
4633 ··-·low_disruption4629 ··-·low_disruption
4634 ··-·medium_severity4630 ··-·medium_severity
4635 ··-·no_reboot_needed4631 ··-·no_reboot_needed
4636 ··-·service_firewalld_enabled4632 ··-·service_firewalld_enabled
 4633 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4634 [customizations.services]
 4635 enabled·=·["firewalld"]
4637 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84636 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4638 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4637 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4639 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4638 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4640 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4639 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4641 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4640 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4642 include·enable_firewalld4641 include·enable_firewalld
  
Offset 4667, 19 lines modifiedOffset 4667, 14 lines modified
4667 Rationale:··iptables·controls·the·Linux·kernel·network·packet·filtering·code.·iptables·allows·system4667 Rationale:··iptables·controls·the·Linux·kernel·network·packet·filtering·code.·iptables·allows·system
4668 ············operators·to·set·up·firewalls·and·IP·masquerading,·etc.4668 ············operators·to·set·up·firewalls·and·IP·masquerading,·etc.
4669 Severity: ··medium4669 Severity: ··medium
4670 Rule·ID:····xccdf_org.ssgproject.content_rule_package_iptables_installed4670 Rule·ID:····xccdf_org.ssgproject.content_rule_package_iptables_installed
4671 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)4671 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)
4672 References:·_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·Req-1.4.14672 References:·_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·Req-1.4.1
4673 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002274673 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
4674 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 28147/33514 bytes (83.99%) of diff not shown.
492 KB
./usr/share/doc/ssg-nondebian/ssg-openembedded-guide-standard.html
    
Offset 15087, 95 lines modifiedOffset 15087, 95 lines modified
0003aee0:·2d74·6172·6765·743d·2223·6964·6d31·3038··-target="#idm1080003aee0:·2d74·6172·6765·743d·2223·6964·6d31·3038··-target="#idm108
0003aef0:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·0003aef0:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·
0003af00:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003af00:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003af10:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003af10:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003af20:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003af20:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003af30:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003af30:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003af40:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003af40:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003af50:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
 0003af60:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003af70:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003af80:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003af90:·7073·6522·2069·643d·2269·646d·3130·3839··pse"·id="idm1089
 0003afa0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003afb0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003afc0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003afd0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003afe0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003aff0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b000:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b010:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b020:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b030:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b040:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b050:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b060:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b070:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b080:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b090:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
 0003b0a0:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac
 0003b0b0:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac
 0003b0c0:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.····
 0003b0d0:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.··
0003af50:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003af60:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003af70:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003af80:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003af90:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003afa0:·643d·2269·646d·3130·3839·223e·3c70·7265··d="idm1089"><pre 
0003afb0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003afc0:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003afd0:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003afe0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003aff0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b000:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b010:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b020:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b030:·743d·2223·6964·6d31·3039·3022·2074·6162··t="#idm1090"·tab 
0003b040:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b050:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b060:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b070:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b080:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b090:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b0a0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b0b0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b0c0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b0d0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b0e0:·643d·2269·646d·3130·3930·223e·3c74·6162··d="idm1090"><tab 
0003b0f0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b100:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b110:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b120:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b130:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b140:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b150:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b160:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b170:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b180:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b190:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b1a0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b1b0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b1c0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b1d0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b1e0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003b1f0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f 
0003b200:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f 
0003b210:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage 
0003b220:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:. 
0003b230:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003b240:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5 
0003b250:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC 
0003b260:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.· 
0003b270:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11. 
0003b280:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s 
0003b290:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_ 
0003b2a0:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l 
0003b2b0:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.·· 
0003b2c0:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit 
0003b2d0:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_ 
0003b2e0:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa 
0003b2f0:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe 
0003b300:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur 
0003b310:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal 
0003b320:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.· 
0003b330:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.·· 
0003b340:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present 
0003b350:·0a20·2077·6865·6e3a·2027·226b·6572·6e65··.··when:·'"kerne 
0003b360:·6c22·2069·6e20·616e·7369·626c·655f·6661··l"·in·ansible_fa 
0003b370:·6374·732e·7061·636b·6167·6573·270a·2020··cts.packages'.·· 
0003b380:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-50003b0e0:·7461·6773·3a0a·2020·2d20·434a·4953·2d35··tags:.··-·CJIS-5
0003b390:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST0003b0f0:·2e31·302e·312e·330a·2020·2d20·4e49·5354··.10.1.3.··-·NIST
0003b3a0:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a).0003b100:·2d38·3030·2d35·332d·434d·2d36·2861·290a··-800-53-CM-6(a).
0003b3b0:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-0003b110:·2020·2d20·5043·492d·4453·532d·5265·712d····-·PCI-DSS-Req-
0003b3c0:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS0003b120:·3131·2e35·0a20·202d·2050·4349·2d44·5353··11.5.··-·PCI-DSS
0003b3d0:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en0003b130:·7634·2d31·312e·352e·320a·2020·2d20·656e··v4-11.5.2.··-·en
0003b3e0:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.··0003b140:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.··
0003b3f0:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity0003b150:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity
0003b400:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt0003b160:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt
0003b410:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s0003b170:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s
0003b420:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r0003b180:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r
0003b430:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··-0003b190:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··-
0003b440:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in0003b1a0:·2070·6163·6b61·6765·5f61·6964·655f·696e···package_aide_in
0003b450:·7374·616c·6c65·640a·3c2f·636f·6465·3e3c··stalled.</code><0003b1b0:·7374·616c·6c65·640a·0a2d·206e·616d·653a··stalled..-·name:
 0003b1c0:·2045·6e73·7572·6520·6169·6465·2069·7320···Ensure·aide·is·
 0003b1d0:·696e·7374·616c·6c65·640a·2020·7061·636b··installed.··pack
 0003b1e0:·6167·653a·0a20·2020·206e·616d·653a·2061··age:.····name:·a
 0003b1f0:·6964·650a·2020·2020·7374·6174·653a·2070··ide.····state:·p
 0003b200:·7265·7365·6e74·0a20·2077·6865·6e3a·2027··resent.··when:·'
 0003b210:·226b·6572·6e65·6c22·2069·6e20·616e·7369··"kernel"·in·ansi
 0003b220:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
 0003b230:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·
 0003b240:·434a·4953·2d35·2e31·302e·312e·330a·2020··CJIS-5.10.1.3.··
 0003b250:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 0003b260:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
 0003b270:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
 0003b280:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
 0003b290:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
Max diff block lines reached; 458026/469782 bytes (97.50%) of diff not shown.
32.7 KB
html2text {}
    
Offset 118, 19 lines modifiedOffset 118, 14 lines modified
118 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3118 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)119 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3120 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5121 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199122 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
123 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79123 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2124 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
126 [[packages]] 
127 name·=·"aide" 
128 version·=·"*" 
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
134 -·name:·Gather·the·package·facts130 -·name:·Gather·the·package·facts
135 ··package_facts:131 ··package_facts:
Offset 159, 14 lines modifiedOffset 154, 19 lines modified
159 ··-·PCI-DSSv4-11.5.2154 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy155 ··-·enable_strategy
161 ··-·low_complexity156 ··-·low_complexity
162 ··-·low_disruption157 ··-·low_disruption
163 ··-·medium_severity158 ··-·medium_severity
164 ··-·no_reboot_needed159 ··-·no_reboot_needed
165 ··-·package_aide_installed160 ··-·package_aide_installed
 161 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 162 [[packages]]
 163 name·=·"aide"
 164 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
171 include·install_aide170 include·install_aide
  
Offset 4053, 19 lines modifiedOffset 4053, 14 lines modified
4053 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed4053 Rule·ID:····xccdf_org.ssgproject.content_rule_package_firewalld_installed
4054 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-0023224054 ············_\x8d_\x8i_\x8s_\x8a····CCI-000382,·CCI-000366,·CCI-002314,·CCI-002322
4055 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)4055 ············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
4056 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.14056 References:·_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
4057 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,4057 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000298-GPOS-00116,
4058 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-002324058 ····················SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00232
4059 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.24059 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
4060 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4061 [[packages]] 
4062 name·=·"firewalld" 
4063 version·=·"*" 
4064 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84060 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4065 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4061 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4066 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4062 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4067 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4063 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4068 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4064 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4069 -·name:·Gather·the·package·facts4065 -·name:·Gather·the·package·facts
4070 ··package_facts:4066 ··package_facts:
Offset 4092, 14 lines modifiedOffset 4087, 19 lines modified
4092 ··-·PCI-DSSv4-1.2.14087 ··-·PCI-DSSv4-1.2.1
4093 ··-·enable_strategy4088 ··-·enable_strategy
4094 ··-·low_complexity4089 ··-·low_complexity
4095 ··-·low_disruption4090 ··-·low_disruption
4096 ··-·medium_severity4091 ··-·medium_severity
4097 ··-·no_reboot_needed4092 ··-·no_reboot_needed
4098 ··-·package_firewalld_installed4093 ··-·package_firewalld_installed
 4094 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4095 [[packages]]
 4096 name·=·"firewalld"
 4097 version·=·"*"
4099 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84098 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4100 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4099 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4101 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4100 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4102 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4101 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4103 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4102 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4104 include·install_firewalld4103 include·install_firewalld
  
Offset 4127, 18 lines modifiedOffset 4127, 14 lines modified
4127 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)4127 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)
4128 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-14128 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
4129 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.14129 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
4130 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-4130 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-
4131 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-002324131 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
4132 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A214132 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
4133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.24133 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
4134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4135 [customizations.services] 
4136 enabled·=·["firewalld"] 
4137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4142 -·name:·Gather·the·package·facts4139 -·name:·Gather·the·package·facts
4143 ··package_facts:4140 ··package_facts:
Offset 4190, 14 lines modifiedOffset 4186, 18 lines modified
4190 ··-·PCI-DSSv4-1.2.14186 ··-·PCI-DSSv4-1.2.1
4191 ··-·enable_strategy4187 ··-·enable_strategy
4192 ··-·low_complexity4188 ··-·low_complexity
4193 ··-·low_disruption4189 ··-·low_disruption
4194 ··-·medium_severity4190 ··-·medium_severity
4195 ··-·no_reboot_needed4191 ··-·no_reboot_needed
4196 ··-·service_firewalld_enabled4192 ··-·service_firewalld_enabled
 4193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4194 [customizations.services]
 4195 enabled·=·["firewalld"]
4197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4202 include·enable_firewalld4201 include·enable_firewalld
  
Offset 4227, 19 lines modifiedOffset 4227, 14 lines modified
4227 Rationale:··iptables·controls·the·Linux·kernel·network·packet·filtering·code.·iptables·allows·system4227 Rationale:··iptables·controls·the·Linux·kernel·network·packet·filtering·code.·iptables·allows·system
4228 ············operators·to·set·up·firewalls·and·IP·masquerading,·etc.4228 ············operators·to·set·up·firewalls·and·IP·masquerading,·etc.
4229 Severity: ··medium4229 Severity: ··medium
4230 Rule·ID:····xccdf_org.ssgproject.content_rule_package_iptables_installed4230 Rule·ID:····xccdf_org.ssgproject.content_rule_package_iptables_installed
4231 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)4231 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)
4232 References:·_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·Req-1.4.14232 References:·_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·Req-1.4.1
4233 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-002274233 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000480-GPOS-00227
4234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 28091/33458 bytes (83.96%) of diff not shown.
358 KB
./usr/share/doc/ssg-nondebian/ssg-openeuler2203-guide-standard.html
    
Offset 15112, 95 lines modifiedOffset 15112, 95 lines modified
0003b070:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b070:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b080:·2223·6964·6d31·3134·3922·2074·6162·696e··"#idm1149"·tabin0003b080:·2223·6964·6d31·3134·3922·2074·6162·696e··"#idm1149"·tabin
0003b090:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b090:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b0a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b0a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b0b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b0b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b0c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b0c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b0d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b0d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b0e0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003b0e0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
 0003b0f0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
 0003b100:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b110:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b120:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b130:·2269·646d·3131·3439·223e·3c74·6162·6c65··"idm1149"><table
 0003b140:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003b150:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003b160:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003b170:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b180:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003b190:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b1a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b1b0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003b1c0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b1d0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003b1e0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003b1f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003b200:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003b0f0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003b100:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b110:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b120:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b130:·6c61·7073·6522·2069·643d·2269·646d·3131··lapse"·id="idm11 
0003b140:·3439·223e·3c70·7265·3e3c·636f·6465·3e0a··49"><pre><code>. 
0003b150:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003b160:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003b170:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003b180:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003b190:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003b1a0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003b1b0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003b1c0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
0003b1d0:·3135·3022·2074·6162·696e·6465·783d·2230··150"·tabindex="0 
0003b1e0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003b1f0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003b200:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003b210:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003b220:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003b230:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
0003b240:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b250:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b260:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b270:·6c61·7073·6522·2069·643d·2269·646d·3131··lapse"·id="idm11 
0003b280:·3530·223e·3c74·6162·6c65·2063·6c61·7373··50"><table·class 
0003b290:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003b2a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003b2b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003b2c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003b2d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003b2e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b2f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003b300:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003b310:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b320:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b330:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b210:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 0003b220:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 0003b230:·653e·2d20·6e61·6d65·3a20·4761·7468·6572··e>-·name:·Gather
 0003b240:·2074·6865·2070·6163·6b61·6765·2066·6163···the·package·fac
 0003b250:·7473·0a20·2070·6163·6b61·6765·5f66·6163··ts.··package_fac
 0003b260:·7473·3a0a·2020·2020·6d61·6e61·6765·723a··ts:.····manager:
0003b340:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b350:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b360:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b370:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na 
0003b380:·6d65·3a20·4761·7468·6572·2074·6865·2070··me:·Gather·the·p 
0003b390:·6163·6b61·6765·2066·6163·7473·0a20·2070··ackage·facts.··p 
0003b3a0:·6163·6b61·6765·5f66·6163·7473·3a0a·2020··ackage_facts:.·· 
0003b3b0:·2020·6d61·6e61·6765·723a·2061·7574·6f0a····manager:·auto. 
0003b3c0:·2020·7461·6773·3a0a·2020·2d20·434a·4953····tags:.··-·CJIS 
0003b3d0:·2d35·2e31·302e·312e·330a·2020·2d20·4e49··-5.10.1.3.··-·NI 
0003b3e0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a 
0003b3f0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re 
0003b400:·712d·3131·2e35·0a20·202d·2050·4349·2d44··q-11.5.··-·PCI-D 
0003b410:·5353·7634·2d31·312e·352e·320a·2020·2d20··SSv4-11.5.2.··-· 
0003b420:·656e·6162·6c65·5f73·7472·6174·6567·790a··enable_strategy. 
0003b430:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi 
0003b440:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru 
0003b450:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium 
0003b460:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no 
0003b470:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.· 
0003b480:·202d·2070·6163·6b61·6765·5f61·6964·655f···-·package_aide_ 
0003b490:·696e·7374·616c·6c65·640a·0a2d·206e·616d··installed..-·nam 
0003b4a0:·653a·2045·6e73·7572·6520·6169·6465·2069··e:·Ensure·aide·i 
0003b4b0:·7320·696e·7374·616c·6c65·640a·2020·7061··s·installed.··pa 
0003b4c0:·636b·6167·653a·0a20·2020·206e·616d·653a··ckage:.····name: 
0003b4d0:·2061·6964·650a·2020·2020·7374·6174·653a···aide.····state: 
0003b4e0:·2070·7265·7365·6e74·0a20·2077·6865·6e3a···present.··when: 
0003b4f0:·2027·226b·6572·6e65·6c22·2069·6e20·616e···'"kernel"·in·an 
0003b500:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack 
0003b510:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··0003b270:·2061·7574·6f0a·2020·7461·6773·3a0a·2020···auto.··tags:.··
0003b520:·2d20·434a·4953·2d35·2e31·302e·312e·330a··-·CJIS-5.10.1.3.0003b280:·2d20·434a·4953·2d35·2e31·302e·312e·330a··-·CJIS-5.10.1.3.
0003b530:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-0003b290:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
0003b540:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI-0003b2a0:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI-
0003b550:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-0003b2b0:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-
0003b560:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.0003b2c0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.
0003b570:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str0003b2d0:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str
0003b580:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co0003b2e0:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co
0003b590:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low0003b2f0:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low
0003b5a0:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·0003b300:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
0003b5b0:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.0003b310:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.
0003b5c0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne0003b320:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
0003b5d0:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package0003b330:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package
0003b5e0:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed.0003b340:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed.
 0003b350:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure·
 0003b360:·6169·6465·2069·7320·696e·7374·616c·6c65··aide·is·installe
 0003b370:·640a·2020·7061·636b·6167·653a·0a20·2020··d.··package:.···
 0003b380:·206e·616d·653a·2061·6964·650a·2020·2020···name:·aide.····
 0003b390:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
 0003b3a0:·2077·6865·6e3a·2027·226b·6572·6e65·6c22···when:·'"kernel"
 0003b3b0:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact
 0003b3c0:·732e·7061·636b·6167·6573·270a·2020·7461··s.packages'.··ta
 0003b3d0:·6773·3a0a·2020·2d20·434a·4953·2d35·2e31··gs:.··-·CJIS-5.1
 0003b3e0:·302e·312e·330a·2020·2d20·4e49·5354·2d38··0.1.3.··-·NIST-8
 0003b3f0:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).··
 0003b400:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11
 0003b410:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4
 0003b420:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab
 0003b430:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-·
 0003b440:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.·
Max diff block lines reached; 327234/338990 bytes (96.53%) of diff not shown.
27.0 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 14 lines modified
122 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3122 ···························A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
123 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)123 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
124 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3124 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199126 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79127 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 -·name:·Gather·the·package·facts134 -·name:·Gather·the·package·facts
139 ··package_facts:135 ··package_facts:
Offset 163, 14 lines modifiedOffset 158, 19 lines modified
163 ··-·PCI-DSSv4-11.5.2158 ··-·PCI-DSSv4-11.5.2
164 ··-·enable_strategy159 ··-·enable_strategy
165 ··-·low_complexity160 ··-·low_complexity
166 ··-·low_disruption161 ··-·low_disruption
167 ··-·medium_severity162 ··-·medium_severity
168 ··-·no_reboot_needed163 ··-·no_reboot_needed
169 ··-·package_aide_installed164 ··-·package_aide_installed
 165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 166 [[packages]]
 167 name·=·"aide"
 168 version·=·"*"
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
175 include·install_aide174 include·install_aide
  
Offset 4476, 18 lines modifiedOffset 4476, 14 lines modified
4476 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-0022354476 ············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
4477 ···················164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),4477 ···················164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),
4478 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.3104478 References:·_\x8h_\x8i_\x8p_\x8a_\x8a··164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310
4479 ···················(c),·164.310(d)(1),·164.310(d)(2)(iii)4479 ···················(c),·164.310(d)(1),·164.310(d)(2)(iii)
4480 ············_\x8n_\x8i_\x8s_\x8t···CM-64480 ············_\x8n_\x8i_\x8s_\x8t···CM-6
4481 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.14481 ············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
4482 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002274482 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
4483 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
4484 [customizations.services] 
4485 masked·=·["debug-shell"] 
4486 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84483 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4487 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4484 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4488 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4485 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4489 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4486 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4490 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable4487 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
4491 -·name:·Gather·the·package·facts4488 -·name:·Gather·the·package·facts
4492 ··package_facts:4489 ··package_facts:
Offset 4570, 14 lines modifiedOffset 4566, 18 lines modified
4570 ··-·NIST-800-53-CM-64566 ··-·NIST-800-53-CM-6
4571 ··-·disable_strategy4567 ··-·disable_strategy
4572 ··-·low_complexity4568 ··-·low_complexity
4573 ··-·low_disruption4569 ··-·low_disruption
4574 ··-·medium_severity4570 ··-·medium_severity
4575 ··-·no_reboot_needed4571 ··-·no_reboot_needed
4576 ··-·service_debug-shell_disabled4572 ··-·service_debug-shell_disabled
 4573 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 4574 [customizations.services]
 4575 masked·=·["debug-shell"]
4577 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x84576 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
4578 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low4577 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
4579 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low4578 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
4580 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false4579 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
4581 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable4580 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
4582 include·disable_debug-shell4581 include·disable_debug-shell
  
Offset 6018, 18 lines modifiedOffset 6018, 14 lines modified
6018 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,·SR6018 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,·SR
6019 ···························7.26019 ···························7.2
6020 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,6020 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,
6021 ···························A.15.2.1,·A.15.2.2,·A.17.2.16021 ···························A.15.2.1,·A.15.2.2,·A.17.2.1
6022 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)6022 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
6023 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-16023 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
6024 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002276024 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
6025 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6026 [customizations.services] 
6027 enabled·=·["rsyslog"] 
6028 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86025 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6029 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6026 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6030 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6027 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6031 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6028 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6032 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6029 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6033 -·name:·Gather·the·package·facts6030 -·name:·Gather·the·package·facts
6034 ··package_facts:6031 ··package_facts:
Offset 6065, 14 lines modifiedOffset 6061, 18 lines modified
6065 ··-·NIST-800-53-CM-6(a)6061 ··-·NIST-800-53-CM-6(a)
6066 ··-·enable_strategy6062 ··-·enable_strategy
6067 ··-·low_complexity6063 ··-·low_complexity
6068 ··-·low_disruption6064 ··-·low_disruption
6069 ··-·medium_severity6065 ··-·medium_severity
6070 ··-·no_reboot_needed6066 ··-·no_reboot_needed
6071 ··-·service_rsyslog_enabled6067 ··-·service_rsyslog_enabled
 6068 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 6069 [customizations.services]
 6070 enabled·=·["rsyslog"]
6072 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86071 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6073 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6072 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6074 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6073 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6075 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6074 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6076 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6075 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6077 include·enable_rsyslog6076 include·enable_rsyslog
  
Offset 6348, 18 lines modifiedOffset 6348, 14 lines modified
6348 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)6348 ············_\x8n_\x8i_\x8s_\x8t···········AC-4,·CM-7(b),·CA-3(5),·SC-7(21),·CM-6(a)
6349 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-16349 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1
6350 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.16350 ············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
6351 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-6351 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000096-GPOS-00050,·SRG-OS-000297-GPOS-00115,·SRG-OS-000480-GPOS-
6352 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-002326352 ···························00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
6353 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A216353 ············_\x8b_\x8s_\x8i············SYS.1.6.A5,·SYS.1.6.A21
6354 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.26354 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········1.2.1,·1.2
6355 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6356 [customizations.services] 
6357 enabled·=·["firewalld"] 
Max diff block lines reached; 22083/27626 bytes (79.94%) of diff not shown.
39.3 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-high-rev-4.html
    
Offset 19069, 66 lines modifiedOffset 19069, 66 lines modified
0004a7c0:·7461·7267·6574·3d22·2369·646d·3736·3334··target="#idm76340004a7c0:·7461·7267·6574·3d22·2369·646d·3736·3334··target="#idm7634
0004a7d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0004a7d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0004a7e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0004a7e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0004a7f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0004a7f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0004a800:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0004a800:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0004a810:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0004a810:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0004a820:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0004a820:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0004a830:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</0004a830:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s
 0004a840:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
0004a840:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0004a850:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0004a850:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0004a860:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0004a860:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0004a870:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm76
0004a870:·646d·3736·3334·223e·3c74·6162·6c65·2063··dm7634"><table·c0004a880:·3334·223e·3c74·6162·6c65·2063·6c61·7373··34"><table·class
0004a880:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0004a890:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0004a890:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0004a8a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0004a8a0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0004a8b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0004a8b0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0004a8c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0004a8c0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0004a8d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0004a8d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0004a8e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0004a8f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m 
0004a900:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><0004a8e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0004a8f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0004a900:·6e3a·3c2f·7468·3e3c·7464·3e6d·6564·6975··n:</th><td>mediu
 0004a910:·6d3c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··m</td></tr><tr><
0004a910:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</0004a920:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0004a920:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td>0004a930:·7464·3e74·7275·653c·2f74·643e·3c2f·7472··td>true</td></tr
0004a930:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0004a940:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
0004a940:·6174·6567·793a·3c2f·7468·3e3c·7464·3e64··ategy:</th><td>d0004a950:·793a·3c2f·7468·3e3c·7464·3e64·6973·6162··y:</th><td>disab
0004a950:·6973·6162·6c65·3c2f·7464·3e3c·2f74·723e··isable</td></tr>0004a960:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0004a960:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co0004a970:·626c·653e·3c70·7265·3e3c·636f·6465·3e61··ble><pre><code>a
0004a970:·6465·3e61·7069·5665·7273·696f·6e3a·206d··de>apiVersion:·m0004a980:·7069·5665·7273·696f·6e3a·206d·6163·6869··piVersion:·machi
0004a980:·6163·6869·6e65·636f·6e66·6967·7572·6174··achineconfigurat0004a990:·6e65·636f·6e66·6967·7572·6174·696f·6e2e··neconfiguration.
0004a990:·696f·6e2e·6f70·656e·7368·6966·742e·696f··ion.openshift.io0004a9a0:·6f70·656e·7368·6966·742e·696f·2f76·310a··openshift.io/v1.
0004a9a0:·2f76·310a·6b69·6e64·3a20·4d61·6368·696e··/v1.kind:·Machin0004a9b0:·6b69·6e64·3a20·4d61·6368·696e·6543·6f6e··kind:·MachineCon
0004a9b0:·6543·6f6e·6669·670a·7370·6563·3a0a·2020··eConfig.spec:.··0004a9c0:·6669·670a·7370·6563·3a0a·2020·636f·6e66··fig.spec:.··conf
0004a9c0:·636f·6e66·6967·3a0a·2020·2020·6967·6e69··config:.····igni0004a9d0:·6967·3a0a·2020·2020·6967·6e69·7469·6f6e··ig:.····ignition
0004a9d0:·7469·6f6e·3a0a·2020·2020·2020·7665·7273··tion:.······vers0004a9e0:·3a0a·2020·2020·2020·7665·7273·696f·6e3a··:.······version:
0004a9e0:·696f·6e3a·2033·2e31·2e30·0a20·2020·2073··ion:·3.1.0.····s0004a9f0:·2033·2e31·2e30·0a20·2020·2073·7973·7465···3.1.0.····syste
0004a9f0:·7973·7465·6d64·3a0a·2020·2020·2020·756e··ystemd:.······un0004aa00:·6d64·3a0a·2020·2020·2020·756e·6974·733a··md:.······units:
0004aa00:·6974·733a·0a20·2020·2020·202d·206e·616d··its:.······-·nam 
0004aa10:·653a·2064·6562·7567·2d73·6865·6c6c·2e73··e:·debug-shell.s 
0004aa20:·6572·7669·6365·0a20·2020·2020·2020·2065··ervice.········e 
0004aa30:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.·· 
0004aa40:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true 
0004aa50:·0a20·2020·2020·202d·206e·616d·653a·2064··.······-·name:·d0004aa10:·0a20·2020·2020·202d·206e·616d·653a·2064··.······-·name:·d
0004aa60:·6562·7567·2d73·6865·6c6c·2e73·6f63·6b65··ebug-shell.socke0004aa20:·6562·7567·2d73·6865·6c6c·2e73·6572·7669··ebug-shell.servi
 0004aa30:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl
 0004aa40:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······
 0004aa50:·2020·6d61·736b·3a20·7472·7565·0a20·2020····mask:·true.···
 0004aa60:·2020·202d·206e·616d·653a·2064·6562·7567·····-·name:·debug
 0004aa70:·2d73·6865·6c6c·2e73·6f63·6b65·740a·2020··-shell.socket.··
0004aa70:·740a·2020·2020·2020·2020·656e·6162·6c65··t.········enable0004aa80:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f
0004aa80:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.·······0004aa90:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas
0004aa90:·206d·6173·6b3a·2074·7275·650a·3c2f·636f···mask:·true.</co0004aaa0:·6b3a·2074·7275·650a·3c2f·636f·6465·3e3c··k:·true.</code><
0004aaa0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0004aab0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0004aab0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0004aac0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0004aac0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0004aad0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0004aad0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0004aae0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0004aae0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0004aaf0:·612d·7461·7267·6574·3d22·2369·646d·3736··a-target="#idm76
0004aaf0:·646d·3736·3335·2220·7461·6269·6e64·6578··dm7635"·tabindex0004ab00:·3335·2220·7461·6269·6e64·6578·3d22·3022··35"·tabindex="0"
0004ab00:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0004ab10:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0004ab10:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0004ab20:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0004ab20:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0004ab30:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0004ab30:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0004ab40:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0004ab40:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0004ab50:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
 0004ab60:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
0004ab50:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern 
0004ab60:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·... 
0004ab70:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0004ab70:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0004ab80:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0004ab80:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0004ab90:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0004ab90:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0004aba0:·2269·646d·3736·3335·223e·3c74·6162·6c65··"idm7635"><table0004aba0:·2269·646d·3736·3335·223e·3c74·6162·6c65··"idm7635"><table
0004abb0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0004abb0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0004abc0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0004abc0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0004abd0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0004abd0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
Offset 34734, 66 lines modifiedOffset 34734, 66 lines modified
00087ad0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00087ad0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00087ae0:·6d31·3833·3933·2220·7461·6269·6e64·6578··m18393"·tabindex00087ae0:·6d31·3833·3933·2220·7461·6269·6e64·6578··m18393"·tabindex
00087af0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00087af0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00087b00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00087b00:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00087b10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00087b10:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00087b20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00087b20:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00087b30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00087b30:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 00087b40:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern
 00087b50:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·...
 00087b60:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00087b70:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00087b80:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00087b90:·2269·646d·3138·3339·3322·3e3c·7461·626c··"idm18393"><tabl
 00087ba0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 00087bb0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 00087bc0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 00087bd0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 00087be0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 00087bf0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00087c00:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00087c10:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00087c20:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
 00087c30:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 00087c40:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
 00087c50:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00087c60:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 00087c70:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></
 00087c80:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 00087c90:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion
 00087ca0:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu
 00087cb0:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift
 00087cc0:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac
 00087cd0:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:
 00087ce0:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i
 00087cf0:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v
 00087d00:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··
 00087d10:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····
 00087d20:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·
 00087d30:·6e61·6d65·3a20·626c·7565·746f·6f74·682e··name:·bluetooth.
 00087d40:·7365·7276·6963·650a·2020·2020·2020·2020··service.········
 00087d50:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.·
 00087d60:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru
 00087d70:·650a·2020·2020·2020·2d20·6e61·6d65·3a20··e.······-·name:·
 00087d80:·626c·7565·746f·6f74·682e·736f·636b·6574··bluetooth.socket
 00087d90:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled
 00087da0:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········
 00087db0:·6d61·736b·3a20·7472·7565·0a3c·2f63·6f64··mask:·true.</cod
 00087dc0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 00087dd0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 00087de0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
Max diff block lines reached; 16750/32672 bytes (51.27%) of diff not shown.
7.24 KB
html2text {}
    
Offset 432, 15 lines modifiedOffset 432, 15 lines modified
432 Identifiers:·CCE-82496-1432 Identifiers:·CCE-82496-1
433 ·············_\x8c_\x8u_\x8i····3.4.5433 ·············_\x8c_\x8u_\x8i····3.4.5
434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
444 apiVersion:·machineconfiguration.openshift.io/v1444 apiVersion:·machineconfiguration.openshift.io/v1
445 kind:·MachineConfig445 kind:·MachineConfig
446 spec:446 spec:
Offset 451, 15 lines modifiedOffset 451, 15 lines modified
451 ······units:451 ······units:
452 ······-·name:·debug-shell.service452 ······-·name:·debug-shell.service
453 ········enabled:·false453 ········enabled:·false
454 ········mask:·true454 ········mask:·true
455 ······-·name:·debug-shell.socket455 ······-·name:·debug-shell.socket
456 ········enabled:·false456 ········enabled:·false
457 ········mask:·true457 ········mask:·true
458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
463 apiVersion:·machineconfiguration.openshift.io/v1463 apiVersion:·machineconfiguration.openshift.io/v1
464 kind:·MachineConfig464 kind:·MachineConfig
465 spec:465 spec:
Offset 1881, 15 lines modifiedOffset 1881, 15 lines modified
1881 ············_\x8c_\x8u_\x8i············3.1.161881 ············_\x8c_\x8u_\x8i············3.1.16
1882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1893 apiVersion:·machineconfiguration.openshift.io/v11893 apiVersion:·machineconfiguration.openshift.io/v1
1894 kind:·MachineConfig1894 kind:·MachineConfig
1895 spec:1895 spec:
Offset 1900, 15 lines modifiedOffset 1900, 15 lines modified
1900 ······units:1900 ······units:
1901 ······-·name:·bluetooth.service1901 ······-·name:·bluetooth.service
1902 ········enabled:·false1902 ········enabled:·false
1903 ········mask:·true1903 ········mask:·true
1904 ······-·name:·bluetooth.socket1904 ······-·name:·bluetooth.socket
1905 ········enabled:·false1905 ········enabled:·false
1906 ········mask:·true1906 ········mask:·true
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1912 apiVersion:·machineconfiguration.openshift.io/v11912 apiVersion:·machineconfiguration.openshift.io/v1
1913 kind:·MachineConfig1913 kind:·MachineConfig
1914 spec:1914 spec:
Offset 2218, 15 lines modifiedOffset 2218, 15 lines modified
2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2230 apiVersion:·machineconfiguration.openshift.io/v12230 apiVersion:·machineconfiguration.openshift.io/v1
2231 kind:·MachineConfig2231 kind:·MachineConfig
2232 spec:2232 spec:
Offset 2237, 15 lines modifiedOffset 2237, 15 lines modified
2237 ······units:2237 ······units:
2238 ······-·name:·autofs.service2238 ······-·name:·autofs.service
2239 ········enabled:·false2239 ········enabled:·false
2240 ········mask:·true2240 ········mask:·true
2241 ······-·name:·autofs.socket2241 ······-·name:·autofs.socket
2242 ········enabled:·false2242 ········enabled:·false
2243 ········mask:·true2243 ········mask:·true
2244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2249 apiVersion:·machineconfiguration.openshift.io/v12249 apiVersion:·machineconfiguration.openshift.io/v1
2250 kind:·MachineConfig2250 kind:·MachineConfig
2251 spec:2251 spec:
Offset 3587, 15 lines modifiedOffset 3587, 15 lines modified
3587 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.3587 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
3588 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.3588 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
3589 Severity: ···high3589 Severity: ···high
3590 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled3590 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
3591 Identifiers:·CCE-86189-83591 Identifiers:·CCE-86189-8
3592 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)3592 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
3593 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-0010303593 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
3594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x83594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
3595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3599 apiVersion:·machineconfiguration.openshift.io/v13599 apiVersion:·machineconfiguration.openshift.io/v1
3600 kind:·MachineConfig3600 kind:·MachineConfig
3601 spec:3601 spec:
Offset 3606, 15 lines modifiedOffset 3606, 15 lines modified
3606 ······units:3606 ······units:
3607 ······-·name:·sshd.service3607 ······-·name:·sshd.service
3608 ········enabled:·false3608 ········enabled:·false
3609 ········mask:·true3609 ········mask:·true
3610 ······-·name:·sshd.socket3610 ······-·name:·sshd.socket
3611 ········enabled:·false3611 ········enabled:·false
3612 ········mask:·true3612 ········mask:·true
3613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x83613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
3614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3618 apiVersion:·machineconfiguration.openshift.io/v13618 apiVersion:·machineconfiguration.openshift.io/v1
3619 kind:·MachineConfig3619 kind:·MachineConfig
3620 spec:3620 spec:
Max diff block lines reached; -1/7394 bytes (-0.01%) of diff not shown.
39.3 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-high.html
    
Offset 19068, 67 lines modifiedOffset 19068, 67 lines modified
0004a7b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0004a7b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0004a7c0:·3d22·2369·646d·3736·3334·2220·7461·6269··="#idm7634"·tabi0004a7c0:·3d22·2369·646d·3736·3334·2220·7461·6269··="#idm7634"·tabi
0004a7d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0004a7d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0004a7e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0004a7e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0004a7f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0004a7f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0004a800:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0004a800:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0004a810:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0004a810:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0004a820:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc0004a820:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
 0004a830:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
0004a830:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0004a840:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0004a840:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0004a850:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0004a850:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0004a860:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0004a860:·7073·6522·2069·643d·2269·646d·3736·3334··pse"·id="idm76340004a870:·2069·643d·2269·646d·3736·3334·223e·3c74···id="idm7634"><t
0004a870:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0004a880:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0004a880:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0004a890:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0004a890:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0004a8a0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0004a8a0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0004a8b0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0004a8b0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0004a8c0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0004a8c0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0004a8d0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0004a8d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0004a8e0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0004a8f0:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium< 
0004a900:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0004a8e0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0004a8f0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0004a900:·3e3c·7464·3e6d·6564·6975·6d3c·2f74·643e··><td>medium</td>
 0004a910:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0004a910:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0004a920:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru
0004a920:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><0004a930:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0004a930:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0004a940:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0004a940:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable0004a950:·3e3c·7464·3e64·6973·6162·6c65·3c2f·7464··><td>disable</td
0004a950:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0004a960:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
0004a960:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api0004a970:·7265·3e3c·636f·6465·3e61·7069·5665·7273··re><code>apiVers
0004a970:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine0004a980:·696f·6e3a·206d·6163·6869·6e65·636f·6e66··ion:·machineconf
0004a980:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op0004a990:·6967·7572·6174·696f·6e2e·6f70·656e·7368··iguration.opensh
0004a990:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki0004a9a0:·6966·742e·696f·2f76·310a·6b69·6e64·3a20··ift.io/v1.kind:·
0004a9a0:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi0004a9b0:·4d61·6368·696e·6543·6f6e·6669·670a·7370··MachineConfig.sp
0004a9b0:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config0004a9c0:·6563·3a0a·2020·636f·6e66·6967·3a0a·2020··ec:.··config:.··
0004a9c0:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.0004a9d0:·2020·6967·6e69·7469·6f6e·3a0a·2020·2020····ignition:.····
0004a9d0:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·30004a9e0:·2020·7665·7273·696f·6e3a·2033·2e31·2e30····version:·3.1.0
0004a9e0:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd0004a9f0:·0a20·2020·2073·7973·7465·6d64·3a0a·2020··.····systemd:.··
0004a9f0:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·0004aa00:·2020·2020·756e·6974·733a·0a20·2020·2020······units:.·····
0004aa00:·2020·2020·202d·206e·616d·653a·2064·6562·······-·name:·deb 
0004aa10:·7567·2d73·6865·6c6c·2e73·6572·7669·6365··ug-shell.service 
0004aa20:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled 
0004aa30:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········ 
0004aa40:·6d61·736b·3a20·7472·7565·0a20·2020·2020··mask:·true.····· 
0004aa50:·202d·206e·616d·653a·2064·6562·7567·2d73···-·name:·debug-s0004aa10:·202d·206e·616d·653a·2064·6562·7567·2d73···-·name:·debug-s
0004aa60:·6865·6c6c·2e73·6f63·6b65·740a·2020·2020··hell.socket.····0004aa20:·6865·6c6c·2e73·6572·7669·6365·0a20·2020··hell.service.···
0004aa70:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal0004aa30:·2020·2020·2065·6e61·626c·6564·3a20·6661·······enabled:·fa
0004aa80:·7365·0a20·2020·2020·2020·206d·6173·6b3a··se.········mask:0004aa40:·6c73·650a·2020·2020·2020·2020·6d61·736b··lse.········mask
 0004aa50:·3a20·7472·7565·0a20·2020·2020·202d·206e··:·true.······-·n
 0004aa60:·616d·653a·2064·6562·7567·2d73·6865·6c6c··ame:·debug-shell
 0004aa70:·2e73·6f63·6b65·740a·2020·2020·2020·2020··.socket.········
 0004aa80:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.·
 0004aa90:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru
0004aa90:·2074·7275·650a·3c2f·636f·6465·3e3c·2f70···true.</code></p0004aaa0:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
0004aaa0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0004aab0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0004aab0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0004aac0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0004aac0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0004aad0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0004aad0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0004aae0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0004aae0:·7461·7267·6574·3d22·2369·646d·3736·3335··target="#idm76350004aaf0:·6574·3d22·2369·646d·3736·3335·2220·7461··et="#idm7635"·ta
0004aaf0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0004ab00:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0004ab00:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0004ab10:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0004ab10:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0004ab20:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0004ab20:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0004ab30:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0004ab30:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0004ab40:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0004ab40:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0004ab50:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0004ab50:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s 
0004ab60:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b0004ab60:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
0004ab70:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0004ab70:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0004ab80:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0004ab80:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0004ab90:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm760004ab90:·6c61·7073·6522·2069·643d·2269·646d·3736··lapse"·id="idm76
0004aba0:·3335·223e·3c74·6162·6c65·2063·6c61·7373··35"><table·class0004aba0:·3335·223e·3c74·6162·6c65·2063·6c61·7373··35"><table·class
0004abb0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0004abb0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0004abc0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0004abc0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0004abd0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0004abd0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
Offset 34734, 66 lines modifiedOffset 34734, 66 lines modified
00087ad0:·6172·6765·743d·2223·6964·6d31·3833·3933··arget="#idm1839300087ad0:·6172·6765·743d·2223·6964·6d31·3833·3933··arget="#idm18393
00087ae0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r00087ae0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
00087af0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari00087af0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
00087b00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals00087b00:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
00087b10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa00087b10:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
00087b20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr00087b20:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
00087b30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat00087b30:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 00087b40:·696f·6e20·4b75·6265·726e·6574·6573·2073··ion·Kubernetes·s
 00087b50:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 00087b60:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00087b70:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00087b80:·6c61·7073·6522·2069·643d·2269·646d·3138··lapse"·id="idm18
 00087b90:·3339·3322·3e3c·7461·626c·6520·636c·6173··393"><table·clas
 00087ba0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00087bb0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00087bc0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 00087bd0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 00087be0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 00087bf0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00087c00:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 00087c10:·6f6e·3a3c·2f74·683e·3c74·643e·6d65·6469··on:</th><td>medi
 00087c20:·756d·3c2f·7464·3e3c·2f74·723e·3c74·723e··um</td></tr><tr>
 00087c30:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 00087c40:·3c74·643e·7472·7565·3c2f·7464·3e3c·2f74··<td>true</td></t
 00087c50:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00087c60:·6779·3a3c·2f74·683e·3c74·643e·6469·7361··gy:</th><td>disa
 00087c70:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 00087c80:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 00087c90:·6170·6956·6572·7369·6f6e·3a20·6d61·6368··apiVersion:·mach
 00087ca0:·696e·6563·6f6e·6669·6775·7261·7469·6f6e··ineconfiguration
 00087cb0:·2e6f·7065·6e73·6869·6674·2e69·6f2f·7631··.openshift.io/v1
 00087cc0:·0a6b·696e·643a·204d·6163·6869·6e65·436f··.kind:·MachineCo
 00087cd0:·6e66·6967·0a73·7065·633a·0a20·2063·6f6e··nfig.spec:.··con
 00087ce0:·6669·673a·0a20·2020·2069·676e·6974·696f··fig:.····ignitio
 00087cf0:·6e3a·0a20·2020·2020·2076·6572·7369·6f6e··n:.······version
 00087d00:·3a20·332e·312e·300a·2020·2020·7379·7374··:·3.1.0.····syst
 00087d10:·656d·643a·0a20·2020·2020·2075·6e69·7473··emd:.······units
 00087d20:·3a0a·2020·2020·2020·2d20·6e61·6d65·3a20··:.······-·name:·
 00087d30:·626c·7565·746f·6f74·682e·7365·7276·6963··bluetooth.servic
 00087d40:·650a·2020·2020·2020·2020·656e·6162·6c65··e.········enable
 00087d50:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.·······
 00087d60:·206d·6173·6b3a·2074·7275·650a·2020·2020···mask:·true.····
 00087d70:·2020·2d20·6e61·6d65·3a20·626c·7565·746f····-·name:·blueto
 00087d80:·6f74·682e·736f·636b·6574·0a20·2020·2020··oth.socket.·····
 00087d90:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals
 00087da0:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:·
 00087db0:·7472·7565·0a3c·2f63·6f64·653e·3c2f·7072··true.</code></pr
 00087dc0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
 00087dd0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
 00087de0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
Max diff block lines reached; 16612/32672 bytes (50.84%) of diff not shown.
7.24 KB
html2text {}
    
Offset 432, 15 lines modifiedOffset 432, 15 lines modified
432 Identifiers:·CCE-82496-1432 Identifiers:·CCE-82496-1
433 ·············_\x8c_\x8u_\x8i····3.4.5433 ·············_\x8c_\x8u_\x8i····3.4.5
434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
444 apiVersion:·machineconfiguration.openshift.io/v1444 apiVersion:·machineconfiguration.openshift.io/v1
445 kind:·MachineConfig445 kind:·MachineConfig
446 spec:446 spec:
Offset 451, 15 lines modifiedOffset 451, 15 lines modified
451 ······units:451 ······units:
452 ······-·name:·debug-shell.service452 ······-·name:·debug-shell.service
453 ········enabled:·false453 ········enabled:·false
454 ········mask:·true454 ········mask:·true
455 ······-·name:·debug-shell.socket455 ······-·name:·debug-shell.socket
456 ········enabled:·false456 ········enabled:·false
457 ········mask:·true457 ········mask:·true
458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
463 apiVersion:·machineconfiguration.openshift.io/v1463 apiVersion:·machineconfiguration.openshift.io/v1
464 kind:·MachineConfig464 kind:·MachineConfig
465 spec:465 spec:
Offset 1881, 15 lines modifiedOffset 1881, 15 lines modified
1881 ············_\x8c_\x8u_\x8i············3.1.161881 ············_\x8c_\x8u_\x8i············3.1.16
1882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1893 apiVersion:·machineconfiguration.openshift.io/v11893 apiVersion:·machineconfiguration.openshift.io/v1
1894 kind:·MachineConfig1894 kind:·MachineConfig
1895 spec:1895 spec:
Offset 1900, 15 lines modifiedOffset 1900, 15 lines modified
1900 ······units:1900 ······units:
1901 ······-·name:·bluetooth.service1901 ······-·name:·bluetooth.service
1902 ········enabled:·false1902 ········enabled:·false
1903 ········mask:·true1903 ········mask:·true
1904 ······-·name:·bluetooth.socket1904 ······-·name:·bluetooth.socket
1905 ········enabled:·false1905 ········enabled:·false
1906 ········mask:·true1906 ········mask:·true
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1912 apiVersion:·machineconfiguration.openshift.io/v11912 apiVersion:·machineconfiguration.openshift.io/v1
1913 kind:·MachineConfig1913 kind:·MachineConfig
1914 spec:1914 spec:
Offset 2218, 15 lines modifiedOffset 2218, 15 lines modified
2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2230 apiVersion:·machineconfiguration.openshift.io/v12230 apiVersion:·machineconfiguration.openshift.io/v1
2231 kind:·MachineConfig2231 kind:·MachineConfig
2232 spec:2232 spec:
Offset 2237, 15 lines modifiedOffset 2237, 15 lines modified
2237 ······units:2237 ······units:
2238 ······-·name:·autofs.service2238 ······-·name:·autofs.service
2239 ········enabled:·false2239 ········enabled:·false
2240 ········mask:·true2240 ········mask:·true
2241 ······-·name:·autofs.socket2241 ······-·name:·autofs.socket
2242 ········enabled:·false2242 ········enabled:·false
2243 ········mask:·true2243 ········mask:·true
2244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2249 apiVersion:·machineconfiguration.openshift.io/v12249 apiVersion:·machineconfiguration.openshift.io/v1
2250 kind:·MachineConfig2250 kind:·MachineConfig
2251 spec:2251 spec:
Offset 3587, 15 lines modifiedOffset 3587, 15 lines modified
3587 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.3587 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
3588 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.3588 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
3589 Severity: ···high3589 Severity: ···high
3590 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled3590 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
3591 Identifiers:·CCE-86189-83591 Identifiers:·CCE-86189-8
3592 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)3592 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
3593 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-0010303593 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
3594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x83594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
3595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3599 apiVersion:·machineconfiguration.openshift.io/v13599 apiVersion:·machineconfiguration.openshift.io/v1
3600 kind:·MachineConfig3600 kind:·MachineConfig
3601 spec:3601 spec:
Offset 3606, 15 lines modifiedOffset 3606, 15 lines modified
3606 ······units:3606 ······units:
3607 ······-·name:·sshd.service3607 ······-·name:·sshd.service
3608 ········enabled:·false3608 ········enabled:·false
3609 ········mask:·true3609 ········mask:·true
3610 ······-·name:·sshd.socket3610 ······-·name:·sshd.socket
3611 ········enabled:·false3611 ········enabled:·false
3612 ········mask:·true3612 ········mask:·true
3613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x83613 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
3614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3614 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium3615 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
3616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true3616 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
3617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3617 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3618 apiVersion:·machineconfiguration.openshift.io/v13618 apiVersion:·machineconfiguration.openshift.io/v1
3619 kind:·MachineConfig3619 kind:·MachineConfig
3620 spec:3620 spec:
Max diff block lines reached; -1/7394 bytes (-0.01%) of diff not shown.
29.6 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-moderate-rev-4.html
    
Offset 19070, 66 lines modifiedOffset 19070, 66 lines modified
0004a7d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0004a7d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0004a7e0:·3736·3334·2220·7461·6269·6e64·6578·3d22··7634"·tabindex="0004a7e0:·3736·3334·2220·7461·6269·6e64·6578·3d22··7634"·tabindex="
0004a7f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0004a7f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0004a800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0004a800:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0004a810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0004a810:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0004a820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0004a820:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0004a830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0004a830:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0004a840:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.0004a840:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
 0004a850:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
0004a850:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0004a860:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0004a860:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0004a870:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0004a870:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0004a880:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0004a880:·643d·2269·646d·3736·3334·223e·3c74·6162··d="idm7634"><tab0004a890:·646d·3736·3334·223e·3c74·6162·6c65·2063··dm7634"><table·c
0004a890:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0004a8a0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0004a8a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0004a8b0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0004a8b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0004a8c0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0004a8c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0004a8d0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0004a8d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0004a8e0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0004a8e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0004a8f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0004a900:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0004a910:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6d··ption:</th><td>m
 0004a920:·6564·6975·6d3c·2f74·643e·3c2f·7472·3e3c··edium</td></tr><
 0004a930:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0004a940:·7468·3e3c·7464·3e74·7275·653c·2f74·643e··th><td>true</td>
0004a8f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0004a950:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0004a900:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0004a910:·7464·3e6d·6564·6975·6d3c·2f74·643e·3c2f··td>medium</td></ 
0004a920:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0004a930:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true< 
0004a940:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0004a950:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0004a960:·6174·6567·793a·3c2f·7468·3e3c·7464·3e64··ategy:</th><td>d
0004a960:·7464·3e64·6973·6162·6c65·3c2f·7464·3e3c··td>disable</td><0004a970:·6973·6162·6c65·3c2f·7464·3e3c·2f74·723e··isable</td></tr>
0004a970:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0004a980:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0004a980:·3e3c·636f·6465·3e61·7069·5665·7273·696f··><code>apiVersio0004a990:·6465·3e61·7069·5665·7273·696f·6e3a·206d··de>apiVersion:·m
0004a990:·6e3a·206d·6163·6869·6e65·636f·6e66·6967··n:·machineconfig0004a9a0:·6163·6869·6e65·636f·6e66·6967·7572·6174··achineconfigurat
0004a9a0:·7572·6174·696f·6e2e·6f70·656e·7368·6966··uration.openshif0004a9b0:·696f·6e2e·6f70·656e·7368·6966·742e·696f··ion.openshift.io
0004a9b0:·742e·696f·2f76·310a·6b69·6e64·3a20·4d61··t.io/v1.kind:·Ma0004a9c0:·2f76·310a·6b69·6e64·3a20·4d61·6368·696e··/v1.kind:·Machin
0004a9c0:·6368·696e·6543·6f6e·6669·670a·7370·6563··chineConfig.spec0004a9d0:·6543·6f6e·6669·670a·7370·6563·3a0a·2020··eConfig.spec:.··
0004a9d0:·3a0a·2020·636f·6e66·6967·3a0a·2020·2020··:.··config:.····0004a9e0:·636f·6e66·6967·3a0a·2020·2020·6967·6e69··config:.····igni
0004a9e0:·6967·6e69·7469·6f6e·3a0a·2020·2020·2020··ignition:.······0004a9f0:·7469·6f6e·3a0a·2020·2020·2020·7665·7273··tion:.······vers
0004a9f0:·7665·7273·696f·6e3a·2033·2e31·2e30·0a20··version:·3.1.0.·0004aa00:·696f·6e3a·2033·2e31·2e30·0a20·2020·2073··ion:·3.1.0.····s
0004aa00:·2020·2073·7973·7465·6d64·3a0a·2020·2020·····systemd:.····0004aa10:·7973·7465·6d64·3a0a·2020·2020·2020·756e··ystemd:.······un
0004aa10:·2020·756e·6974·733a·0a20·2020·2020·202d····units:.······- 
0004aa20:·206e·616d·653a·2064·6562·7567·2d73·6865···name:·debug-she 
0004aa30:·6c6c·2e73·6572·7669·6365·0a20·2020·2020··ll.service.····· 
0004aa40:·2020·2065·6e61·626c·6564·3a20·6661·6c73·····enabled:·fals 
0004aa50:·650a·2020·2020·2020·2020·6d61·736b·3a20··e.········mask:· 
0004aa60:·7472·7565·0a20·2020·2020·202d·206e·616d··true.······-·nam0004aa20:·6974·733a·0a20·2020·2020·202d·206e·616d··its:.······-·nam
0004aa70:·653a·2064·6562·7567·2d73·6865·6c6c·2e73··e:·debug-shell.s0004aa30:·653a·2064·6562·7567·2d73·6865·6c6c·2e73··e:·debug-shell.s
0004aa80:·6f63·6b65·740a·2020·2020·2020·2020·656e··ocket.········en0004aa40:·6572·7669·6365·0a20·2020·2020·2020·2065··ervice.········e
0004aa90:·6162·6c65·643a·2066·616c·7365·0a20·2020··abled:·false.···0004aa50:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.··
0004aaa0:·2020·2020·206d·6173·6b3a·2074·7275·650a·······mask:·true.0004aa60:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true
 0004aa70:·0a20·2020·2020·202d·206e·616d·653a·2064··.······-·name:·d
 0004aa80:·6562·7567·2d73·6865·6c6c·2e73·6f63·6b65··ebug-shell.socke
 0004aa90:·740a·2020·2020·2020·2020·656e·6162·6c65··t.········enable
 0004aaa0:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.·······
 0004aab0:·206d·6173·6b3a·2074·7275·650a·3c2f·636f···mask:·true.</co
0004aab0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0004aac0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0004aac0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0004aad0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0004aad0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0004aae0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0004aae0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0004aaf0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0004aaf0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0004ab00:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0004ab00:·3d22·2369·646d·3736·3335·2220·7461·6269··="#idm7635"·tabi0004ab10:·646d·3736·3335·2220·7461·6269·6e64·6578··dm7635"·tabindex
0004ab10:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0004ab20:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0004ab20:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0004ab30:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0004ab30:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0004ab40:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0004ab40:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0004ab50:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0004ab50:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0004ab60:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0004ab70:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
0004ab60:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku 
0004ab70:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet 
0004ab80:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0004ab80:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0004ab90:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0004ab90:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0004aba0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0004aba0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0004abb0:·2069·643d·2269·646d·3736·3335·223e·3c74···id="idm7635"><t0004abb0:·2069·643d·2269·646d·3736·3335·223e·3c74···id="idm7635"><t
0004abc0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0004abc0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0004abd0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0004abd0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0004abe0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0004abe0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
Offset 34735, 67 lines modifiedOffset 34735, 67 lines modified
00087ae0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00087ae0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00087af0:·2223·6964·6d31·3833·3933·2220·7461·6269··"#idm18393"·tabi00087af0:·2223·6964·6d31·3833·3933·2220·7461·6269··"#idm18393"·tabi
00087b00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00087b00:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00087b10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00087b10:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00087b20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00087b20:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00087b30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00087b30:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00087b40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00087b40:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00087b50:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc00087b50:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
 00087b60:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
00087b60:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>00087b70:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
00087b70:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane00087b80:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
00087b80:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla00087b90:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
00087b90:·7073·6522·2069·643d·2269·646d·3138·3339··pse"·id="idm183900087ba0:·2069·643d·2269·646d·3138·3339·3322·3e3c···id="idm18393"><
00087ba0:·3322·3e3c·7461·626c·6520·636c·6173·733d··3"><table·class=00087bb0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
00087bb0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str00087bc0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
00087bc0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde00087bd0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
00087bd0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden00087be0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
00087be0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com00087bf0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
00087bf0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td00087c00:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
00087c00:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00087c10:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00087c20:·3a3c·2f74·683e·3c74·643e·6d65·6469·756d··:</th><td>medium 
00087c30:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00087c10:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00087c20:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 00087c30:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td
 00087c40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
00087c40:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t00087c50:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr
00087c50:·643e·7472·7565·3c2f·7464·3e3c·2f74·723e··d>true</td></tr>00087c60:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr>
00087c60:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy00087c70:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
00087c70:·3a3c·2f74·683e·3c74·643e·6469·7361·626c··:</th><td>disabl00087c80:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t
00087c80:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab00087c90:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
00087c90:·6c65·3e3c·7072·653e·3c63·6f64·653e·6170··le><pre><code>ap00087ca0:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer
00087ca0:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin00087cb0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon
00087cb0:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o00087cc0:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens
00087cc0:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k00087cd0:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:
00087cd0:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf00087ce0:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s
00087ce0:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi00087cf0:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.·
00087cf0:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition:00087d00:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.···
00087d00:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:·00087d10:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1.
00087d10:·332e·312e·300a·2020·2020·7379·7374·656d··3.1.0.····system00087d20:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.·
00087d20:·643a·0a20·2020·2020·2075·6e69·7473·3a0a··d:.······units:.00087d30:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.····
00087d30:·2020·2020·2020·2d20·6e61·6d65·3a20·626c········-·name:·bl 
00087d40:·7565·746f·6f74·682e·7365·7276·6963·650a··uetooth.service. 
00087d50:·2020·2020·2020·2020·656e·6162·6c65·643a··········enabled: 
00087d60:·2066·616c·7365·0a20·2020·2020·2020·206d···false.········m 
00087d70:·6173·6b3a·2074·7275·650a·2020·2020·2020··ask:·true.······ 
00087d80:·2d20·6e61·6d65·3a20·626c·7565·746f·6f74··-·name:·bluetoot00087d40:·2020·2d20·6e61·6d65·3a20·626c·7565·746f····-·name:·blueto
 00087d50:·6f74·682e·7365·7276·6963·650a·2020·2020··oth.service.····
Max diff block lines reached; 8582/24642 bytes (34.83%) of diff not shown.
5.4 KB
html2text {}
    
Offset 432, 15 lines modifiedOffset 432, 15 lines modified
432 Identifiers:·CCE-82496-1432 Identifiers:·CCE-82496-1
433 ·············_\x8c_\x8u_\x8i····3.4.5433 ·············_\x8c_\x8u_\x8i····3.4.5
434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
444 apiVersion:·machineconfiguration.openshift.io/v1444 apiVersion:·machineconfiguration.openshift.io/v1
445 kind:·MachineConfig445 kind:·MachineConfig
446 spec:446 spec:
Offset 451, 15 lines modifiedOffset 451, 15 lines modified
451 ······units:451 ······units:
452 ······-·name:·debug-shell.service452 ······-·name:·debug-shell.service
453 ········enabled:·false453 ········enabled:·false
454 ········mask:·true454 ········mask:·true
455 ······-·name:·debug-shell.socket455 ······-·name:·debug-shell.socket
456 ········enabled:·false456 ········enabled:·false
457 ········mask:·true457 ········mask:·true
458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
463 apiVersion:·machineconfiguration.openshift.io/v1463 apiVersion:·machineconfiguration.openshift.io/v1
464 kind:·MachineConfig464 kind:·MachineConfig
465 spec:465 spec:
Offset 1881, 15 lines modifiedOffset 1881, 15 lines modified
1881 ············_\x8c_\x8u_\x8i············3.1.161881 ············_\x8c_\x8u_\x8i············3.1.16
1882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1893 apiVersion:·machineconfiguration.openshift.io/v11893 apiVersion:·machineconfiguration.openshift.io/v1
1894 kind:·MachineConfig1894 kind:·MachineConfig
1895 spec:1895 spec:
Offset 1900, 15 lines modifiedOffset 1900, 15 lines modified
1900 ······units:1900 ······units:
1901 ······-·name:·bluetooth.service1901 ······-·name:·bluetooth.service
1902 ········enabled:·false1902 ········enabled:·false
1903 ········mask:·true1903 ········mask:·true
1904 ······-·name:·bluetooth.socket1904 ······-·name:·bluetooth.socket
1905 ········enabled:·false1905 ········enabled:·false
1906 ········mask:·true1906 ········mask:·true
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1912 apiVersion:·machineconfiguration.openshift.io/v11912 apiVersion:·machineconfiguration.openshift.io/v1
1913 kind:·MachineConfig1913 kind:·MachineConfig
1914 spec:1914 spec:
Offset 2218, 15 lines modifiedOffset 2218, 15 lines modified
2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2230 apiVersion:·machineconfiguration.openshift.io/v12230 apiVersion:·machineconfiguration.openshift.io/v1
2231 kind:·MachineConfig2231 kind:·MachineConfig
2232 spec:2232 spec:
Offset 2237, 15 lines modifiedOffset 2237, 15 lines modified
2237 ······units:2237 ······units:
2238 ······-·name:·autofs.service2238 ······-·name:·autofs.service
2239 ········enabled:·false2239 ········enabled:·false
2240 ········mask:·true2240 ········mask:·true
2241 ······-·name:·autofs.socket2241 ······-·name:·autofs.socket
2242 ········enabled:·false2242 ········enabled:·false
2243 ········mask:·true2243 ········mask:·true
2244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2249 apiVersion:·machineconfiguration.openshift.io/v12249 apiVersion:·machineconfiguration.openshift.io/v1
2250 kind:·MachineConfig2250 kind:·MachineConfig
2251 spec:2251 spec:
29.3 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-moderate.html
    
Offset 19070, 66 lines modifiedOffset 19070, 66 lines modified
0004a7d0:·7267·6574·3d22·2369·646d·3736·3334·2220··rget="#idm7634"·0004a7d0:·7267·6574·3d22·2369·646d·3736·3334·2220··rget="#idm7634"·
0004a7e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0004a7e0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0004a7f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0004a7f0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0004a800:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0004a800:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0004a810:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0004a810:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0004a820:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0004a820:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0004a830:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0004a830:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0004a840:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a>0004a840:·6e20·4b75·6265·726e·6574·6573·2073·6e69··n·Kubernetes·sni
 0004a850:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
0004a850:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0004a860:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0004a860:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0004a870:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0004a870:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0004a880:·7073·6522·2069·643d·2269·646d·3736·3334··pse"·id="idm7634
0004a880:·3736·3334·223e·3c74·6162·6c65·2063·6c61··7634"><table·cla0004a890:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0004a890:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0004a8a0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0004a8a0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0004a8b0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0004a8b0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0004a8c0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0004a8c0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0004a8d0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0004a8d0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0004a8e0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0004a8e0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0004a8f0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0004a900:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med 
0004a910:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr0004a8f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0004a900:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0004a910:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
 0004a920:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0004a920:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0004a930:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0004a930:·3e3c·7464·3e74·7275·653c·2f74·643e·3c2f··><td>true</td></0004a940:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><
0004a940:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0004a950:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0004a950:·6567·793a·3c2f·7468·3e3c·7464·3e64·6973··egy:</th><td>dis0004a960:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable
0004a960:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0004a970:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0004a970:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0004a980:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api
0004a980:·3e61·7069·5665·7273·696f·6e3a·206d·6163··>apiVersion:·mac0004a990:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine
0004a990:·6869·6e65·636f·6e66·6967·7572·6174·696f··hineconfiguratio0004a9a0:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op
0004a9a0:·6e2e·6f70·656e·7368·6966·742e·696f·2f76··n.openshift.io/v0004a9b0:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki
0004a9b0:·310a·6b69·6e64·3a20·4d61·6368·696e·6543··1.kind:·MachineC0004a9c0:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi
0004a9c0:·6f6e·6669·670a·7370·6563·3a0a·2020·636f··onfig.spec:.··co0004a9d0:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config
0004a9d0:·6e66·6967·3a0a·2020·2020·6967·6e69·7469··nfig:.····igniti0004a9e0:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.
0004a9e0:·6f6e·3a0a·2020·2020·2020·7665·7273·696f··on:.······versio0004a9f0:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3
0004a9f0:·6e3a·2033·2e31·2e30·0a20·2020·2073·7973··n:·3.1.0.····sys0004aa00:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd
0004aa00:·7465·6d64·3a0a·2020·2020·2020·756e·6974··temd:.······unit0004aa10:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·
0004aa10:·733a·0a20·2020·2020·202d·206e·616d·653a··s:.······-·name: 
0004aa20:·2064·6562·7567·2d73·6865·6c6c·2e73·6572···debug-shell.ser 
0004aa30:·7669·6365·0a20·2020·2020·2020·2065·6e61··vice.········ena 
0004aa40:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.···· 
0004aa50:·2020·2020·6d61·736b·3a20·7472·7565·0a20······mask:·true.· 
0004aa60:·2020·2020·202d·206e·616d·653a·2064·6562·······-·name:·deb0004aa20:·2020·2020·202d·206e·616d·653a·2064·6562·······-·name:·deb
0004aa70:·7567·2d73·6865·6c6c·2e73·6f63·6b65·740a··ug-shell.socket.0004aa30:·7567·2d73·6865·6c6c·2e73·6572·7669·6365··ug-shell.service
0004aa80:·2020·2020·2020·2020·656e·6162·6c65·643a··········enabled:0004aa40:·0a20·2020·2020·2020·2065·6e61·626c·6564··.········enabled
0004aa90:·2066·616c·7365·0a20·2020·2020·2020·206d···false.········m0004aa50:·3a20·6661·6c73·650a·2020·2020·2020·2020··:·false.········
 0004aa60:·6d61·736b·3a20·7472·7565·0a20·2020·2020··mask:·true.·····
 0004aa70:·202d·206e·616d·653a·2064·6562·7567·2d73···-·name:·debug-s
 0004aa80:·6865·6c6c·2e73·6f63·6b65·740a·2020·2020··hell.socket.····
 0004aa90:·2020·2020·656e·6162·6c65·643a·2066·616c······enabled:·fal
 0004aaa0:·7365·0a20·2020·2020·2020·206d·6173·6b3a··se.········mask:
0004aaa0:·6173·6b3a·2074·7275·650a·3c2f·636f·6465··ask:·true.</code0004aab0:·2074·7275·650a·3c2f·636f·6465·3e3c·2f70···true.</code></p
0004aab0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0004aac0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0004aac0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0004aad0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0004aad0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0004aae0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0004aae0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0004aaf0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0004aaf0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0004ab00:·7461·7267·6574·3d22·2369·646d·3736·3335··target="#idm7635
0004ab00:·3736·3335·2220·7461·6269·6e64·6578·3d22··7635"·tabindex="0004ab10:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0004ab10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0004ab20:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0004ab20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0004ab30:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0004ab30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0004ab40:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0004ab40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0004ab50:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0004ab50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0004ab60:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0004ab70:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</
0004ab60:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet 
0004ab70:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</ 
0004ab80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0004ab80:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0004ab90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0004ab90:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0004aba0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0004aba0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0004abb0:·646d·3736·3335·223e·3c74·6162·6c65·2063··dm7635"><table·c0004abb0:·646d·3736·3335·223e·3c74·6162·6c65·2063··dm7635"><table·c
0004abc0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0004abc0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0004abd0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0004abd0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0004abe0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0004abe0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
Offset 34735, 66 lines modifiedOffset 34735, 66 lines modified
00087ae0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm100087ae0:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
00087af0:·3833·3933·2220·7461·6269·6e64·6578·3d22··8393"·tabindex="00087af0:·3833·3933·2220·7461·6269·6e64·6578·3d22··8393"·tabindex="
00087b00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00087b00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00087b10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00087b10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00087b20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00087b20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00087b30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00087b30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00087b40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00087b40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00087b50:·6469·6174·696f·6e20·4b75·6265·726e·6574··diation·Kubernet
 00087b60:·6573·2073·6e69·7070·6574·20e2·87b2·3c2f··es·snippet·...</
 00087b70:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00087b80:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00087b90:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00087ba0:·646d·3138·3339·3322·3e3c·7461·626c·6520··dm18393"><table·
 00087bb0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00087bc0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00087bd0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00087be0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 00087bf0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 00087c00:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 00087c10:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 00087c20:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 00087c30:·6d65·6469·756d·3c2f·7464·3e3c·2f74·723e··medium</td></tr>
 00087c40:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00087c50:·2f74·683e·3c74·643e·7472·7565·3c2f·7464··/th><td>true</td
 00087c60:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00087c70:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00087c80:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr
 00087c90:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00087ca0:·6f64·653e·6170·6956·6572·7369·6f6e·3a20··ode>apiVersion:·
 00087cb0:·6d61·6368·696e·6563·6f6e·6669·6775·7261··machineconfigura
 00087cc0:·7469·6f6e·2e6f·7065·6e73·6869·6674·2e69··tion.openshift.i
 00087cd0:·6f2f·7631·0a6b·696e·643a·204d·6163·6869··o/v1.kind:·Machi
 00087ce0:·6e65·436f·6e66·6967·0a73·7065·633a·0a20··neConfig.spec:.·
 00087cf0:·2063·6f6e·6669·673a·0a20·2020·2069·676e···config:.····ign
 00087d00:·6974·696f·6e3a·0a20·2020·2020·2076·6572··ition:.······ver
 00087d10:·7369·6f6e·3a20·332e·312e·300a·2020·2020··sion:·3.1.0.····
 00087d20:·7379·7374·656d·643a·0a20·2020·2020·2075··systemd:.······u
 00087d30:·6e69·7473·3a0a·2020·2020·2020·2d20·6e61··nits:.······-·na
 00087d40:·6d65·3a20·626c·7565·746f·6f74·682e·7365··me:·bluetooth.se
 00087d50:·7276·6963·650a·2020·2020·2020·2020·656e··rvice.········en
 00087d60:·6162·6c65·643a·2066·616c·7365·0a20·2020··abled:·false.···
 00087d70:·2020·2020·206d·6173·6b3a·2074·7275·650a·······mask:·true.
 00087d80:·2020·2020·2020·2d20·6e61·6d65·3a20·626c········-·name:·bl
 00087d90:·7565·746f·6f74·682e·736f·636b·6574·0a20··uetooth.socket.·
 00087da0:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:·
 00087db0:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma
 00087dc0:·736b·3a20·7472·7565·0a3c·2f63·6f64·653e··sk:·true.</code>
 00087dd0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00087de0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 00087df0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
Max diff block lines reached; 8444/24366 bytes (34.65%) of diff not shown.
5.4 KB
html2text {}
    
Offset 432, 15 lines modifiedOffset 432, 15 lines modified
432 Identifiers:·CCE-82496-1432 Identifiers:·CCE-82496-1
433 ·············_\x8c_\x8u_\x8i····3.4.5433 ·············_\x8c_\x8u_\x8i····3.4.5
434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235434 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)435 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6436 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1437 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8439 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low440 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium441 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true442 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable443 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
444 apiVersion:·machineconfiguration.openshift.io/v1444 apiVersion:·machineconfiguration.openshift.io/v1
445 kind:·MachineConfig445 kind:·MachineConfig
446 spec:446 spec:
Offset 451, 15 lines modifiedOffset 451, 15 lines modified
451 ······units:451 ······units:
452 ······-·name:·debug-shell.service452 ······-·name:·debug-shell.service
453 ········enabled:·false453 ········enabled:·false
454 ········mask:·true454 ········mask:·true
455 ······-·name:·debug-shell.socket455 ······-·name:·debug-shell.socket
456 ········enabled:·false456 ········enabled:·false
457 ········mask:·true457 ········mask:·true
458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8458 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low459 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium460 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true461 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable462 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
463 apiVersion:·machineconfiguration.openshift.io/v1463 apiVersion:·machineconfiguration.openshift.io/v1
464 kind:·MachineConfig464 kind:·MachineConfig
465 spec:465 spec:
Offset 1881, 15 lines modifiedOffset 1881, 15 lines modified
1881 ············_\x8c_\x8u_\x8i············3.1.161881 ············_\x8c_\x8u_\x8i············3.1.16
1882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511882 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31883 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61884 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21885 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71886 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41887 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81888 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1889 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1890 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1891 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1892 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1893 apiVersion:·machineconfiguration.openshift.io/v11893 apiVersion:·machineconfiguration.openshift.io/v1
1894 kind:·MachineConfig1894 kind:·MachineConfig
1895 spec:1895 spec:
Offset 1900, 15 lines modifiedOffset 1900, 15 lines modified
1900 ······units:1900 ······units:
1901 ······-·name:·bluetooth.service1901 ······-·name:·bluetooth.service
1902 ········enabled:·false1902 ········enabled:·false
1903 ········mask:·true1903 ········mask:·true
1904 ······-·name:·bluetooth.socket1904 ······-·name:·bluetooth.socket
1905 ········enabled:·false1905 ········enabled:·false
1906 ········mask:·true1906 ········mask:·true
1907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81907 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1908 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1909 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1910 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1911 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1912 apiVersion:·machineconfiguration.openshift.io/v11912 apiVersion:·machineconfiguration.openshift.io/v1
1913 kind:·MachineConfig1913 kind:·MachineConfig
1914 spec:1914 spec:
Offset 2218, 15 lines modifiedOffset 2218, 15 lines modified
2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2218 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42219 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62220 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32221 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72222 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72223 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272224 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2230 apiVersion:·machineconfiguration.openshift.io/v12230 apiVersion:·machineconfiguration.openshift.io/v1
2231 kind:·MachineConfig2231 kind:·MachineConfig
2232 spec:2232 spec:
Offset 2237, 15 lines modifiedOffset 2237, 15 lines modified
2237 ······units:2237 ······units:
2238 ······-·name:·autofs.service2238 ······-·name:·autofs.service
2239 ········enabled:·false2239 ········enabled:·false
2240 ········mask:·true2240 ········mask:·true
2241 ······-·name:·autofs.socket2241 ······-·name:·autofs.socket
2242 ········enabled:·false2242 ········enabled:·false
2243 ········mask:·true2243 ········mask:·true
2244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82244 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2245 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2246 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2247 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2248 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2249 apiVersion:·machineconfiguration.openshift.io/v12249 apiVersion:·machineconfiguration.openshift.io/v1
2250 kind:·MachineConfig2250 kind:·MachineConfig
2251 spec:2251 spec:
29.6 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-nerc-cip.html
    
Offset 19028, 67 lines modifiedOffset 19028, 67 lines modified
0004a530:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0004a530:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0004a540:·6964·6d37·3633·3422·2074·6162·696e·6465··idm7634"·tabinde0004a540:·6964·6d37·3633·3422·2074·6162·696e·6465··idm7634"·tabinde
0004a550:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0004a550:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0004a560:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0004a560:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0004a570:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0004a570:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0004a580:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0004a580:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0004a590:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0004a590:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0004a5a0:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip0004a5a0:·656d·6564·6961·7469·6f6e·204b·7562·6572··emediation·Kuber
 0004a5b0:·6e65·7465·7320·736e·6970·7065·7420·e287··netes·snippet·..
0004a5b0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0004a5c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0004a5c0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0004a5d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0004a5d0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0004a5e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0004a5e0:·2220·6964·3d22·6964·6d37·3633·3422·3e3c··"·id="idm7634"><0004a5f0:·3d22·6964·6d37·3633·3422·3e3c·7461·626c··="idm7634"><tabl
0004a5f0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0004a600:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0004a600:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0004a610:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0004a610:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0004a620:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0004a620:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0004a630:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0004a630:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0004a640:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
0004a640:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0004a650:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0004a650:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0004a660:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0004a670:·683e·3c74·643e·6d65·6469·756d·3c2f·7464··h><td>medium</td 
0004a680:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0004a660:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0004a670:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0004a680:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t
 0004a690:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0004a690:·626f·6f74·3a3c·2f74·683e·3c74·643e·7472··boot:</th><td>tr0004a6a0:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
0004a6a0:·7565·3c2f·7464·3e3c·2f74·723e·3c74·723e··ue</td></tr><tr>0004a6b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0004a6b0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0004a6c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0004a6c0:·683e·3c74·643e·6469·7361·626c·653c·2f74··h><td>disable</t0004a6d0:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></
0004a6d0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0004a6e0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0004a6e0:·7072·653e·3c63·6f64·653e·6170·6956·6572··pre><code>apiVer0004a6f0:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion
0004a6f0:·7369·6f6e·3a20·6d61·6368·696e·6563·6f6e··sion:·machinecon0004a700:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu
0004a700:·6669·6775·7261·7469·6f6e·2e6f·7065·6e73··figuration.opens0004a710:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift
0004a710:·6869·6674·2e69·6f2f·7631·0a6b·696e·643a··hift.io/v1.kind:0004a720:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac
0004a720:·204d·6163·6869·6e65·436f·6e66·6967·0a73···MachineConfig.s0004a730:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:
0004a730:·7065·633a·0a20·2063·6f6e·6669·673a·0a20··pec:.··config:.·0004a740:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i
0004a740:·2020·2069·676e·6974·696f·6e3a·0a20·2020·····ignition:.···0004a750:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v
0004a750:·2020·2076·6572·7369·6f6e·3a20·332e·312e·····version:·3.1.0004a760:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··
0004a760:·300a·2020·2020·7379·7374·656d·643a·0a20··0.····systemd:.·0004a770:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····
0004a770:·2020·2020·2075·6e69·7473·3a0a·2020·2020·······units:.····0004a780:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·
0004a780:·2020·2d20·6e61·6d65·3a20·6465·6275·672d····-·name:·debug- 
0004a790:·7368·656c·6c2e·7365·7276·6963·650a·2020··shell.service.·· 
0004a7a0:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f 
0004a7b0:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas 
0004a7c0:·6b3a·2074·7275·650a·2020·2020·2020·2d20··k:·true.······-· 
0004a7d0:·6e61·6d65·3a20·6465·6275·672d·7368·656c··name:·debug-shel0004a790:·6e61·6d65·3a20·6465·6275·672d·7368·656c··name:·debug-shel
0004a7e0:·6c2e·736f·636b·6574·0a20·2020·2020·2020··l.socket.·······0004a7a0:·6c2e·7365·7276·6963·650a·2020·2020·2020··l.service.······
 0004a7b0:·2020·656e·6162·6c65·643a·2066·616c·7365····enabled:·false
 0004a7c0:·0a20·2020·2020·2020·206d·6173·6b3a·2074··.········mask:·t
 0004a7d0:·7275·650a·2020·2020·2020·2d20·6e61·6d65··rue.······-·name
 0004a7e0:·3a20·6465·6275·672d·7368·656c·6c2e·736f··:·debug-shell.so
 0004a7f0:·636b·6574·0a20·2020·2020·2020·2065·6e61··cket.········ena
0004a7f0:·2065·6e61·626c·6564·3a20·6661·6c73·650a···enabled:·false.0004a800:·626c·6564·3a20·6661·6c73·650a·2020·2020··bled:·false.····
0004a800:·2020·2020·2020·2020·6d61·736b·3a20·7472··········mask:·tr0004a810:·2020·2020·6d61·736b·3a20·7472·7565·0a3c······mask:·true.<
0004a810:·7565·0a3c·2f63·6f64·653e·3c2f·7072·653e··ue.</code></pre>0004a820:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0004a820:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0004a830:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0004a830:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0004a840:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0004a840:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0004a850:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0004a850:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0004a860:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0004a860:·6765·743d·2223·6964·6d37·3633·3522·2074··get="#idm7635"·t0004a870:·2223·6964·6d37·3633·3522·2074·6162·696e··"#idm7635"·tabin
0004a870:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0004a880:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0004a880:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0004a890:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0004a890:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0004a8a0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0004a8a0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0004a8b0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0004a8b0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0004a8c0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0004a8c0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0004a8d0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
0004a8d0:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip 
0004a8e0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><0004a8e0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
0004a8f0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0004a8f0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0004a900:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0004a900:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0004a910:·7365·2220·6964·3d22·6964·6d37·3633·3522··se"·id="idm7635"0004a910:·7365·2220·6964·3d22·6964·6d37·3633·3522··se"·id="idm7635"
0004a920:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0004a920:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0004a930:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0004a930:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0004a940:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0004a940:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0004a950:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0004a950:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
Offset 34694, 66 lines modifiedOffset 34694, 66 lines modified
00087850:·6574·3d22·2369·646d·3138·3339·3322·2074··et="#idm18393"·t00087850:·6574·3d22·2369·646d·3138·3339·3322·2074··et="#idm18393"·t
00087860:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role00087860:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
00087870:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e00087870:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
00087880:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·00087880:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
00087890:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·00087890:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
000878a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=000878a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
000878b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation000878b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 000878c0:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip
 000878d0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 000878e0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 000878f0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00087900:·7365·2220·6964·3d22·6964·6d31·3833·3933··se"·id="idm18393
 00087910:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00087920:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 00087930:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00087940:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00087950:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00087960:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00087970:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00087980:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00087990:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
 000879a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 000879b0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 000879c0:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><
 000879d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 000879e0:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable
 000879f0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
 00087a00:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api
 00087a10:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine
 00087a20:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op
 00087a30:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki
 00087a40:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi
 00087a50:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config
 00087a60:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.
 00087a70:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3
 00087a80:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd
 00087a90:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·
 00087aa0:·2020·2020·202d·206e·616d·653a·2062·6c75·······-·name:·blu
 00087ab0:·6574·6f6f·7468·2e73·6572·7669·6365·0a20··etooth.service.·
 00087ac0:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:·
 00087ad0:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma
 00087ae0:·736b·3a20·7472·7565·0a20·2020·2020·202d··sk:·true.······-
 00087af0:·206e·616d·653a·2062·6c75·6574·6f6f·7468···name:·bluetooth
 00087b00:·2e73·6f63·6b65·740a·2020·2020·2020·2020··.socket.········
 00087b10:·656e·6162·6c65·643a·2066·616c·7365·0a20··enabled:·false.·
 00087b20:·2020·2020·2020·206d·6173·6b3a·2074·7275·········mask:·tru
 00087b30:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
 00087b40:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
 00087b50:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
 00087b60:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
Max diff block lines reached; 8582/24642 bytes (34.83%) of diff not shown.
5.4 KB
html2text {}
    
Offset 421, 15 lines modifiedOffset 421, 15 lines modified
421 Identifiers:·CCE-82496-1421 Identifiers:·CCE-82496-1
422 ·············_\x8c_\x8u_\x8i····3.4.5422 ·············_\x8c_\x8u_\x8i····3.4.5
423 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235423 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
424 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)424 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
425 ·············_\x8n_\x8i_\x8s_\x8t···CM-6425 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
426 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1426 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
427 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227427 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
428 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8428 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
429 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low429 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
430 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium430 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
431 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true431 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
432 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable432 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
433 apiVersion:·machineconfiguration.openshift.io/v1433 apiVersion:·machineconfiguration.openshift.io/v1
434 kind:·MachineConfig434 kind:·MachineConfig
435 spec:435 spec:
Offset 440, 15 lines modifiedOffset 440, 15 lines modified
440 ······units:440 ······units:
441 ······-·name:·debug-shell.service441 ······-·name:·debug-shell.service
442 ········enabled:·false442 ········enabled:·false
443 ········mask:·true443 ········mask:·true
444 ······-·name:·debug-shell.socket444 ······-·name:·debug-shell.socket
445 ········enabled:·false445 ········enabled:·false
446 ········mask:·true446 ········mask:·true
447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
448 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low448 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
449 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium449 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
450 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true450 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
451 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable451 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
452 apiVersion:·machineconfiguration.openshift.io/v1452 apiVersion:·machineconfiguration.openshift.io/v1
453 kind:·MachineConfig453 kind:·MachineConfig
454 spec:454 spec:
Offset 1870, 15 lines modifiedOffset 1870, 15 lines modified
1870 ············_\x8c_\x8u_\x8i············3.1.161870 ············_\x8c_\x8u_\x8i············3.1.16
1871 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-0015511871 ············_\x8d_\x8i_\x8s_\x8a···········CCI-000085,·CCI-001551
1872 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.31872 References:·_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.5.1,·4.3.3.5.2,·4.3.3.5.3,·4.3.3.5.4,·4.3.3.5.5,·4.3.3.5.6,·4.3.3.5.7,·4.3.3.5.8,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.1,·4.3.3.7.2,·4.3.3.7.3,·4.3.3.7.4,·4.3.4.3.2,·4.3.4.3.3
1873 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.61873 ············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR·2.5,·SR·2.6,·SR·2.7,·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
1874 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.21874 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.12.1.2,·A.12.5.1,·A.12.6.2,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
1875 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-71875 ············_\x8n_\x8i_\x8s_\x8t···········AC-18(a),·AC-18(3),·CM-7(a),·CM-7(b),·CM-6(a),·MP-7
1876 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-41876 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
1877 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x81877 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
1878 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1878 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1879 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1879 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1880 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1880 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1881 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1881 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1882 apiVersion:·machineconfiguration.openshift.io/v11882 apiVersion:·machineconfiguration.openshift.io/v1
1883 kind:·MachineConfig1883 kind:·MachineConfig
1884 spec:1884 spec:
Offset 1889, 15 lines modifiedOffset 1889, 15 lines modified
1889 ······units:1889 ······units:
1890 ······-·name:·bluetooth.service1890 ······-·name:·bluetooth.service
1891 ········enabled:·false1891 ········enabled:·false
1892 ········mask:·true1892 ········mask:·true
1893 ······-·name:·bluetooth.socket1893 ······-·name:·bluetooth.socket
1894 ········enabled:·false1894 ········enabled:·false
1895 ········mask:·true1895 ········mask:·true
1896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81896 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
1897 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1897 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1898 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1898 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1899 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true1899 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
1900 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1900 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1901 apiVersion:·machineconfiguration.openshift.io/v11901 apiVersion:·machineconfiguration.openshift.io/v1
1902 kind:·MachineConfig1902 kind:·MachineConfig
1903 spec:1903 spec:
Offset 2207, 15 lines modifiedOffset 2207, 15 lines modified
2207 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)2207 ·············_\x8h_\x8i_\x8p_\x8a_\x8a··········164.308(a)(3)(i),·164.308(a)(3)(ii)(A),·164.310(d)(1),·164.310(d)(2),·164.312(a)(1),·164.312(a)(2)(iv),·164.312(b)
2208 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.42208 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.2.2,·4.3.3.5.1,·4.3.3.5.2,·4.3.3.6.1,·4.3.3.6.2,·4.3.3.6.3,·4.3.3.6.4,·4.3.3.6.5,·4.3.3.6.6,·4.3.3.6.7,·4.3.3.6.8,·4.3.3.6.9,·4.3.3.7.2,·4.3.3.7.4
2209 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.62209 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·1.1,·SR·1.10,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR·1.5,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.6
2210 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.32210 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.6,·A.13.1.1,·A.13.2.1,·A.18.1.4,·A.6.2.1,·A.6.2.2,·A.7.1.1,·A.9.2.1,·A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
2211 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-72211 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
2212 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-72212 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
2213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002272213 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
2214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x82214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
2215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2219 apiVersion:·machineconfiguration.openshift.io/v12219 apiVersion:·machineconfiguration.openshift.io/v1
2220 kind:·MachineConfig2220 kind:·MachineConfig
2221 spec:2221 spec:
Offset 2226, 15 lines modifiedOffset 2226, 15 lines modified
2226 ······units:2226 ······units:
2227 ······-·name:·autofs.service2227 ······-·name:·autofs.service
2228 ········enabled:·false2228 ········enabled:·false
2229 ········mask:·true2229 ········mask:·true
2230 ······-·name:·autofs.socket2230 ······-·name:·autofs.socket
2231 ········enabled:·false2231 ········enabled:·false
2232 ········mask:·true2232 ········mask:·true
2233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82233 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
2234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2234 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2235 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true2236 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
2237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2237 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2238 apiVersion:·machineconfiguration.openshift.io/v12238 apiVersion:·machineconfiguration.openshift.io/v1
2239 kind:·MachineConfig2239 kind:·MachineConfig
2240 spec:2240 spec:
9.96 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-stig-v1r1.html
    
Offset 23059, 66 lines modifiedOffset 23059, 66 lines modified
0005a120:·2d74·6172·6765·743d·2223·6964·6d32·3733··-target="#idm2730005a120:·2d74·6172·6765·743d·2223·6964·6d32·3733··-target="#idm273
0005a130:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"0005a130:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"
0005a140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0005a140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0005a150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0005a150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0005a160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0005a160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0005a170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0005a170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0005a180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0005a180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0005a190:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...0005a190:·6174·696f·6e20·4b75·6265·726e·6574·6573··ation·Kubernetes
 0005a1a0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0005a1a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0005a1b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0005a1b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0005a1c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0005a1c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0005a1d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0005a1d0:·2269·646d·3237·3336·3622·3e3c·7461·626c··"idm27366"><tabl0005a1e0:·3237·3336·3622·3e3c·7461·626c·6520·636c··27366"><table·cl
0005a1e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0005a1f0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0005a1f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0005a200:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0005a200:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0005a210:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0005a210:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0005a220:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0005a220:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0005a230:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0005a230:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0005a240:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0005a250:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0005a260:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me
 0005a270:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t
 0005a280:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0005a290:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td><
0005a240:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0005a2a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0005a250:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0005a260:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t 
0005a270:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0005a280:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</ 
0005a290:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0005a2a0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0005a2b0:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di
0005a2b0:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></0005a2c0:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr><
0005a2c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0005a2d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0005a2d0:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion0005a2e0:·653e·6170·6956·6572·7369·6f6e·3a20·6d61··e>apiVersion:·ma
0005a2e0:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu0005a2f0:·6368·696e·6563·6f6e·6669·6775·7261·7469··chineconfigurati
0005a2f0:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift0005a300:·6f6e·2e6f·7065·6e73·6869·6674·2e69·6f2f··on.openshift.io/
0005a300:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac0005a310:·7631·0a6b·696e·643a·204d·6163·6869·6e65··v1.kind:·Machine
0005a310:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:0005a320:·436f·6e66·6967·0a73·7065·633a·0a20·2063··Config.spec:.··c
0005a320:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i0005a330:·6f6e·6669·673a·0a20·2020·2069·676e·6974··onfig:.····ignit
0005a330:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v0005a340:·696f·6e3a·0a20·2020·2020·2076·6572·7369··ion:.······versi
0005a340:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··0005a350:·6f6e·3a20·332e·312e·300a·2020·2020·7379··on:·3.1.0.····sy
0005a350:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····0005a360:·7374·656d·643a·0a20·2020·2020·2075·6e69··stemd:.······uni
0005a360:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·0005a370:·7473·3a0a·2020·2020·2020·2d20·6e61·6d65··ts:.······-·name
0005a370:·6e61·6d65·3a20·7373·6864·2e73·6572·7669··name:·sshd.servi0005a380:·3a20·7373·6864·2e73·6572·7669·6365·0a20··:·sshd.service.·
 0005a390:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:·
 0005a3a0:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma
 0005a3b0:·736b·3a20·7472·7565·0a20·2020·2020·202d··sk:·true.······-
 0005a3c0:·206e·616d·653a·2073·7368·642e·736f·636b···name:·sshd.sock
0005a380:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl0005a3d0:·6574·0a20·2020·2020·2020·2065·6e61·626c··et.········enabl
0005a390:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······0005a3e0:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······
0005a3a0:·2020·6d61·736b·3a20·7472·7565·0a20·2020····mask:·true.···0005a3f0:·2020·6d61·736b·3a20·7472·7565·0a3c·2f63····mask:·true.</c
0005a3b0:·2020·202d·206e·616d·653a·2073·7368·642e·····-·name:·sshd. 
0005a3c0:·736f·636b·6574·0a20·2020·2020·2020·2065··socket.········e 
0005a3d0:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.·· 
0005a3e0:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true 
0005a3f0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0005a400:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0005a400:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0005a410:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0005a410:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0005a420:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0005a420:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0005a430:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0005a430:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0005a440:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0005a440:·743d·2223·6964·6d32·3733·3637·2220·7461··t="#idm27367"·ta0005a450:·6964·6d32·3733·3637·2220·7461·6269·6e64··idm27367"·tabind
0005a450:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0005a460:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0005a460:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0005a470:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0005a470:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0005a480:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0005a480:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0005a490:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0005a490:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0005a4a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0005a4a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0005a4b0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
0005a4b0:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp 
0005a4c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0005a4c0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0005a4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0005a4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0005a4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0005a4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0005a4f0:·6522·2069·643d·2269·646d·3237·3336·3722··e"·id="idm27367"0005a4f0:·6522·2069·643d·2269·646d·3237·3336·3722··e"·id="idm27367"
0005a500:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0005a500:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0005a510:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0005a510:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0005a520:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0005a520:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0005a530:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0005a530:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
1.87 KB
html2text {}
    
Offset 705, 15 lines modifiedOffset 705, 15 lines modified
705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
707 Severity: ···high707 Severity: ···high
708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
709 Identifiers:·CCE-86189-8709 Identifiers:·CCE-86189-8
710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
717 apiVersion:·machineconfiguration.openshift.io/v1717 apiVersion:·machineconfiguration.openshift.io/v1
718 kind:·MachineConfig718 kind:·MachineConfig
719 spec:719 spec:
Offset 724, 15 lines modifiedOffset 724, 15 lines modified
724 ······units:724 ······units:
725 ······-·name:·sshd.service725 ······-·name:·sshd.service
726 ········enabled:·false726 ········enabled:·false
727 ········mask:·true727 ········mask:·true
728 ······-·name:·sshd.socket728 ······-·name:·sshd.socket
729 ········enabled:·false729 ········enabled:·false
730 ········mask:·true730 ········mask:·true
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
736 apiVersion:·machineconfiguration.openshift.io/v1736 apiVersion:·machineconfiguration.openshift.io/v1
737 kind:·MachineConfig737 kind:·MachineConfig
738 spec:738 spec:
9.96 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-stig-v2r1.html
    
Offset 23059, 66 lines modifiedOffset 23059, 66 lines modified
0005a120:·2d74·6172·6765·743d·2223·6964·6d32·3733··-target="#idm2730005a120:·2d74·6172·6765·743d·2223·6964·6d32·3733··-target="#idm273
0005a130:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"0005a130:·3636·2220·7461·6269·6e64·6578·3d22·3022··66"·tabindex="0"
0005a140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0005a140:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0005a150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0005a150:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0005a160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0005a160:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0005a170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0005a170:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0005a180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0005a180:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0005a190:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...0005a190:·6174·696f·6e20·4b75·6265·726e·6574·6573··ation·Kubernetes
 0005a1a0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0005a1a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0005a1b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0005a1b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0005a1c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0005a1c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0005a1d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0005a1d0:·2269·646d·3237·3336·3622·3e3c·7461·626c··"idm27366"><tabl0005a1e0:·3237·3336·3622·3e3c·7461·626c·6520·636c··27366"><table·cl
0005a1e0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0005a1f0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0005a1f0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0005a200:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0005a200:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0005a210:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0005a210:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0005a220:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0005a220:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0005a230:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0005a230:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0005a240:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0005a250:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0005a260:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6d65··tion:</th><td>me
 0005a270:·6469·756d·3c2f·7464·3e3c·2f74·723e·3c74··dium</td></tr><t
 0005a280:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0005a290:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td><
0005a240:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di0005a2a0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0005a250:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0005a260:·643e·6d65·6469·756d·3c2f·7464·3e3c·2f74··d>medium</td></t 
0005a270:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0005a280:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</ 
0005a290:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0005a2a0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t0005a2b0:·7465·6779·3a3c·2f74·683e·3c74·643e·6469··tegy:</th><td>di
0005a2b0:·643e·6469·7361·626c·653c·2f74·643e·3c2f··d>disable</td></0005a2c0:·7361·626c·653c·2f74·643e·3c2f·7472·3e3c··sable</td></tr><
0005a2c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0005a2d0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0005a2d0:·3c63·6f64·653e·6170·6956·6572·7369·6f6e··<code>apiVersion0005a2e0:·653e·6170·6956·6572·7369·6f6e·3a20·6d61··e>apiVersion:·ma
0005a2e0:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu0005a2f0:·6368·696e·6563·6f6e·6669·6775·7261·7469··chineconfigurati
0005a2f0:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift0005a300:·6f6e·2e6f·7065·6e73·6869·6674·2e69·6f2f··on.openshift.io/
0005a300:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac0005a310:·7631·0a6b·696e·643a·204d·6163·6869·6e65··v1.kind:·Machine
0005a310:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:0005a320:·436f·6e66·6967·0a73·7065·633a·0a20·2063··Config.spec:.··c
0005a320:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i0005a330:·6f6e·6669·673a·0a20·2020·2069·676e·6974··onfig:.····ignit
0005a330:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v0005a340:·696f·6e3a·0a20·2020·2020·2076·6572·7369··ion:.······versi
0005a340:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··0005a350:·6f6e·3a20·332e·312e·300a·2020·2020·7379··on:·3.1.0.····sy
0005a350:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····0005a360:·7374·656d·643a·0a20·2020·2020·2075·6e69··stemd:.······uni
0005a360:·2075·6e69·7473·3a0a·2020·2020·2020·2d20···units:.······-·0005a370:·7473·3a0a·2020·2020·2020·2d20·6e61·6d65··ts:.······-·name
0005a370:·6e61·6d65·3a20·7373·6864·2e73·6572·7669··name:·sshd.servi0005a380:·3a20·7373·6864·2e73·6572·7669·6365·0a20··:·sshd.service.·
 0005a390:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:·
 0005a3a0:·6661·6c73·650a·2020·2020·2020·2020·6d61··false.········ma
 0005a3b0:·736b·3a20·7472·7565·0a20·2020·2020·202d··sk:·true.······-
 0005a3c0:·206e·616d·653a·2073·7368·642e·736f·636b···name:·sshd.sock
0005a380:·6365·0a20·2020·2020·2020·2065·6e61·626c··ce.········enabl0005a3d0:·6574·0a20·2020·2020·2020·2065·6e61·626c··et.········enabl
0005a390:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······0005a3e0:·6564·3a20·6661·6c73·650a·2020·2020·2020··ed:·false.······
0005a3a0:·2020·6d61·736b·3a20·7472·7565·0a20·2020····mask:·true.···0005a3f0:·2020·6d61·736b·3a20·7472·7565·0a3c·2f63····mask:·true.</c
0005a3b0:·2020·202d·206e·616d·653a·2073·7368·642e·····-·name:·sshd. 
0005a3c0:·736f·636b·6574·0a20·2020·2020·2020·2065··socket.········e 
0005a3d0:·6e61·626c·6564·3a20·6661·6c73·650a·2020··nabled:·false.·· 
0005a3e0:·2020·2020·2020·6d61·736b·3a20·7472·7565········mask:·true 
0005a3f0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0005a400:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0005a400:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0005a410:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0005a410:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0005a420:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0005a420:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0005a430:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0005a430:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0005a440:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0005a440:·743d·2223·6964·6d32·3733·3637·2220·7461··t="#idm27367"·ta0005a450:·6964·6d32·3733·3637·2220·7461·6269·6e64··idm27367"·tabind
0005a450:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0005a460:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0005a460:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0005a470:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0005a470:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0005a480:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0005a480:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0005a490:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0005a490:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0005a4a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0005a4a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0005a4b0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
0005a4b0:·4b75·6265·726e·6574·6573·2073·6e69·7070··Kubernetes·snipp 
0005a4c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0005a4c0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0005a4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0005a4d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0005a4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0005a4e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0005a4f0:·6522·2069·643d·2269·646d·3237·3336·3722··e"·id="idm27367"0005a4f0:·6522·2069·643d·2269·646d·3237·3336·3722··e"·id="idm27367"
0005a500:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0005a500:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0005a510:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0005a510:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0005a520:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0005a520:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0005a530:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0005a530:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
1.87 KB
html2text {}
    
Offset 705, 15 lines modifiedOffset 705, 15 lines modified
705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
707 Severity: ···high707 Severity: ···high
708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
709 Identifiers:·CCE-86189-8709 Identifiers:·CCE-86189-8
710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
717 apiVersion:·machineconfiguration.openshift.io/v1717 apiVersion:·machineconfiguration.openshift.io/v1
718 kind:·MachineConfig718 kind:·MachineConfig
719 spec:719 spec:
Offset 724, 15 lines modifiedOffset 724, 15 lines modified
724 ······units:724 ······units:
725 ······-·name:·sshd.service725 ······-·name:·sshd.service
726 ········enabled:·false726 ········enabled:·false
727 ········mask:·true727 ········mask:·true
728 ······-·name:·sshd.socket728 ······-·name:·sshd.socket
729 ········enabled:·false729 ········enabled:·false
730 ········mask:·true730 ········mask:·true
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
736 apiVersion:·machineconfiguration.openshift.io/v1736 apiVersion:·machineconfiguration.openshift.io/v1
737 kind:·MachineConfig737 kind:·MachineConfig
738 spec:738 spec:
9.82 KB
./usr/share/doc/ssg-nondebian/ssg-rhcos4-guide-stig.html
    
Offset 23059, 65 lines modifiedOffset 23059, 65 lines modified
0005a120:·6574·3d22·2369·646d·3237·3336·3622·2074··et="#idm27366"·t0005a120:·6574·3d22·2369·646d·3237·3336·3622·2074··et="#idm27366"·t
0005a130:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0005a130:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0005a140:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0005a140:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0005a150:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0005a150:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0005a160:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0005a160:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0005a170:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0005a170:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0005a180:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0005a180:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0005a190:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><0005a190:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip
 0005a1a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
0005a1a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0005a1b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0005a1b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0005a1c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0005a1c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm20005a1d0:·7365·2220·6964·3d22·6964·6d32·3733·3636··se"·id="idm27366
0005a1d0:·3733·3636·223e·3c74·6162·6c65·2063·6c61··7366"><table·cla0005a1e0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0005a1e0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0005a1f0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0005a1f0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0005a200:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0005a200:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0005a210:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0005a210:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0005a220:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0005a220:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0005a230:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0005a230:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0005a240:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0005a250:·696f·6e3a·3c2f·7468·3e3c·7464·3e6d·6564··ion:</th><td>med 
0005a260:·6975·6d3c·2f74·643e·3c2f·7472·3e3c·7472··ium</td></tr><tr0005a240:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0005a250:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0005a260:·3c2f·7468·3e3c·7464·3e6d·6564·6975·6d3c··</th><td>medium<
 0005a270:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0005a270:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0005a280:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0005a280:·3e3c·7464·3e74·7275·653c·2f74·643e·3c2f··><td>true</td></0005a290:·3e74·7275·653c·2f74·643e·3c2f·7472·3e3c··>true</td></tr><
0005a290:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0005a2a0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0005a2a0:·6567·793a·3c2f·7468·3e3c·7464·3e64·6973··egy:</th><td>dis0005a2b0:·3c2f·7468·3e3c·7464·3e64·6973·6162·6c65··</th><td>disable
0005a2b0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0005a2c0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0005a2c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0005a2d0:·653e·3c70·7265·3e3c·636f·6465·3e61·7069··e><pre><code>api
0005a2d0:·3e61·7069·5665·7273·696f·6e3a·206d·6163··>apiVersion:·mac0005a2e0:·5665·7273·696f·6e3a·206d·6163·6869·6e65··Version:·machine
0005a2e0:·6869·6e65·636f·6e66·6967·7572·6174·696f··hineconfiguratio0005a2f0:·636f·6e66·6967·7572·6174·696f·6e2e·6f70··configuration.op
0005a2f0:·6e2e·6f70·656e·7368·6966·742e·696f·2f76··n.openshift.io/v0005a300:·656e·7368·6966·742e·696f·2f76·310a·6b69··enshift.io/v1.ki
0005a300:·310a·6b69·6e64·3a20·4d61·6368·696e·6543··1.kind:·MachineC0005a310:·6e64·3a20·4d61·6368·696e·6543·6f6e·6669··nd:·MachineConfi
0005a310:·6f6e·6669·670a·7370·6563·3a0a·2020·636f··onfig.spec:.··co0005a320:·670a·7370·6563·3a0a·2020·636f·6e66·6967··g.spec:.··config
0005a320:·6e66·6967·3a0a·2020·2020·6967·6e69·7469··nfig:.····igniti0005a330:·3a0a·2020·2020·6967·6e69·7469·6f6e·3a0a··:.····ignition:.
0005a330:·6f6e·3a0a·2020·2020·2020·7665·7273·696f··on:.······versio0005a340:·2020·2020·2020·7665·7273·696f·6e3a·2033········version:·3
0005a340:·6e3a·2033·2e31·2e30·0a20·2020·2073·7973··n:·3.1.0.····sys0005a350:·2e31·2e30·0a20·2020·2073·7973·7465·6d64··.1.0.····systemd
0005a350:·7465·6d64·3a0a·2020·2020·2020·756e·6974··temd:.······unit0005a360:·3a0a·2020·2020·2020·756e·6974·733a·0a20··:.······units:.·
0005a360:·733a·0a20·2020·2020·202d·206e·616d·653a··s:.······-·name:0005a370:·2020·2020·202d·206e·616d·653a·2073·7368·······-·name:·ssh
0005a370:·2073·7368·642e·7365·7276·6963·650a·2020···sshd.service.··0005a380:·642e·7365·7276·6963·650a·2020·2020·2020··d.service.······
 0005a390:·2020·656e·6162·6c65·643a·2066·616c·7365····enabled:·false
 0005a3a0:·0a20·2020·2020·2020·206d·6173·6b3a·2074··.········mask:·t
 0005a3b0:·7275·650a·2020·2020·2020·2d20·6e61·6d65··rue.······-·name
 0005a3c0:·3a20·7373·6864·2e73·6f63·6b65·740a·2020··:·sshd.socket.··
0005a380:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f0005a3d0:·2020·2020·2020·656e·6162·6c65·643a·2066········enabled:·f
0005a390:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas0005a3e0:·616c·7365·0a20·2020·2020·2020·206d·6173··alse.········mas
0005a3a0:·6b3a·2074·7275·650a·2020·2020·2020·2d20··k:·true.······-· 
0005a3b0:·6e61·6d65·3a20·7373·6864·2e73·6f63·6b65··name:·sshd.socke 
0005a3c0:·740a·2020·2020·2020·2020·656e·6162·6c65··t.········enable 
0005a3d0:·643a·2066·616c·7365·0a20·2020·2020·2020··d:·false.······· 
0005a3e0:·206d·6173·6b3a·2074·7275·650a·3c2f·636f···mask:·true.</co0005a3f0:·6b3a·2074·7275·650a·3c2f·636f·6465·3e3c··k:·true.</code><
0005a3f0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><0005a400:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl
0005a400:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn0005a410:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc
0005a410:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t0005a420:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl
0005a420:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"0005a430:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat
0005a430:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0005a440:·612d·7461·7267·6574·3d22·2369·646d·3237··a-target="#idm27
0005a440:·646d·3237·3336·3722·2074·6162·696e·6465··dm27367"·tabinde0005a450:·3336·3722·2074·6162·696e·6465·783d·2230··367"·tabindex="0
0005a450:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0005a460:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0005a460:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0005a470:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0005a470:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0005a480:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0005a480:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0005a490:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0005a490:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0005a4a0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0005a4b0:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
0005a4a0:·656d·6564·6961·7469·6f6e·204b·7562·6572··emediation·Kuber 
0005a4b0:·6e65·7465·7320·736e·6970·7065·7420·e287··netes·snippet·.. 
0005a4c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0005a4c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0005a4d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0005a4d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0005a4e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0005a4e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0005a4f0:·3d22·6964·6d32·3733·3637·223e·3c74·6162··="idm27367"><tab0005a4f0:·3d22·6964·6d32·3733·3637·223e·3c74·6162··="idm27367"><tab
0005a500:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0005a500:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0005a510:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0005a510:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0005a520:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0005a520:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
1.87 KB
html2text {}
    
Offset 705, 15 lines modifiedOffset 705, 15 lines modified
705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.705 For·more·information·on·how·to·configure·nodes·with·the·Machine·Config·Operator·see·_\x8t_\x8h_\x8e_\x8·_\x8r_\x8e_\x8l_\x8e_\x8v_\x8a_\x8n_\x8t_\x8·_\x8d_\x8o_\x8c_\x8u_\x8m_\x8e_\x8n_\x8t_\x8a_\x8t_\x8i_\x8o_\x8n.
706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.706 Rationale:···Red·Hat·Enterprise·Linux·CoreOS·(RHCOS)·is·a·single-purpose·container·operating·system.·RHCOS·is·only·supported·as·a·component·of·the·OpenShift·Container·Platform.·Remote·management·of·the·RHCOS·nodes·is·performed·at·the·OpenShift·Container·Platform·API·level.·As·a·result,·any·direct·remote·access·to·the·RHCOS·nodes·is·unnecessary.·Disabling·the·SSHD·service·helps·reduce·the·number·of·open·ports·on·each·host.
707 Severity: ···high707 Severity: ···high
708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled708 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_sshd_disabled
709 Identifiers:·CCE-86189-8709 Identifiers:·CCE-86189-8
710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)710 References:··_\x8n_\x8i_\x8s_\x8t········CM-3(6),·IA-2(4)
711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030711 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r·SRG-APP-000185-CTR-000490,·SRG-APP-000141-CTR-000315,·CNTR-OS-001010,·CNTR-OS-001020,·CNTR-OS-001030
712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8712 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8
713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low713 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium714 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true715 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable716 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
717 apiVersion:·machineconfiguration.openshift.io/v1717 apiVersion:·machineconfiguration.openshift.io/v1
718 kind:·MachineConfig718 kind:·MachineConfig
719 spec:719 spec:
Offset 724, 15 lines modifiedOffset 724, 15 lines modified
724 ······units:724 ······units:
725 ······-·name:·sshd.service725 ······-·name:·sshd.service
726 ········enabled:·false726 ········enabled:·false
727 ········mask:·true727 ········mask:·true
728 ······-·name:·sshd.socket728 ······-·name:·sshd.socket
729 ········enabled:·false729 ········enabled:·false
730 ········mask:·true730 ········mask:·true
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_.u_.b_.e_.r_.n_.e_.t_.e_.s_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low732 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium733 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true734 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable735 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
736 apiVersion:·machineconfiguration.openshift.io/v1736 apiVersion:·machineconfiguration.openshift.io/v1
737 kind:·MachineConfig737 kind:·MachineConfig
738 spec:738 spec:
2.8 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_enhanced.html
    
Offset 15095, 281 lines modifiedOffset 15095, 281 lines modified
0003af60:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003af60:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003af70:·3733·3037·2220·7461·6269·6e64·6578·3d22··7307"·tabindex="0003af70:·3733·3037·2220·7461·6269·6e64·6578·3d22··7307"·tabindex="
0003af80:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003af80:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003af90:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003af90:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003afa0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003afa0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003afb0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003afb0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003afc0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003afc0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003afd0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·0003afd0:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
0003afe0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0003aff0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b000:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b010:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b020:·2220·6964·3d22·6964·6d37·3330·3722·3e3c··"·id="idm7307">< 
0003b030:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
0003b040:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
0003b050:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=· 
0003b060:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
0003b070:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003b080:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003b090:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003b0a0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003b0b0:·7267·6574·3d22·2369·646d·3733·3038·2220··rget="#idm7308"· 
0003b0c0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003b0d0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003b0e0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003b0f0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003b100:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003b110:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003b120:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003b130:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003afe0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b140:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003aff0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b150:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003b000:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b160:·643d·2269·646d·3733·3038·223e·3c74·6162··d="idm7308"><tab0003b010:·643d·2269·646d·3733·3037·223e·3c74·6162··d="idm7307"><tab
0003b170:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003b020:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003b180:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003b030:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003b190:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003b040:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003b1a0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003b050:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003b1b0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b060:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003b1c0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b070:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003b1d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003b080:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003b1e0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003b090:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003b1f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b0a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003b200:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003b0b0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003b210:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003b0c0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003b220:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b0d0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003b230:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b0e0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003b240:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003b0f0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003b250:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003b100:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b110:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins
 0003b120:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code
0003b260:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0003b270:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0003b280:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0003b290:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm 
0003b2a0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern 
0003b2b0:·656c·3b20·7468·656e·0a0a·6966·2021·2072··el;·then..if·!·r 
0003b2c0:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003b2d0:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003b2e0:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·" 
0003b2f0:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003b300:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003b310:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003b320:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003b330:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003b340:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003b350:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003b130:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003b360:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003b140:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003b370:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003b150:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003b380:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003b160:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003b390:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm730003b170:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b3a0:·3039·2220·7461·6269·6e64·6578·3d22·3022··09"·tabindex="0"0003b180:·3733·3038·2220·7461·6269·6e64·6578·3d22··7308"·tabindex="
0003b3b0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b190:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b3c0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b1a0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b3d0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b1b0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b3e0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b1c0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b3f0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b1d0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003b1e0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
0003b400:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003b410:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003b420:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b430:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b440:·6170·7365·2220·6964·3d22·6964·6d37·3330··apse"·id="idm730 
0003b450:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class= 
0003b460:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003b470:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003b480:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
0003b490:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003b4a0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003b4b0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b4c0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003b4d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b4e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b4f0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b500:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b510:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b520:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003b530:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003b540:·3c70·7265·3e3c·636f·6465·3e2d·206e·616d··<pre><code>-·nam 
0003b550:·653a·2047·6174·6865·7220·7468·6520·7061··e:·Gather·the·pa 
0003b560:·636b·6167·6520·6661·6374·730a·2020·7061··ckage·facts.··pa 
0003b570:·636b·6167·655f·6661·6374·733a·0a20·2020··ckage_facts:.··· 
0003b580:·206d·616e·6167·6572·3a20·6175·746f·0a20···manager:·auto.· 
0003b590:·2074·6167·733a·0a20·202d·2043·4345·2d39···tags:.··-·CCE-9 
0003b5a0:·3034·3737·2d31·0a20·202d·2043·4a49·532d··0477-1.··-·CJIS- 
0003b5b0:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS 
0003b5c0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003b5d0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003b5e0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003b5f0:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
0003b600:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
0003b610:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
0003b620:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
0003b630:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
0003b640:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
0003b650:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
0003b660:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
0003b670:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name 
0003b680:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is 
0003b690:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac 
0003b6a0:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:· 
0003b6b0:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:· 
0003b6c0:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:· 
0003b6d0:·2722·6b65·726e·656c·2220·696e·2061·6e73··'"kernel"·in·ans 
0003b6e0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
0003b6f0:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··- 
0003b700:·2043·4345·2d39·3034·3737·2d31·0a20·202d···CCE-90477-1.··- 
0003b710:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
Max diff block lines reached; 2683438/2720864 bytes (98.62%) of diff not shown.
207 KB
html2text {}
    
Offset 102, 19 lines modifiedOffset 102, 21 lines modified
102 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)102 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
103 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3103 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
104 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5104 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
105 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199105 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
106 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79106 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
107 ·············_\x8c_\x8i_\x8s············6.1.1107 ·············_\x8c_\x8i_\x8s············6.1.1
108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
109 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8109 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 110 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 111 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 112 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 113 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 114 package·install·aide
110 [[packages]] 
111 name·=·"aide" 
112 version·=·"*" 
113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
118 #·Remediation·is·applicable·only·in·certain·platforms120 #·Remediation·is·applicable·only·in·certain·platforms
119 if·rpm·--quiet·-q·kernel;·then121 if·rpm·--quiet·-q·kernel;·then
Offset 160, 14 lines modifiedOffset 162, 26 lines modified
160 ··-·PCI-DSSv4-11.5.2162 ··-·PCI-DSSv4-11.5.2
161 ··-·enable_strategy163 ··-·enable_strategy
162 ··-·low_complexity164 ··-·low_complexity
163 ··-·low_disruption165 ··-·low_disruption
164 ··-·medium_severity166 ··-·medium_severity
165 ··-·no_reboot_needed167 ··-·no_reboot_needed
166 ··-·package_aide_installed168 ··-·package_aide_installed
 169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 174 package·--add=aide
 175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 176 [[packages]]
 177 name·=·"aide"
 178 version·=·"*"
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
172 dnf·install·aide184 dnf·install·aide
Offset 179, 28 lines modifiedOffset 193, 14 lines modified
179 include·install_aide193 include·install_aide
  
180 class·install_aide·{194 class·install_aide·{
181 ··package·{·'aide':195 ··package·{·'aide':
182 ····ensure·=>·'installed',196 ····ensure·=>·'installed',
183 ··}197 ··}
184 }198 }
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
190 package·install·aide 
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
196 package·--add=aide 
197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
198 Run·the·following·command·to·generate·a·new·database:200 Run·the·following·command·to·generate·a·new·database:
199 $·sudo·/usr/sbin/aide·--init201 $·sudo·/usr/sbin/aide·--init
200 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
201 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz203 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
202 To·initiate·a·manual·check,·run·the·following·command:204 To·initiate·a·manual·check,·run·the·following·command:
203 $·sudo·/usr/sbin/aide·--check205 $·sudo·/usr/sbin/aide·--check
Offset 342, 26 lines modifiedOffset 342, 26 lines modified
342 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*342 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
343 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.343 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
344 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.344 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
345 Severity: ···medium345 Severity: ···medium
346 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot346 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
347 Identifiers:·CCE-90755-0347 Identifiers:·CCE-90755-0
348 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28348 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
349 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
350 [[customizations.filesystem]] 
351 mountpoint·=·"/boot" 
352 size·=·1073741824 
353 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8349 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
354 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low350 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
355 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high351 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
356 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false352 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
357 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable353 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
358 part·/boot354 part·/boot
 355 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 356 [[customizations.filesystem]]
 357 mountpoint·=·"/boot"
 358 size·=·1073741824
359 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*359 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
360 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.360 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
361 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.361 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
362 Severity: ···low362 Severity: ···low
363 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home363 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home
364 Identifiers:·CCE-88231-6364 Identifiers:·CCE-88231-6
365 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8365 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 370, 95 lines modifiedOffset 370, 95 lines modified
370 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6370 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
371 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3371 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
372 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)372 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
373 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4373 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
374 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227374 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
375 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28375 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
376 ·············_\x8c_\x8i_\x8s············1.1.2.3.1376 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
378 [[customizations.filesystem]] 
379 mountpoint·=·"/home" 
380 size·=·1073741824 
381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 205231/211667 bytes (96.96%) of diff not shown.
2.91 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_high.html
    
Offset 15100, 281 lines modifiedOffset 15100, 281 lines modified
0003afb0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003afb0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003afc0:·6964·6d37·3330·3722·2074·6162·696e·6465··idm7307"·tabinde0003afc0:·6964·6d37·3330·3722·2074·6162·696e·6465··idm7307"·tabinde
0003afd0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003afd0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003afe0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003afe0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003aff0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003aff0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b000:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b000:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b010:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b010:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b020:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003b020:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
0003b030:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003b040:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b050:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b060:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b070:·7073·6522·2069·643d·2269·646d·3733·3037··pse"·id="idm7307 
0003b080:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003b090:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003b0a0:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003b0b0:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003b0c0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b0d0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b0e0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b0f0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b100:·2d74·6172·6765·743d·2223·6964·6d37·3330··-target="#idm730 
0003b110:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"· 
0003b120:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b130:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b140:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b150:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b160:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b170:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b180:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003b030:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003b190:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003b040:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003b1a0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003b050:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003b1b0:·2220·6964·3d22·6964·6d37·3330·3822·3e3c··"·id="idm7308"><0003b060:·2220·6964·3d22·6964·6d37·3330·3722·3e3c··"·id="idm7307"><
0003b1c0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003b070:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003b1d0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003b080:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003b1e0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003b090:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003b1f0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003b0a0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003b200:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003b0b0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b210:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003b0c0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003b0d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b0e0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003b0f0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b100:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003b110:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003b220:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b120:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b230:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b240:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b250:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b260:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b270:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b280:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>0003b130:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
0003b290:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><0003b140:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
0003b2a0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre0003b150:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b160:·3e3c·636f·6465·3e0a·7061·636b·6167·6520··><code>.package·
 0003b170:·696e·7374·616c·6c20·6169·6465·0a3c·2f63··install·aide.</c
0003b2b0:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003b2c0:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003b2d0:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b2e0:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b2f0:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003b300:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if· 
0003b310:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003b320:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003b330:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
0003b340:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003b350:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b360:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b370:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b380:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b390:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b3a0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003b180:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
0003b3b0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003b190:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
0003b3c0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003b1a0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
0003b3d0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003b1b0:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
0003b3e0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b1c0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b3f0:·6d37·3330·3922·2074·6162·696e·6465·783d··m7309"·tabindex=0003b1d0:·6964·6d37·3330·3822·2074·6162·696e·6465··idm7308"·tabinde
0003b400:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b1e0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b410:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b1f0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b420:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b200:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b430:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b210:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b440:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b220:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
 0003b230:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0003b450:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b460:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b470:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b480:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b490:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b4a0:·3733·3039·223e·3c74·6162·6c65·2063·6c61··7309"><table·cla 
0003b4b0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b4c0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b4d0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b4e0:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b4f0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b500:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b510:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b520:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b530:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b540:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b550:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b560:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b570:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b580:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b590:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
0003b5a0:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
0003b5b0:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
0003b5c0:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
0003b5d0:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
0003b5e0:·6f0a·2020·7461·6773·3a0a·2020·2d20·4343··o.··tags:.··-·CC 
0003b5f0:·452d·3930·3437·372d·310a·2020·2d20·434a··E-90477-1.··-·CJ 
0003b600:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003b610:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003b620:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003b630:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003b640:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003b650:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003b660:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003b670:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003b680:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003b690:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003b6a0:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003b6b0:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003b6c0:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
0003b6d0:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
0003b6e0:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
0003b6f0:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
0003b700:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
0003b710:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe 
Max diff block lines reached; 2795604/2833030 bytes (98.68%) of diff not shown.
215 KB
html2text {}
    
Offset 103, 19 lines modifiedOffset 103, 21 lines modified
103 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)103 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
104 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3104 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
108 ·············_\x8c_\x8i_\x8s············6.1.1108 ·············_\x8c_\x8i_\x8s············6.1.1
109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 115 package·install·aide
111 [[packages]] 
112 name·=·"aide" 
113 version·=·"*" 
114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
119 #·Remediation·is·applicable·only·in·certain·platforms121 #·Remediation·is·applicable·only·in·certain·platforms
120 if·rpm·--quiet·-q·kernel;·then122 if·rpm·--quiet·-q·kernel;·then
Offset 161, 14 lines modifiedOffset 163, 26 lines modified
161 ··-·PCI-DSSv4-11.5.2163 ··-·PCI-DSSv4-11.5.2
162 ··-·enable_strategy164 ··-·enable_strategy
163 ··-·low_complexity165 ··-·low_complexity
164 ··-·low_disruption166 ··-·low_disruption
165 ··-·medium_severity167 ··-·medium_severity
166 ··-·no_reboot_needed168 ··-·no_reboot_needed
167 ··-·package_aide_installed169 ··-·package_aide_installed
 170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 175 package·--add=aide
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 177 [[packages]]
 178 name·=·"aide"
 179 version·=·"*"
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
173 dnf·install·aide185 dnf·install·aide
Offset 180, 28 lines modifiedOffset 194, 14 lines modified
180 include·install_aide194 include·install_aide
  
181 class·install_aide·{195 class·install_aide·{
182 ··package·{·'aide':196 ··package·{·'aide':
183 ····ensure·=>·'installed',197 ····ensure·=>·'installed',
184 ··}198 ··}
185 }199 }
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
191 package·install·aide 
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·--add=aide 
198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
199 Run·the·following·command·to·generate·a·new·database:201 Run·the·following·command·to·generate·a·new·database:
200 $·sudo·/usr/sbin/aide·--init202 $·sudo·/usr/sbin/aide·--init
201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
202 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
203 To·initiate·a·manual·check,·run·the·following·command:205 To·initiate·a·manual·check,·run·the·following·command:
204 $·sudo·/usr/sbin/aide·--check206 $·sudo·/usr/sbin/aide·--check
Offset 855, 26 lines modifiedOffset 855, 26 lines modified
855 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*855 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
856 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.856 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
857 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.857 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
858 Severity: ···medium858 Severity: ···medium
859 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot859 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
860 Identifiers:·CCE-90755-0860 Identifiers:·CCE-90755-0
861 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28861 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
862 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
863 [[customizations.filesystem]] 
864 mountpoint·=·"/boot" 
865 size·=·1073741824 
866 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8862 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
867 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low863 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
868 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high864 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
869 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false865 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
870 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable866 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
871 part·/boot867 part·/boot
 868 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 869 [[customizations.filesystem]]
 870 mountpoint·=·"/boot"
 871 size·=·1073741824
872 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*872 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
873 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.873 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
874 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.874 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
875 Severity: ···low875 Severity: ···low
876 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home876 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home
877 Identifiers:·CCE-88231-6877 Identifiers:·CCE-88231-6
878 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8878 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 883, 95 lines modifiedOffset 883, 95 lines modified
883 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6883 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·3.1,·SR·3.5,·SR·3.8,·SR·4.1,·SR·4.3,·SR·5.1,·SR·5.2,·SR·5.3,·SR·7.1,·SR·7.6
884 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3884 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
885 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)885 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
886 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4886 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
887 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227887 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
888 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28888 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
889 ·············_\x8c_\x8i_\x8s············1.1.2.3.1889 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
891 [[customizations.filesystem]] 
892 mountpoint·=·"/home" 
893 size·=·1073741824 
894 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 213647/220083 bytes (97.08%) of diff not shown.
1.62 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_intermediary.html
    
Offset 15091, 281 lines modifiedOffset 15091, 281 lines modified
0003af20:·2d74·6172·6765·743d·2223·6964·6d37·3330··-target="#idm7300003af20:·2d74·6172·6765·743d·2223·6964·6d37·3330··-target="#idm730
0003af30:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·0003af30:·3722·2074·6162·696e·6465·783d·2230·2220··7"·tabindex="0"·
0003af40:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003af40:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003af50:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003af50:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003af60:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003af60:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003af70:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003af70:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003af80:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003af80:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003af90:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003afa0:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003afb0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003afc0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003afd0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003afe0:·643d·2269·646d·3733·3037·223e·3c70·7265··d="idm7307"><pre 
0003aff0:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003b000:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003b010:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003b020:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b030:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b040:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b050:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b060:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b070:·743d·2223·6964·6d37·3330·3822·2074·6162··t="#idm7308"·tab 
0003b080:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b090:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b0a0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b0b0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b0c0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b0d0:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003b0e0:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<0003af90:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...<
0003b0f0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003afa0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003b100:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003afb0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003b110:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003afc0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003b120:·6964·6d37·3330·3822·3e3c·7461·626c·6520··idm7308"><table·0003afd0:·6964·6d37·3330·3722·3e3c·7461·626c·6520··idm7307"><table·
0003b130:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003afe0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003b140:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003aff0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003b150:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003b000:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003b160:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003b010:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003b170:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003b020:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003b180:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003b030:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003b190:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr0003b040:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
0003b1a0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003b050:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
0003b1b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b060:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b1c0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003b070:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
0003b1d0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><0003b080:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
0003b1e0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra0003b090:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
0003b1f0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en0003b0a0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
0003b200:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></0003b0b0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003b210:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code0003b0c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b0d0:·3e0a·7061·636b·6167·6520·696e·7374·616c··>.package·instal
0003b220:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003b230:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003b240:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003b250:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·-- 
0003b260:·7175·6965·7420·2d71·206b·6572·6e65·6c3b··quiet·-q·kernel; 
0003b270:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003b280:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
0003b290:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf 
0003b2a0:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003b2b0:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
0003b2c0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003b2d0:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003b2e0:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003b2f0:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003b300:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr0003b0e0:·6c20·6169·6465·0a3c·2f63·6f64·653e·3c2f··l·aide.</code></
0003b310:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003b0f0:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003b320:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003b100:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003b330:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003b110:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003b340:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003b120:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003b350:·6172·6765·743d·2223·6964·6d37·3330·3922··arget="#idm7309"0003b130:·2d74·6172·6765·743d·2223·6964·6d37·3330··-target="#idm730
0003b360:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b140:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
0003b370:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b150:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b380:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b160:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b390:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b170:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b3a0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b180:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b3b0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b190:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003b1a0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
0003b3c0:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003b3d0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b3e0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b3f0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b400:·6522·2069·643d·2269·646d·3733·3039·223e··e"·id="idm7309"> 
0003b410:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003b420:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003b430:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003b440:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003b450:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003b460:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003b470:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b480:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b490:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b4a0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b4b0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b4c0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003b4d0:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b4e0:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b4f0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b500:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:· 
0003b510:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa 
0003b520:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa 
0003b530:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma 
0003b540:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta 
0003b550:·6773·3a0a·2020·2d20·4343·452d·3930·3437··gs:.··-·CCE-9047 
0003b560:·372d·310a·2020·2d20·434a·4953·2d35·2e31··7-1.··-·CJIS-5.1 
0003b570:·302e·312e·330a·2020·2d20·4e49·5354·2d38··0.1.3.··-·NIST-8 
0003b580:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).·· 
0003b590:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11 
0003b5a0:·2e35·0a20·202d·2050·4349·2d44·5353·7634··.5.··-·PCI-DSSv4 
0003b5b0:·2d31·312e·352e·320a·2020·2d20·656e·6162··-11.5.2.··-·enab 
0003b5c0:·6c65·5f73·7472·6174·6567·790a·2020·2d20··le_strategy.··-· 
0003b5d0:·6c6f·775f·636f·6d70·6c65·7869·7479·0a20··low_complexity.· 
0003b5e0:·202d·206c·6f77·5f64·6973·7275·7074·696f···-·low_disruptio 
0003b5f0:·6e0a·2020·2d20·6d65·6469·756d·5f73·6576··n.··-·medium_sev 
0003b600:·6572·6974·790a·2020·2d20·6e6f·5f72·6562··erity.··-·no_reb 
0003b610:·6f6f·745f·6e65·6564·6564·0a20·202d·2070··oot_needed.··-·p 
0003b620:·6163·6b61·6765·5f61·6964·655f·696e·7374··ackage_aide_inst 
0003b630:·616c·6c65·640a·0a2d·206e·616d·653a·2045··alled..-·name:·E 
0003b640:·6e73·7572·6520·6169·6465·2069·7320·696e··nsure·aide·is·in 
0003b650:·7374·616c·6c65·640a·2020·7061·636b·6167··stalled.··packag 
0003b660:·653a·0a20·2020·206e·616d·653a·2061·6964··e:.····name:·aid 
0003b670:·650a·2020·2020·7374·6174·653a·2070·7265··e.····state:·pre 
0003b680:·7365·6e74·0a20·2077·6865·6e3a·2027·226b··sent.··when:·'"k 
0003b690:·6572·6e65·6c22·2069·6e20·616e·7369·626c··ernel"·in·ansibl 
0003b6a0:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages 
0003b6b0:·270a·2020·7461·6773·3a0a·2020·2d20·4343··'.··tags:.··-·CC 
0003b6c0:·452d·3930·3437·372d·310a·2020·2d20·434a··E-90477-1.··-·CJ 
0003b6d0:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003b6e0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
Max diff block lines reached; 1526354/1563780 bytes (97.61%) of diff not shown.
130 KB
html2text {}
    
Offset 118, 19 lines modifiedOffset 118, 21 lines modified
118 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)118 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
119 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3119 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79122 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
123 ·············_\x8c_\x8i_\x8s············6.1.1123 ·············_\x8c_\x8i_\x8s············6.1.1
124 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2124 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 130 package·install·aide
126 [[packages]] 
127 name·=·"aide" 
128 version·=·"*" 
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
134 #·Remediation·is·applicable·only·in·certain·platforms136 #·Remediation·is·applicable·only·in·certain·platforms
135 if·rpm·--quiet·-q·kernel;·then137 if·rpm·--quiet·-q·kernel;·then
Offset 176, 14 lines modifiedOffset 178, 26 lines modified
176 ··-·PCI-DSSv4-11.5.2178 ··-·PCI-DSSv4-11.5.2
177 ··-·enable_strategy179 ··-·enable_strategy
178 ··-·low_complexity180 ··-·low_complexity
179 ··-·low_disruption181 ··-·low_disruption
180 ··-·medium_severity182 ··-·medium_severity
181 ··-·no_reboot_needed183 ··-·no_reboot_needed
182 ··-·package_aide_installed184 ··-·package_aide_installed
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 190 package·--add=aide
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 192 [[packages]]
 193 name·=·"aide"
 194 version·=·"*"
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
188 dnf·install·aide200 dnf·install·aide
Offset 195, 28 lines modifiedOffset 209, 14 lines modified
195 include·install_aide209 include·install_aide
  
196 class·install_aide·{210 class·install_aide·{
197 ··package·{·'aide':211 ··package·{·'aide':
198 ····ensure·=>·'installed',212 ····ensure·=>·'installed',
199 ··}213 ··}
200 }214 }
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
206 package·install·aide 
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
212 package·--add=aide 
213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
214 Run·the·following·command·to·generate·a·new·database:216 Run·the·following·command·to·generate·a·new·database:
215 $·sudo·/usr/sbin/aide·--init217 $·sudo·/usr/sbin/aide·--init
216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
217 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these219 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
218 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their220 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
219 integrity.·The·newly-generated·database·can·be·installed·as·follows:221 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 378, 26 lines modifiedOffset 378, 26 lines modified
378 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.378 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
379 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition379 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition
380 ·············should·be·restricted.380 ·············should·be·restricted.
381 Severity: ···medium381 Severity: ···medium
382 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot382 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
383 Identifiers:·CCE-90755-0383 Identifiers:·CCE-90755-0
384 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28384 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
386 [[customizations.filesystem]] 
387 mountpoint·=·"/boot" 
388 size·=·1073741824 
389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
390 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low386 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
391 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high387 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
392 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false388 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
393 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable389 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
394 part·/boot390 part·/boot
 391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 392 [[customizations.filesystem]]
 393 mountpoint·=·"/boot"
 394 size·=·1073741824
395 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*395 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
396 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at396 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at
397 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such397 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such
398 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the398 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
399 mountpoint·can·instead·be·configured·later.399 mountpoint·can·instead·be·configured·later.
400 ·············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more400 ·············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more
401 Rationale:···restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill401 Rationale:···restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill
Offset 412, 105 lines modifiedOffset 412, 105 lines modified
412 ····························SR·7.6412 ····························SR·7.6
413 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3413 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.13.1.1,·A.13.2.1,·A.14.1.3
414 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)414 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
415 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4415 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
416 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227416 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
417 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28417 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
418 ·············_\x8c_\x8i_\x8s············1.1.2.3.1418 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
419 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
420 [[customizations.filesystem]] 
421 mountpoint·=·"/home" 
422 size·=·1073741824 
423 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8419 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 127848/133472 bytes (95.79%) of diff not shown.
216 KB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-anssi_bp28_minimal.html
    
Offset 14772, 297 lines modifiedOffset 14772, 297 lines modified
00039b30:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm1000039b30:·612d·7461·7267·6574·3d22·2369·646d·3130··a-target="#idm10
00039b40:·3630·3722·2074·6162·696e·6465·783d·2230··607"·tabindex="000039b40:·3630·3722·2074·6162·696e·6465·783d·2230··607"·tabindex="0
00039b50:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00039b50:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00039b60:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00039b60:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00039b70:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00039b70:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00039b80:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00039b80:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00039b90:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00039b90:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00039ba0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B 
00039bb0:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet00039ba0:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
 00039bb0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00039bc0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00039bd0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00039be0:·3d22·6964·6d31·3036·3037·223e·3c74·6162··="idm10607"><tab
 00039bf0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 00039c00:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00039c10:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00039c20:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00039c30:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00039c40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00039c50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00039c60:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00039c70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00039c80:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00039c90:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 00039ca0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00039cb0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00039cc0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00039cd0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00039ce0:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins
 00039cf0:·7461·6c6c·2064·6e66·2d61·7574·6f6d·6174··tall·dnf-automat
 00039d00:·6963·0a3c·2f63·6f64·653e·3c2f·7072·653e··ic.</code></pre>
 00039d10:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 00039d20:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 00039d30:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 00039d40:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 00039d50:·6765·743d·2223·6964·6d31·3036·3038·2220··get="#idm10608"·
 00039d60:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 00039d70:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 00039d80:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 00039d90:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 00039da0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 00039db0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 00039dc0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
00039bc0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div00039dd0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00039bd0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co00039de0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00039be0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00039df0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00039bf0:·2069·643d·2269·646d·3130·3630·3722·3e3c···id="idm10607"><00039e00:·643d·2269·646d·3130·3630·3822·3e3c·7461··d="idm10608"><ta
 00039e10:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 00039e20:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 00039e30:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 00039e40:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 00039e50:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 00039e60:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 00039e70:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00039e80:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 00039e90:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00039ea0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 00039eb0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 00039ec0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00039ed0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00039c00:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
00039c10:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
00039c20:·646e·662d·6175·746f·6d61·7469·6322·0a76··dnf-automatic".v 
00039c30:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
00039c40:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00039c50:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00039c60:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00039c70:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00039c80:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00039c90:·6964·6d31·3036·3038·2220·7461·6269·6e64··idm10608"·tabind 
00039ca0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00039cb0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00039cc0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00039cd0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00039ce0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00039cf0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
00039d00:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
00039d10:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
00039d20:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
00039d30:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
00039d40:·3130·3630·3822·3e3c·7461·626c·6520·636c··10608"><table·cl 
00039d50:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
00039d60:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00039d70:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00039d80:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00039d90:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00039da0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00039db0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00039dc0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
00039dd0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00039de0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
00039df0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t00039ee0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
00039e00:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
00039e10:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
00039e20:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
00039e30:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
00039e40:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
00039e50:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
00039e60:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
00039e70:·6f72·6d73·0a69·6620·2120·2820·7b20·7270··orms.if·!·(·{·rp 
00039e80:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker00039ef0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00039f00:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 00039f10:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 00039f20:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 00039f30:·2070·6c61·7466·6f72·6d73·0a69·6620·2120···platforms.if·!·
 00039f40:·2820·7b20·7270·6d20·2d2d·7175·6965·7420··(·{·rpm·--quiet·
 00039f50:·2d71·206b·6572·6e65·6c20·3b7d·2026·616d··-q·kernel·;}·&am
 00039f60:·703b·2661·6d70·3b20·7b20·7270·6d20·2d2d··p;&amp;·{·rpm·--
 00039f70:·7175·6965·7420·2d71·2072·706d·2d6f·7374··quiet·-q·rpm-ost
00039e90:·6e65·6c20·3b7d·2026·616d·703b·2661·6d70··nel·;}·&amp;&amp00039f80:·7265·6520·3b7d·2026·616d·703b·2661·6d70··ree·;}·&amp;&amp
00039ea0:·3b20·7b20·7270·6d20·2d2d·7175·6965·7420··;·{·rpm·--quiet·00039f90:·3b20·7b20·7270·6d20·2d2d·7175·6965·7420··;·{·rpm·--quiet·
00039eb0:·2d71·2072·706d·2d6f·7374·7265·6520·3b7d··-q·rpm-ostree·;} 
00039ec0:·2026·616d·703b·2661·6d70·3b20·7b20·7270···&amp;&amp;·{·rp 
00039ed0:·6d20·2d2d·7175·6965·7420·2d71·2062·6f6f··m·--quiet·-q·boo 
00039ee0:·7463·203b·7d20·2661·6d70·3b26·616d·703b··tc·;}·&amp;&amp; 
00039ef0:·207b·2021·2072·706d·202d·2d71·7569·6574···{·!·rpm·--quiet00039fa0:·2d71·2062·6f6f·7463·203b·7d20·2661·6d70··-q·bootc·;}·&amp
 00039fb0:·3b26·616d·703b·207b·2021·2072·706d·202d··;&amp;·{·!·rpm·-
 00039fc0:·2d71·7569·6574·202d·7120·6f70·656e·7368··-quiet·-q·opensh
 00039fd0:·6966·742d·6b75·6265·6c65·7420·3b7d·2029··ift-kubelet·;}·)
 00039fe0:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 00039ff0:·202d·7120·2d2d·7175·6965·7420·2264·6e66···-q·--quiet·"dnf
 0003a000:·2d61·7574·6f6d·6174·6963·2220·3b20·7468··-automatic"·;·th
 0003a010:·656e·0a20·2020·2064·6e66·2069·6e73·7461··en.····dnf·insta
 0003a020:·6c6c·202d·7920·2264·6e66·2d61·7574·6f6d··ll·-y·"dnf-autom
 0003a030:·6174·6963·220a·6669·0a0a·656c·7365·0a20··atic".fi..else.·
 0003a040:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003a050:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
Max diff block lines reached; 163808/203442 bytes (80.52%) of diff not shown.
16.9 KB
html2text {}
    
Offset 84, 19 lines modifiedOffset 84, 21 lines modified
84 ·············suitable·for·automatic,·regular·execution.84 ·············suitable·for·automatic,·regular·execution.
85 Severity: ···medium85 Severity: ···medium
86 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed86 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
87 Identifiers:·CCE-87561-787 Identifiers:·CCE-87561-7
88 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.288 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
89 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008089 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
90 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R6190 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
91 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x891 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 92 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 93 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 94 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 95 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 96 package·install·dnf-automatic
92 [[packages]] 
93 name·=·"dnf-automatic" 
94 version·=·"*" 
95 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x897 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
96 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low98 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
97 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low99 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
98 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false100 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
99 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable101 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
100 #·Remediation·is·applicable·only·in·certain·platforms102 #·Remediation·is·applicable·only·in·certain·platforms
101 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc103 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc
Offset 138, 14 lines modifiedOffset 140, 26 lines modified
138 ··-·CCE-87561-7140 ··-·CCE-87561-7
139 ··-·enable_strategy141 ··-·enable_strategy
140 ··-·low_complexity142 ··-·low_complexity
141 ··-·low_disruption143 ··-·low_disruption
142 ··-·medium_severity144 ··-·medium_severity
143 ··-·no_reboot_needed145 ··-·no_reboot_needed
144 ··-·package_dnf-automatic_installed146 ··-·package_dnf-automatic_installed
 147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 152 package·--add=dnf-automatic
 153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 154 [[packages]]
 155 name·=·"dnf-automatic"
 156 version·=·"*"
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
150 dnf·install·dnf-automatic162 dnf·install·dnf-automatic
Offset 157, 28 lines modifiedOffset 171, 14 lines modified
157 include·install_dnf-automatic171 include·install_dnf-automatic
  
158 class·install_dnf-automatic·{172 class·install_dnf-automatic·{
159 ··package·{·'dnf-automatic':173 ··package·{·'dnf-automatic':
160 ····ensure·=>·'installed',174 ····ensure·=>·'installed',
161 ··}175 ··}
162 }176 }
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
168 package·install·dnf-automatic 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·--add=dnf-automatic 
175 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*177 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
176 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed178 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
177 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/179 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
178 automatic.conf.180 automatic.conf.
179 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation181 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
180 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and182 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
181 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in183 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 9382, 14 lines modifiedOffset 9382, 21 lines modified
9382 Rationale:···Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally9382 Rationale:···Removing·the·DHCP·server·ensures·that·it·cannot·be·easily·or·accidentally
9383 ·············reactivated·and·disrupt·network·operation.9383 ·············reactivated·and·disrupt·network·operation.
9384 Severity: ···medium9384 Severity: ···medium
9385 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_kea_removed9385 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_kea_removed
9386 Identifiers:·CCE-86596-49386 Identifiers:·CCE-86596-4
9387 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R629387 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R62
9388 ·············_\x8c_\x8i_\x8s···2.1.39388 ·············_\x8c_\x8i_\x8s···2.1.3
 9389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 9390 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9391 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9392 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9393 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 9394 package·remove·kea
9389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89395 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9390 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9396 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9391 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9397 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9392 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9398 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9393 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable9399 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
9394 #·CAUTION:·This·remediation·script·will·remove·kea9400 #·CAUTION:·This·remediation·script·will·remove·kea
Offset 9414, 14 lines modifiedOffset 9421, 21 lines modified
9414 ··-·CCE-86596-49421 ··-·CCE-86596-4
9415 ··-·disable_strategy9422 ··-·disable_strategy
9416 ··-·low_complexity9423 ··-·low_complexity
9417 ··-·low_disruption9424 ··-·low_disruption
9418 ··-·medium_severity9425 ··-·medium_severity
9419 ··-·no_reboot_needed9426 ··-·no_reboot_needed
9420 ··-·package_kea_removed9427 ··-·package_kea_removed
 9428 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 9429 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 9430 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 9431 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 9432 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 9433 package·--remove=kea
9421 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89434 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9422 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9435 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9423 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9436 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9424 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9437 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9425 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable9438 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
9426 dnf·remove·kea9439 dnf·remove·kea
Offset 9433, 28 lines modifiedOffset 9447, 14 lines modified
9433 include·remove_kea9447 include·remove_kea
  
Max diff block lines reached; 12301/17318 bytes (71.03%) of diff not shown.
4.3 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis.html
    
Offset 15141, 281 lines modifiedOffset 15141, 281 lines modified
0003b240:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b240:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b250:·743d·2223·6964·6d37·3330·3722·2074·6162··t="#idm7307"·tab0003b250:·743d·2223·6964·6d37·3330·3722·2074·6162··t="#idm7307"·tab
0003b260:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b260:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b270:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b270:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b280:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b280:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b290:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b290:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b2a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b2a0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b2b0:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003b2b0:·2122·3e52·656d·6564·6961·7469·6f6e·2073··!">Remediation·s
0003b2c0:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003b2d0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b2e0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b2f0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b300:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b310:·3733·3037·223e·3c70·7265·3e3c·636f·6465··7307"><pre><code 
0003b320:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003b330:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003b340:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003b350:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b360:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b370:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b380:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b390:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b3a0:·6d37·3330·3822·2074·6162·696e·6465·783d··m7308"·tabindex= 
0003b3b0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b3c0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b3d0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b3e0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b3f0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b400:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s 
0003b410:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br0003b2c0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
0003b420:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003b2d0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
0003b430:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003b2e0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
0003b440:·6170·7365·2220·6964·3d22·6964·6d37·3330··apse"·id="idm7300003b2f0:·6170·7365·2220·6964·3d22·6964·6d37·3330··apse"·id="idm730
0003b450:·3822·3e3c·7461·626c·6520·636c·6173·733d··8"><table·class=0003b300:·3722·3e3c·7461·626c·6520·636c·6173·733d··7"><table·class=
0003b460:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str0003b310:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
0003b470:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde0003b320:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
0003b480:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003b330:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
0003b490:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com0003b340:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
0003b4a0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td0003b350:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
0003b4b0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003b360:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003b4c0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption0003b370:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
0003b4d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b4e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003b4f0:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
0003b500:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
0003b510:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
0003b520:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</ 
0003b530:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table> 
0003b540:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem 
0003b550:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl 
0003b560:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c 
0003b570:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms 
0003b580:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet· 
0003b590:·2d71·206b·6572·6e65·6c3b·2074·6865·6e0a··-q·kernel;·then. 
0003b5a0:·0a69·6620·2120·7270·6d20·2d71·202d·2d71··.if·!·rpm·-q·--q 
0003b5b0:·7569·6574·2022·6169·6465·2220·3b20·7468··uiet·"aide"·;·th 
0003b5c0:·656e·0a20·2020·2064·6e66·2069·6e73·7461··en.····dnf·insta 
0003b5d0:·6c6c·202d·7920·2261·6964·6522·0a66·690a··ll·-y·"aide".fi. 
0003b5e0:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a 
0003b5f0:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed 
0003b600:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap 
0003b610:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin 
0003b620:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.< 
0003b630:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b640:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b650:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b660:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b670:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b680:·2223·6964·6d37·3330·3922·2074·6162·696e··"#idm7309"·tabin 
0003b690:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b6a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b6b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b6c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b6d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b6e0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans 
0003b6f0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·... 
0003b700:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b710:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b720:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b730:·2269·646d·3733·3039·223e·3c74·6162·6c65··"idm7309"><table 
0003b740:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta 
0003b750:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl 
0003b760:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table 
0003b770:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr> 
0003b780:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:< 
0003b790:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b7a0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis 
0003b7b0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td 
0003b7c0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003b7d0:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t 
0003b7e0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td> 
0003b7f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str 
0003b800:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e 
0003b810:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr>< 
0003b820:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod 
0003b830:·653e·2d20·6e61·6d65·3a20·4761·7468·6572··e>-·name:·Gather 
0003b840:·2074·6865·2070·6163·6b61·6765·2066·6163···the·package·fac 
0003b850:·7473·0a20·2070·6163·6b61·6765·5f66·6163··ts.··package_fac 
0003b860:·7473·3a0a·2020·2020·6d61·6e61·6765·723a··ts:.····manager: 
0003b870:·2061·7574·6f0a·2020·7461·6773·3a0a·2020···auto.··tags:.·· 
0003b880:·2d20·4343·452d·3930·3437·372d·310a·2020··-·CCE-90477-1.·· 
0003b890:·2d20·434a·4953·2d35·2e31·302e·312e·330a··-·CJIS-5.10.1.3. 
0003b8a0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
0003b8b0:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI- 
0003b8c0:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··- 
0003b8d0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5. 
0003b8e0:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str 
0003b8f0:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co 
0003b900:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low 
0003b910:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-· 
0003b920:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity. 
0003b930:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne 
0003b940:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package 
0003b950:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed. 
0003b960:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure· 
0003b970:·6169·6465·2069·7320·696e·7374·616c·6c65··aide·is·installe 
0003b980:·640a·2020·7061·636b·6167·653a·0a20·2020··d.··package:.··· 
0003b990:·206e·616d·653a·2061·6964·650a·2020·2020···name:·aide.···· 
0003b9a0:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.· 
0003b9b0:·2077·6865·6e3a·2027·226b·6572·6e65·6c22···when:·'"kernel" 
0003b9c0:·2069·6e20·616e·7369·626c·655f·6661·6374···in·ansible_fact 
0003b9d0:·732e·7061·636b·6167·6573·270a·2020·7461··s.packages'.··ta 
0003b9e0:·6773·3a0a·2020·2d20·4343·452d·3930·3437··gs:.··-·CCE-9047 
0003b9f0:·372d·310a·2020·2d20·434a·4953·2d35·2e31··7-1.··-·CJIS-5.1 
0003ba00:·302e·312e·330a·2020·2d20·4e49·5354·2d38··0.1.3.··-·NIST-8 
0003ba10:·3030·2d35·332d·434d·2d36·2861·290a·2020··00-53-CM-6(a).·· 
0003ba20:·2d20·5043·492d·4453·532d·5265·712d·3131··-·PCI-DSS-Req-11 
Max diff block lines reached; 4112473/4149899 bytes (99.10%) of diff not shown.
348 KB
html2text {}
    
Offset 109, 19 lines modifiedOffset 109, 21 lines modified
109 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)109 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
110 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3110 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
112 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199112 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
113 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79113 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
114 ·············_\x8c_\x8i_\x8s············6.1.1114 ·············_\x8c_\x8i_\x8s············6.1.1
115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 121 package·install·aide
117 [[packages]] 
118 name·=·"aide" 
119 version·=·"*" 
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
125 #·Remediation·is·applicable·only·in·certain·platforms127 #·Remediation·is·applicable·only·in·certain·platforms
126 if·rpm·--quiet·-q·kernel;·then128 if·rpm·--quiet·-q·kernel;·then
Offset 167, 14 lines modifiedOffset 169, 26 lines modified
167 ··-·PCI-DSSv4-11.5.2169 ··-·PCI-DSSv4-11.5.2
168 ··-·enable_strategy170 ··-·enable_strategy
169 ··-·low_complexity171 ··-·low_complexity
170 ··-·low_disruption172 ··-·low_disruption
171 ··-·medium_severity173 ··-·medium_severity
172 ··-·no_reboot_needed174 ··-·no_reboot_needed
173 ··-·package_aide_installed175 ··-·package_aide_installed
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 181 package·--add=aide
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
179 dnf·install·aide191 dnf·install·aide
Offset 186, 28 lines modifiedOffset 200, 14 lines modified
186 include·install_aide200 include·install_aide
  
187 class·install_aide·{201 class·install_aide·{
188 ··package·{·'aide':202 ··package·{·'aide':
189 ····ensure·=>·'installed',203 ····ensure·=>·'installed',
190 ··}204 ··}
191 }205 }
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·install·aide 
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
203 package·--add=aide 
204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
205 Run·the·following·command·to·generate·a·new·database:207 Run·the·following·command·to·generate·a·new·database:
206 $·sudo·/usr/sbin/aide·--init208 $·sudo·/usr/sbin/aide·--init
207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:209 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
208 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz210 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
209 To·initiate·a·manual·check,·run·the·following·command:211 To·initiate·a·manual·check,·run·the·following·command:
210 $·sudo·/usr/sbin/aide·--check212 $·sudo·/usr/sbin/aide·--check
Offset 746, 14 lines modifiedOffset 746, 39 lines modified
746 »       echo·"to·see·what·package·to·(re)install"·>&2746 »       echo·"to·see·what·package·to·(re)install"·>&2
  
747 »       false··#·end·with·an·error·code747 »       false··#·end·with·an·error·code
748 elif·test·"$rc"·!=·0;·then748 elif·test·"$rc"·!=·0;·then
749 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2749 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
750 »       false··#·end·with·an·error·code750 »       false··#·end·with·an·error·code
751 fi751 fi
 752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 754 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 755 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 756 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 757 ---
 758 apiVersion:·machineconfiguration.openshift.io/v1
 759 kind:·MachineConfig
 760 spec:
 761 ··config:
 762 ····ignition:
 763 ······version:·3.1.0
 764 ····systemd:
 765 ······units:
 766 ········-·name:·configure-crypto-policy.service
 767 ··········enabled:·true
 768 ··········contents:·|
 769 ············[Unit]
 770 ············Before=kubelet.service
 771 ············[Service]
 772 ············Type=oneshot
 773 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 774 ············RemainAfterExit=yes
 775 ············[Install]
 776 ············WantedBy=multi-user.target
752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8777 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low778 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
754 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low779 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
755 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false780 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
756 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict781 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
757 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable782 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
758 ··set_fact:783 ··set_fact:
Offset 800, 39 lines modifiedOffset 825, 14 lines modified
800 ··-·PCI-DSSv4-2.2.7825 ··-·PCI-DSSv4-2.2.7
801 ··-·configure_crypto_policy826 ··-·configure_crypto_policy
802 ··-·high_severity827 ··-·high_severity
803 ··-·low_complexity828 ··-·low_complexity
804 ··-·low_disruption829 ··-·low_disruption
805 ··-·no_reboot_needed830 ··-·no_reboot_needed
Max diff block lines reached; 351811/356697 bytes (98.63%) of diff not shown.
2.58 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis_server_l1.html
    
Offset 15103, 281 lines modifiedOffset 15103, 281 lines modified
0003afe0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003afe0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003aff0:·646d·3733·3037·2220·7461·6269·6e64·6578··dm7307"·tabindex0003aff0:·646d·3733·3037·2220·7461·6269·6e64·6578··dm7307"·tabindex
0003b000:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b000:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b010:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b010:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b020:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b020:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b030:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b030:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b040:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b040:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b050:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b050:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
0003b060:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b070:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b080:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b090:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b0a0:·7365·2220·6964·3d22·6964·6d37·3330·3722··se"·id="idm7307" 
0003b0b0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
0003b0c0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b0d0:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b0e0:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003b0f0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b100:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b110:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b120:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b130:·7461·7267·6574·3d22·2369·646d·3733·3038··target="#idm7308 
0003b140:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b150:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b160:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b170:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b180:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b190:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b1a0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b1b0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b060:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b1c0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b070:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b1d0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b080:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b1e0:·2069·643d·2269·646d·3733·3038·223e·3c74···id="idm7308"><t0003b090:·2069·643d·2269·646d·3733·3037·223e·3c74···id="idm7307"><t
0003b1f0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b0a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b200:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b0b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b210:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b0c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b220:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b0d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b230:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b0e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b240:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003b0f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003b250:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b100:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b260:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003b110:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b270:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b120:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b280:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b130:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b290:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b140:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b2a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b2b0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003b2c0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003b2d0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b2e0:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b2f0:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b300:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b310:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r 
0003b320:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003b330:·726e·656c·3b20·7468·656e·0a0a·6966·2021··rnel;·then..if·! 
0003b340:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003b350:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003b360:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y 
0003b370:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003b380:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b390:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b3a0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b3b0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b3c0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b3d0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b3e0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b3f0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b400:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b410:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b420:·3733·3039·2220·7461·6269·6e64·6578·3d22··7309"·tabindex=" 
0003b430:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b440:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b450:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b460:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b470:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b480:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003b490:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b4a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b4b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b4c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b4d0:·3330·3922·3e3c·7461·626c·6520·636c·6173··309"><table·clas 
0003b4e0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b4f0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b500:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b510:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b520:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b530:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b540:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b550:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b560:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b150:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b160:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003b170:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003b180:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b190:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i
 0003b1a0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co
 0003b1b0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003b1c0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b1d0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003b1e0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003b1f0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003b200:·646d·3733·3038·2220·7461·6269·6e64·6578··dm7308"·tabindex
 0003b210:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003b220:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003b230:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003b240:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003b250:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003b260:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003b570:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b580:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b590:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b5a0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b5b0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b5c0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n 
0003b5d0:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
0003b5e0:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
0003b5f0:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
0003b600:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto 
0003b610:·0a20·2074·6167·733a·0a20·202d·2043·4345··.··tags:.··-·CCE 
0003b620:·2d39·3034·3737·2d31·0a20·202d·2043·4a49··-90477-1.··-·CJI 
0003b630:·532d·352e·3130·2e31·2e33·0a20·202d·204e··S-5.10.1.3.··-·N 
0003b640:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003b650:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003b660:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003b670:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003b680:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003b690:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003b6a0:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003b6b0:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
Max diff block lines reached; 2425129/2462555 bytes (98.48%) of diff not shown.
238 KB
html2text {}
    
Offset 103, 19 lines modifiedOffset 103, 21 lines modified
103 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)103 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
104 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3104 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
108 ·············_\x8c_\x8i_\x8s············6.1.1108 ·············_\x8c_\x8i_\x8s············6.1.1
109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 115 package·install·aide
111 [[packages]] 
112 name·=·"aide" 
113 version·=·"*" 
114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
119 #·Remediation·is·applicable·only·in·certain·platforms121 #·Remediation·is·applicable·only·in·certain·platforms
120 if·rpm·--quiet·-q·kernel;·then122 if·rpm·--quiet·-q·kernel;·then
Offset 161, 14 lines modifiedOffset 163, 26 lines modified
161 ··-·PCI-DSSv4-11.5.2163 ··-·PCI-DSSv4-11.5.2
162 ··-·enable_strategy164 ··-·enable_strategy
163 ··-·low_complexity165 ··-·low_complexity
164 ··-·low_disruption166 ··-·low_disruption
165 ··-·medium_severity167 ··-·medium_severity
166 ··-·no_reboot_needed168 ··-·no_reboot_needed
167 ··-·package_aide_installed169 ··-·package_aide_installed
 170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 175 package·--add=aide
 176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 177 [[packages]]
 178 name·=·"aide"
 179 version·=·"*"
168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
173 dnf·install·aide185 dnf·install·aide
Offset 180, 28 lines modifiedOffset 194, 14 lines modified
180 include·install_aide194 include·install_aide
  
181 class·install_aide·{195 class·install_aide·{
182 ··package·{·'aide':196 ··package·{·'aide':
183 ····ensure·=>·'installed',197 ····ensure·=>·'installed',
184 ··}198 ··}
185 }199 }
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
191 package·install·aide 
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
197 package·--add=aide 
198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
199 Run·the·following·command·to·generate·a·new·database:201 Run·the·following·command·to·generate·a·new·database:
200 $·sudo·/usr/sbin/aide·--init202 $·sudo·/usr/sbin/aide·--init
201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
202 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
203 To·initiate·a·manual·check,·run·the·following·command:205 To·initiate·a·manual·check,·run·the·following·command:
204 $·sudo·/usr/sbin/aide·--check206 $·sudo·/usr/sbin/aide·--check
Offset 740, 14 lines modifiedOffset 740, 39 lines modified
740 »       echo·"to·see·what·package·to·(re)install"·>&2740 »       echo·"to·see·what·package·to·(re)install"·>&2
  
741 »       false··#·end·with·an·error·code741 »       false··#·end·with·an·error·code
742 elif·test·"$rc"·!=·0;·then742 elif·test·"$rc"·!=·0;·then
743 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2743 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
744 »       false··#·end·with·an·error·code744 »       false··#·end·with·an·error·code
745 fi745 fi
 746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 747 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 748 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 749 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 750 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 751 ---
 752 apiVersion:·machineconfiguration.openshift.io/v1
 753 kind:·MachineConfig
 754 spec:
 755 ··config:
 756 ····ignition:
 757 ······version:·3.1.0
 758 ····systemd:
 759 ······units:
 760 ········-·name:·configure-crypto-policy.service
 761 ··········enabled:·true
 762 ··········contents:·|
 763 ············[Unit]
 764 ············Before=kubelet.service
 765 ············[Service]
 766 ············Type=oneshot
 767 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 768 ············RemainAfterExit=yes
 769 ············[Install]
 770 ············WantedBy=multi-user.target
746 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8771 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
747 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low772 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
748 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low773 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
749 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false774 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
750 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict775 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
751 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable776 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
752 ··set_fact:777 ··set_fact:
Offset 794, 39 lines modifiedOffset 819, 14 lines modified
794 ··-·PCI-DSSv4-2.2.7819 ··-·PCI-DSSv4-2.2.7
795 ··-·configure_crypto_policy820 ··-·configure_crypto_policy
796 ··-·high_severity821 ··-·high_severity
797 ··-·low_complexity822 ··-·low_complexity
798 ··-·low_disruption823 ··-·low_disruption
799 ··-·no_reboot_needed824 ··-·no_reboot_needed
Max diff block lines reached; 239275/244161 bytes (98.00%) of diff not shown.
2.27 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis_workstation_l1.html
    
Offset 15094, 281 lines modifiedOffset 15094, 281 lines modified
0003af50:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003af50:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003af60:·6964·6d37·3330·3722·2074·6162·696e·6465··idm7307"·tabinde0003af60:·6964·6d37·3330·3722·2074·6162·696e·6465··idm7307"·tabinde
0003af70:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003af70:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003af80:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003af80:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003af90:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003af90:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003afa0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003afa0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003afb0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003afb0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003afc0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003afc0:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
0003afd0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003afe0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003aff0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b000:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b010:·7073·6522·2069·643d·2269·646d·3733·3037··pse"·id="idm7307 
0003b020:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003b030:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003b040:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003b050:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003b060:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b070:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b080:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b090:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b0a0:·2d74·6172·6765·743d·2223·6964·6d37·3330··-target="#idm730 
0003b0b0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"· 
0003b0c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b0d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b0e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b0f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b100:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b110:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b120:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di0003afd0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
0003b130:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c0003afe0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
0003b140:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse0003aff0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
0003b150:·2220·6964·3d22·6964·6d37·3330·3822·3e3c··"·id="idm7308"><0003b000:·2220·6964·3d22·6964·6d37·3330·3722·3e3c··"·id="idm7307"><
0003b160:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab0003b010:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
0003b170:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped0003b020:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
0003b180:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·0003b030:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
0003b190:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003b040:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
0003b1a0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex0003b050:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
0003b1b0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003b060:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
0003b1c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003b070:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
0003b1d0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t0003b080:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003b1e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b090:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b1f0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003b0a0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
0003b200:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003b0b0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
0003b210:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b220:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b230:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b240:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b250:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003b260:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003b270:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b280:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b290:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003b2a0:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if· 
0003b2b0:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003b2c0:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003b2d0:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
0003b2e0:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003b2f0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b300:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b310:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b320:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b330:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b340:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b350:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b360:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b370:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b380:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b390:·6d37·3330·3922·2074·6162·696e·6465·783d··m7309"·tabindex= 
0003b3a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b3b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b3c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b3d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b3e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b3f0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b400:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b410:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b420:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b430:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b440:·3733·3039·223e·3c74·6162·6c65·2063·6c61··7309"><table·cla 
0003b450:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b460:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b470:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b480:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b490:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b4a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b4b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b4c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b4d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b4e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b4f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b500:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b510:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b520:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b530:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
0003b540:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
0003b550:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
0003b560:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
0003b570:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
0003b580:·6f0a·2020·7461·6773·3a0a·2020·2d20·4343··o.··tags:.··-·CC 
0003b590:·452d·3930·3437·372d·310a·2020·2d20·434a··E-90477-1.··-·CJ 
0003b5a0:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003b5b0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6 
0003b5c0:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS- 
0003b5d0:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI 
0003b5e0:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.·· 
0003b5f0:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg 
0003b600:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple 
0003b610:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis 
0003b620:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi 
0003b630:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-· 
0003b640:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed 
0003b650:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid 
0003b660:·655f·696e·7374·616c·6c65·640a·0a2d·206e··e_installed..-·n 
0003b670:·616d·653a·2045·6e73·7572·6520·6169·6465··ame:·Ensure·aide 
0003b680:·2069·7320·696e·7374·616c·6c65·640a·2020···is·installed.·· 
0003b690:·7061·636b·6167·653a·0a20·2020·206e·616d··package:.····nam 
0003b6a0:·653a·2061·6964·650a·2020·2020·7374·6174··e:·aide.····stat 
0003b6b0:·653a·2070·7265·7365·6e74·0a20·2077·6865··e:·present.··whe 
0003b6c0:·6e3a·2027·226b·6572·6e65·6c22·2069·6e20··n:·'"kernel"·in· 
0003b6d0:·616e·7369·626c·655f·6661·6374·732e·7061··ansible_facts.pa 
0003b6e0:·636b·6167·6573·270a·2020·7461·6773·3a0a··ckages'.··tags:. 
0003b6f0:·2020·2d20·4343·452d·3930·3437·372d·310a····-·CCE-90477-1. 
0003b700:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003b710:·330a·2020·2d20·4e49·5354·2d38·3030·2d35··3.··-·NIST-800-5 
0003b720:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC 
0003b730:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.· 
Max diff block lines reached; 2123346/2160772 bytes (98.27%) of diff not shown.
212 KB
html2text {}
    
Offset 101, 19 lines modifiedOffset 101, 21 lines modified
101 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)101 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
102 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3102 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
103 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5103 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
104 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199104 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
105 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79105 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
106 ·············_\x8c_\x8i_\x8s············6.1.1106 ·············_\x8c_\x8i_\x8s············6.1.1
107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 113 package·install·aide
109 [[packages]] 
110 name·=·"aide" 
111 version·=·"*" 
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
117 #·Remediation·is·applicable·only·in·certain·platforms119 #·Remediation·is·applicable·only·in·certain·platforms
118 if·rpm·--quiet·-q·kernel;·then120 if·rpm·--quiet·-q·kernel;·then
Offset 159, 14 lines modifiedOffset 161, 26 lines modified
159 ··-·PCI-DSSv4-11.5.2161 ··-·PCI-DSSv4-11.5.2
160 ··-·enable_strategy162 ··-·enable_strategy
161 ··-·low_complexity163 ··-·low_complexity
162 ··-·low_disruption164 ··-·low_disruption
163 ··-·medium_severity165 ··-·medium_severity
164 ··-·no_reboot_needed166 ··-·no_reboot_needed
165 ··-·package_aide_installed167 ··-·package_aide_installed
 168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 173 package·--add=aide
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 175 [[packages]]
 176 name·=·"aide"
 177 version·=·"*"
166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
167 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
168 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
169 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
170 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
171 dnf·install·aide183 dnf·install·aide
Offset 178, 28 lines modifiedOffset 192, 14 lines modified
178 include·install_aide192 include·install_aide
  
179 class·install_aide·{193 class·install_aide·{
180 ··package·{·'aide':194 ··package·{·'aide':
181 ····ensure·=>·'installed',195 ····ensure·=>·'installed',
182 ··}196 ··}
183 }197 }
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
189 package·install·aide 
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
195 package·--add=aide 
196 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*198 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
197 Run·the·following·command·to·generate·a·new·database:199 Run·the·following·command·to·generate·a·new·database:
198 $·sudo·/usr/sbin/aide·--init200 $·sudo·/usr/sbin/aide·--init
199 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:201 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
200 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz202 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
201 To·initiate·a·manual·check,·run·the·following·command:203 To·initiate·a·manual·check,·run·the·following·command:
202 $·sudo·/usr/sbin/aide·--check204 $·sudo·/usr/sbin/aide·--check
Offset 738, 14 lines modifiedOffset 738, 39 lines modified
738 »       echo·"to·see·what·package·to·(re)install"·>&2738 »       echo·"to·see·what·package·to·(re)install"·>&2
  
739 »       false··#·end·with·an·error·code739 »       false··#·end·with·an·error·code
740 elif·test·"$rc"·!=·0;·then740 elif·test·"$rc"·!=·0;·then
741 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2741 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
742 »       false··#·end·with·an·error·code742 »       false··#·end·with·an·error·code
743 fi743 fi
 744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 745 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 746 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 747 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 748 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 749 ---
 750 apiVersion:·machineconfiguration.openshift.io/v1
 751 kind:·MachineConfig
 752 spec:
 753 ··config:
 754 ····ignition:
 755 ······version:·3.1.0
 756 ····systemd:
 757 ······units:
 758 ········-·name:·configure-crypto-policy.service
 759 ··········enabled:·true
 760 ··········contents:·|
 761 ············[Unit]
 762 ············Before=kubelet.service
 763 ············[Service]
 764 ············Type=oneshot
 765 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 766 ············RemainAfterExit=yes
 767 ············[Install]
 768 ············WantedBy=multi-user.target
744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8769 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
745 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low770 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
746 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low771 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
747 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false772 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
748 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict773 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
749 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable774 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
750 ··set_fact:775 ··set_fact:
Offset 792, 39 lines modifiedOffset 817, 14 lines modified
792 ··-·PCI-DSSv4-2.2.7817 ··-·PCI-DSSv4-2.2.7
793 ··-·configure_crypto_policy818 ··-·configure_crypto_policy
794 ··-·high_severity819 ··-·high_severity
795 ··-·low_complexity820 ··-·low_complexity
796 ··-·low_disruption821 ··-·low_disruption
797 ··-·no_reboot_needed822 ··-·no_reboot_needed
Max diff block lines reached; 211671/216557 bytes (97.74%) of diff not shown.
4.16 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-cis_workstation_l2.html
    
Offset 15133, 281 lines modifiedOffset 15133, 281 lines modified
0003b1c0:·7461·7267·6574·3d22·2369·646d·3733·3037··target="#idm73070003b1c0:·7461·7267·6574·3d22·2369·646d·3733·3037··target="#idm7307
0003b1d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b1d0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b1e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b1e0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b1f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b1f0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b200:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b200:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b210:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b210:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b220:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b220:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b230:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003b240:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003b250:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b260:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b270:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b280:·3d22·6964·6d37·3330·3722·3e3c·7072·653e··="idm7307"><pre> 
0003b290:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003b2a0:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003b2b0:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003b2c0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b2d0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b2e0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b2f0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b300:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b310:·3d22·2369·646d·3733·3038·2220·7461·6269··="#idm7308"·tabi 
0003b320:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b330:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b340:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b350:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b360:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b370:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003b380:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</0003b230:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</
0003b390:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b240:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003b3a0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b250:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003b3b0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b260:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003b3c0:·646d·3733·3038·223e·3c74·6162·6c65·2063··dm7308"><table·c0003b270:·646d·3733·3037·223e·3c74·6162·6c65·2063··dm7307"><table·c
0003b3d0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b280:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003b3e0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003b290:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003b3f0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003b2a0:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003b400:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003b2b0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003b410:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003b2c0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003b420:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003b2d0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003b430:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru0003b2e0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003b440:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003b2f0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003b450:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003b300:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003b460:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003b310:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
0003b470:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></0003b320:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
0003b480:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat0003b330:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
0003b490:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena0003b340:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003b4a0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t0003b350:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003b4b0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>0003b360:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003b370:·0a70·6163·6b61·6765·2069·6e73·7461·6c6c··.package·install
0003b4c0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003b4d0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003b4e0:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003b4f0:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q 
0003b500:·7569·6574·202d·7120·6b65·726e·656c·3b20··uiet·-q·kernel;· 
0003b510:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003b520:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003b530:·203b·2074·6865·6e0a·2020·2020·646e·6620···;·then.····dnf· 
0003b540:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003b550:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003b560:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003b570:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003b580:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003b590:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003b5a0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre0003b380:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p
0003b5b0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003b390:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
0003b5c0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003b3a0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
0003b5d0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003b3b0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
0003b5e0:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003b3c0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
0003b5f0:·7267·6574·3d22·2369·646d·3733·3039·2220··rget="#idm7309"·0003b3d0:·7461·7267·6574·3d22·2369·646d·3733·3038··target="#idm7308
0003b600:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b3e0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b610:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b3f0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b620:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b400:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b630:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b410:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b640:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b420:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b650:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b430:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003b440:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 0003b450:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b460:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b470:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b480:·2069·643d·2269·646d·3733·3038·223e·3c74···id="idm7308"><t
 0003b490:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b4a0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b660:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003b670:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b680:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b690:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b6a0:·2220·6964·3d22·6964·6d37·3330·3922·3e3c··"·id="idm7309">< 
0003b6b0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b6c0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b6d0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b6e0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"0003b4b0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b6f0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b700:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low0003b4c0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b4d0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b4e0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b4f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b500:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003b510:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b520:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b530:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003b540:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b550:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003b560:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003b570:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b580:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat
 0003b590:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl
 0003b5a0:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai
 0003b5b0:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r
 0003b5c0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
 0003b5d0:·726e·656c·3b20·7468·656e·0a0a·6966·2021··rnel;·then..if·!
 0003b5e0:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet·
 0003b5f0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.··
 0003b600:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y
 0003b610:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else
 0003b620:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·
 0003b630:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio
 0003b640:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica
 0003b650:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was
 0003b660:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code
 0003b670:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b680:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b690:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b6a0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 0003b6b0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 0003b6c0:·3733·3039·2220·7461·6269·6e64·6578·3d22··7309"·tabindex="
 0003b6d0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 0003b6e0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
Max diff block lines reached; 3983284/4020710 bytes (99.07%) of diff not shown.
338 KB
html2text {}
    
Offset 107, 19 lines modifiedOffset 107, 21 lines modified
107 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)107 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
108 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3108 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
110 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199110 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
111 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79111 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
112 ·············_\x8c_\x8i_\x8s············6.1.1112 ·············_\x8c_\x8i_\x8s············6.1.1
113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 119 package·install·aide
115 [[packages]] 
116 name·=·"aide" 
117 version·=·"*" 
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
123 #·Remediation·is·applicable·only·in·certain·platforms125 #·Remediation·is·applicable·only·in·certain·platforms
124 if·rpm·--quiet·-q·kernel;·then126 if·rpm·--quiet·-q·kernel;·then
Offset 165, 14 lines modifiedOffset 167, 26 lines modified
165 ··-·PCI-DSSv4-11.5.2167 ··-·PCI-DSSv4-11.5.2
166 ··-·enable_strategy168 ··-·enable_strategy
167 ··-·low_complexity169 ··-·low_complexity
168 ··-·low_disruption170 ··-·low_disruption
169 ··-·medium_severity171 ··-·medium_severity
170 ··-·no_reboot_needed172 ··-·no_reboot_needed
171 ··-·package_aide_installed173 ··-·package_aide_installed
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 179 package·--add=aide
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 181 [[packages]]
 182 name·=·"aide"
 183 version·=·"*"
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
177 dnf·install·aide189 dnf·install·aide
Offset 184, 28 lines modifiedOffset 198, 14 lines modified
184 include·install_aide198 include·install_aide
  
185 class·install_aide·{199 class·install_aide·{
186 ··package·{·'aide':200 ··package·{·'aide':
187 ····ensure·=>·'installed',201 ····ensure·=>·'installed',
188 ··}202 ··}
189 }203 }
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
195 package·install·aide 
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
201 package·--add=aide 
202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
203 Run·the·following·command·to·generate·a·new·database:205 Run·the·following·command·to·generate·a·new·database:
204 $·sudo·/usr/sbin/aide·--init206 $·sudo·/usr/sbin/aide·--init
205 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
206 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz208 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
207 To·initiate·a·manual·check,·run·the·following·command:209 To·initiate·a·manual·check,·run·the·following·command:
208 $·sudo·/usr/sbin/aide·--check210 $·sudo·/usr/sbin/aide·--check
Offset 744, 14 lines modifiedOffset 744, 39 lines modified
744 »       echo·"to·see·what·package·to·(re)install"·>&2744 »       echo·"to·see·what·package·to·(re)install"·>&2
  
745 »       false··#·end·with·an·error·code745 »       false··#·end·with·an·error·code
746 elif·test·"$rc"·!=·0;·then746 elif·test·"$rc"·!=·0;·then
747 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2747 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
748 »       false··#·end·with·an·error·code748 »       false··#·end·with·an·error·code
749 fi749 fi
 750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 751 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 752 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 753 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 754 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 755 ---
 756 apiVersion:·machineconfiguration.openshift.io/v1
 757 kind:·MachineConfig
 758 spec:
 759 ··config:
 760 ····ignition:
 761 ······version:·3.1.0
 762 ····systemd:
 763 ······units:
 764 ········-·name:·configure-crypto-policy.service
 765 ··········enabled:·true
 766 ··········contents:·|
 767 ············[Unit]
 768 ············Before=kubelet.service
 769 ············[Service]
 770 ············Type=oneshot
 771 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 772 ············RemainAfterExit=yes
 773 ············[Install]
 774 ············WantedBy=multi-user.target
750 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8775 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
751 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low776 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
752 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low777 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
753 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false778 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
754 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict779 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
755 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable780 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
756 ··set_fact:781 ··set_fact:
Offset 798, 39 lines modifiedOffset 823, 14 lines modified
798 ··-·PCI-DSSv4-2.2.7823 ··-·PCI-DSSv4-2.2.7
799 ··-·configure_crypto_policy824 ··-·configure_crypto_policy
800 ··-·high_severity825 ··-·high_severity
801 ··-·low_complexity826 ··-·low_complexity
802 ··-·low_disruption827 ··-·low_disruption
803 ··-·no_reboot_needed828 ··-·no_reboot_needed
Max diff block lines reached; 340723/345609 bytes (98.59%) of diff not shown.
1.68 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-e8.html
    
Offset 16140, 180 lines modifiedOffset 16140, 180 lines modified
0003f0b0:·6765·743d·2223·6964·6d38·3033·3322·2074··get="#idm8033"·t0003f0b0:·6765·743d·2223·6964·6d38·3033·3322·2074··get="#idm8033"·t
0003f0c0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003f0c0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003f0d0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003f0d0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003f0e0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003f0e0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003f0f0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003f0f0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003f100:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003f100:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003f110:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003f110:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003f120:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003f130:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003f140:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003f150:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003f160:·2069·643d·2269·646d·3830·3333·223e·3c74···id="idm8033"><t 
0003f170:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003f180:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003f190:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003f1a0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003f1b0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003f120:·204b·7562·6572·6e65·7465·7320·736e·6970···Kubernetes·snip
 0003f130:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0003f140:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003f150:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003f160:·7365·2220·6964·3d22·6964·6d38·3033·3322··se"·id="idm8033"
 0003f170:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 0003f180:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
 0003f190:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
 0003f1a0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 0003f1b0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 0003f1c0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 0003f1d0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003f1e0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003f1c0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003f1f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003f1d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003f200:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 0003f210:·6f6f·743a·3c2f·7468·3e3c·7464·3e74·7275··oot:</th><td>tru
0003f1e0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003f1f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003f200:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003f210:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003f220:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003f220:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
0003f230:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003f230:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
0003f240:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>0003f240:·3e3c·7464·3e72·6573·7472·6963·743c·2f74··><td>restrict</t
0003f250:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr0003f250:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003f260:·7072·653e·3c63·6f64·653e·2d2d·2d0a·6170··pre><code>---.ap
 0003f270:·6956·6572·7369·6f6e·3a20·6d61·6368·696e··iVersion:·machin
 0003f280:·6563·6f6e·6669·6775·7261·7469·6f6e·2e6f··econfiguration.o
 0003f290:·7065·6e73·6869·6674·2e69·6f2f·7631·0a6b··penshift.io/v1.k
 0003f2a0:·696e·643a·204d·6163·6869·6e65·436f·6e66··ind:·MachineConf
 0003f2b0:·6967·0a73·7065·633a·0a20·2063·6f6e·6669··ig.spec:.··confi
 0003f2c0:·673a·0a20·2020·2069·676e·6974·696f·6e3a··g:.····ignition:
 0003f2d0:·0a20·2020·2020·2076·6572·7369·6f6e·3a20··.······version:·
 0003f2e0:·332e·312e·300a·2020·2020·7379·7374·656d··3.1.0.····system
 0003f2f0:·643a·0a20·2020·2020·2075·6e69·7473·3a0a··d:.······units:.
 0003f300:·2020·2020·2020·2020·2d20·6e61·6d65·3a20··········-·name:·
 0003f310:·636f·6e66·6967·7572·652d·6372·7970·746f··configure-crypto
 0003f320:·2d70·6f6c·6963·792e·7365·7276·6963·650a··-policy.service.
 0003f330:·2020·2020·2020·2020·2020·656e·6162·6c65············enable
 0003f340:·643a·2074·7275·650a·2020·2020·2020·2020··d:·true.········
 0003f350:·2020·636f·6e74·656e·7473·3a20·7c0a·2020····contents:·|.··
 0003f360:·2020·2020·2020·2020·2020·5b55·6e69·745d············[Unit]
 0003f370:·0a20·2020·2020·2020·2020·2020·2042·6566··.············Bef
 0003f380:·6f72·653d·6b75·6265·6c65·742e·7365·7276··ore=kubelet.serv
 0003f390:·6963·650a·2020·2020·2020·2020·2020·2020··ice.············
 0003f3a0:·5b53·6572·7669·6365·5d0a·2020·2020·2020··[Service].······
 0003f3b0:·2020·2020·2020·5479·7065·3d6f·6e65·7368········Type=onesh
 0003f3c0:·6f74·0a20·2020·2020·2020·2020·2020·2045··ot.············E
 0003f3d0:·7865·6353·7461·7274·3d75·7064·6174·652d··xecStart=update-
 0003f3e0:·6372·7970·746f·2d70·6f6c·6963·6965·7320··crypto-policies·
 0003f3f0:·2d2d·7365·7420·7b7b·2e76·6172·5f73·7973··--set·{{.var_sys
 0003f400:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic
 0003f410:·797d·7d0a·2020·2020·2020·2020·2020·2020··y}}.············
 0003f420:·5265·6d61·696e·4166·7465·7245·7869·743d··RemainAfterExit=
 0003f430:·7965·730a·2020·2020·2020·2020·2020·2020··yes.············
 0003f440:·5b49·6e73·7461·6c6c·5d0a·2020·2020·2020··[Install].······
 0003f450:·2020·2020·2020·5761·6e74·6564·4279·3d6d········WantedBy=m
 0003f460:·756c·7469·2d75·7365·722e·7461·7267·6574··ulti-user.target
 0003f470:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003f480:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003f490:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003f4a0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003f4b0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003f4c0:·743d·2223·6964·6d38·3033·3422·2074·6162··t="#idm8034"·tab
 0003f4d0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003f4e0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003f4f0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003f500:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003f510:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003f520:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
 0003f530:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
 0003f540:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003f550:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003f560:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003f570:·643d·2269·646d·3830·3334·223e·3c74·6162··d="idm8034"><tab
 0003f580:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003f590:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003f5a0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003f5b0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003f5c0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003f5d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003f5e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003f5f0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003f600:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003f610:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003f620:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003f630:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003f640:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003f650:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></
 0003f660:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
0003f260:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·0003f670:·3c63·6f64·653e·2d20·6e61·6d65·3a20·5843··<code>-·name:·XC
0003f270:·5843·4344·4620·5661·6c75·6520·7661·725f··XCCDF·Value·var_0003f680:·4344·4620·5661·6c75·6520·7661·725f·7379··CDF·Value·var_sy
0003f280:·7379·7374·656d·5f63·7279·7074·6f5f·706f··system_crypto_po 
0003f290:·6c69·6379·2023·2070·726f·6d6f·7465·2074··licy·#·promote·t 
0003f2a0:·6f20·7661·7269·6162·6c65·0a20·2073·6574··o·variable.··set 
0003f2b0:·5f66·6163·743a·0a20·2020·2076·6172·5f73··_fact:.····var_s 
0003f2c0:·7973·7465·6d5f·6372·7970·746f·5f70·6f6c··ystem_crypto_pol 
0003f2d0:·6963·793a·2021·2173·7472·203c·6162·6272··icy:·!!str·<abbr 
0003f2e0:·2074·6974·6c65·3d22·6672·6f6d·2050·726f···title="from·Pro 
0003f2f0:·6669·6c65·2f72·6566·696e·652d·7661·6c75··file/refine-valu 
0003f300:·653a·2078·6363·6466·5f6f·7267·2e73·7367··e:·xccdf_org.ssg 
0003f310:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_ 
0003f320:·7661·6c75·655f·7661·725f·7379·7374·656d··value_var_system 
0003f330:·5f63·7279·7074·6f5f·706f·6c69·6379·223e··_crypto_policy"> 
0003f340:·4445·4641·554c·543c·2f61·6262·723e·0a20··DEFAULT</abbr>.· 
0003f350:·2074·6167·733a·0a20·2020·202d·2061·6c77···tags:.····-·alw 
0003f360:·6179·730a·0a2d·206e·616d·653a·2043·6f6e··ays..-·name:·Con 
0003f370:·6669·6775·7265·2053·7973·7465·6d20·4372··figure·System·Cr 
0003f380:·7970·746f·6772·6170·6879·2050·6f6c·6963··yptography·Polic 
0003f390:·790a·2020·6c69·6e65·696e·6669·6c65·3a0a··y.··lineinfile:. 
0003f3a0:·2020·2020·7061·7468·3a20·2f65·7463·2f63······path:·/etc/c 
0003f3b0:·7279·7074·6f2d·706f·6c69·6369·6573·2f63··rypto-policies/c 
Max diff block lines reached; 1592547/1616035 bytes (98.55%) of diff not shown.
138 KB
html2text {}
    
Offset 350, 14 lines modifiedOffset 350, 39 lines modified
350 »       echo·"to·see·what·package·to·(re)install"·>&2350 »       echo·"to·see·what·package·to·(re)install"·>&2
  
351 »       false··#·end·with·an·error·code351 »       false··#·end·with·an·error·code
352 elif·test·"$rc"·!=·0;·then352 elif·test·"$rc"·!=·0;·then
353 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2353 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
354 »       false··#·end·with·an·error·code354 »       false··#·end·with·an·error·code
355 fi355 fi
 356 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 357 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 358 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 359 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 360 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 361 ---
 362 apiVersion:·machineconfiguration.openshift.io/v1
 363 kind:·MachineConfig
 364 spec:
 365 ··config:
 366 ····ignition:
 367 ······version:·3.1.0
 368 ····systemd:
 369 ······units:
 370 ········-·name:·configure-crypto-policy.service
 371 ··········enabled:·true
 372 ··········contents:·|
 373 ············[Unit]
 374 ············Before=kubelet.service
 375 ············[Service]
 376 ············Type=oneshot
 377 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 378 ············RemainAfterExit=yes
 379 ············[Install]
 380 ············WantedBy=multi-user.target
356 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
357 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low382 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
358 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low383 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
359 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false384 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
360 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict385 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
361 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable386 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
362 ··set_fact:387 ··set_fact:
Offset 404, 39 lines modifiedOffset 429, 14 lines modified
404 ··-·PCI-DSSv4-2.2.7429 ··-·PCI-DSSv4-2.2.7
405 ··-·configure_crypto_policy430 ··-·configure_crypto_policy
406 ··-·high_severity431 ··-·high_severity
407 ··-·low_complexity432 ··-·low_complexity
408 ··-·low_disruption433 ··-·low_disruption
409 ··-·no_reboot_needed434 ··-·no_reboot_needed
410 ··-·restrict_strategy435 ··-·restrict_strategy
411 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
412 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
413 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
414 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
415 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
416 --- 
417 apiVersion:·machineconfiguration.openshift.io/v1 
418 kind:·MachineConfig 
419 spec: 
420 ··config: 
421 ····ignition: 
422 ······version:·3.1.0 
423 ····systemd: 
424 ······units: 
425 ········-·name:·configure-crypto-policy.service 
426 ··········enabled:·true 
427 ··········contents:·| 
428 ············[Unit] 
429 ············Before=kubelet.service 
430 ············[Service] 
431 ············Type=oneshot 
432 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
433 ············RemainAfterExit=yes 
434 ············[Install] 
435 ············WantedBy=multi-user.target 
436 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*436 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
437 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.437 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
438 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.438 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
439 Severity: ···medium439 Severity: ···medium
440 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy440 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
441 Identifiers:·CCE-88557-4441 Identifiers:·CCE-88557-4
442 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453442 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
Offset 1444, 14 lines modifiedOffset 1444, 38 lines modified
1444 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"1444 ····sed·-i·-E·--follow-symlinks·"s/(.*password.*sufficient.*pam_unix.so.*)\snullok=?[[:alnum:]]*(.*)/\1\2/g"·"/etc/pam.d/password-auth"
1445 fi1445 fi
1446 fi1446 fi
  
1447 else1447 else
1448 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1448 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1449 fi1449 fi
 1450 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1451 ---
 1452 apiVersion:·machineconfiguration.openshift.io/v1
 1453 kind:·MachineConfig
 1454 spec:
 1455 ··config:
 1456 ····ignition:
 1457 ······version:·3.1.0
 1458 ····storage:
 1459 ······files:
 1460 ······-·contents:
 1461 ··········source:
 1462 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1463 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1464 ········mode:·0644
 1465 ········path:·/etc/pam.d/password-auth
 1466 ········overwrite:·true
 1467 ······-·contents:
 1468 ··········source:
 1469 data:,%23%20Generated%20by%20authselect%20on%20Sat%20Oct%2027%2014%3A59%3A36%202018%0A%23%20Do%20not%20modify%20this%20file%20manually.%0A%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_env.so%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_faildelay.so%20delay%3D2000000%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_fprintd.so%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet%0Aauth%20%20%20%20%20%20%20%20%5Bdefault%3D1%20ignore%3Dignore%20success%3Dok%5D%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20try_first_pass%0Aauth%20%20%20%20%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3E%3D%201000%20quiet_success%0Aauth%20%20%20%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20forward_pass%0Aauth%20%20%20%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_localuser.so%0Aaccount%20%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20uid%20%3C%201000%20quiet%0Aaccount%20%20%20%20%20%5Bdefault%3Dbad%20success%3Dok%20user_unknown%3Dignore%5D%20pam_sss.so%0Aaccount%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_permit.so%0A%0Apassword%20%20%20%20requisite%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_pwquality.so%20try_first_pass%20local_users_only%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%20sha512%20shadow%20try_first_pass%20use_authtok%0Apassword%20%20%20%20sufficient%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%20use_authtok%0Apassword%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_deny.so%0A%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_keyinit.so%20revoke%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_limits.so%0A-
 1470 session%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_systemd.so%0Asession%20%20%20%20%20%5Bsuccess%3D1%20default%3Dignore%5D%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_succeed_if.so%20service%20in%20crond%20quiet%20use_uid%0Asession%20%20%20%20%20required%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_unix.so%0Asession%20%20%20%20%20optional%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20pam_sss.so%0A
 1471 ········mode:·0644
 1472 ········path:·/etc/pam.d/system-auth
 1473 ········overwrite:·true
1450 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81474 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1451 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1475 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1452 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1476 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1453 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1477 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1454 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure1478 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···configure
1455 -·name:·Gather·the·package·facts1479 -·name:·Gather·the·package·facts
1456 ··package_facts:1480 ··package_facts:
Offset 1594, 38 lines modifiedOffset 1618, 14 lines modified
1594 ··-·PCI-DSSv4-8.3.11618 ··-·PCI-DSSv4-8.3.1
1595 ··-·configure_strategy1619 ··-·configure_strategy
1596 ··-·high_severity1620 ··-·high_severity
1597 ··-·low_complexity1621 ··-·low_complexity
1598 ··-·medium_disruption1622 ··-·medium_disruption
1599 ··-·no_empty_passwords1623 ··-·no_empty_passwords
1600 ··-·no_reboot_needed1624 ··-·no_reboot_needed
1601 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
Max diff block lines reached; 120041/141253 bytes (84.98%) of diff not shown.
2.42 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-hipaa.html
    
Offset 16938, 181 lines modifiedOffset 16938, 181 lines modified
00042290:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00042290:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
000422a0:·743d·2223·6964·6d38·3033·3322·2074·6162··t="#idm8033"·tab000422a0:·743d·2223·6964·6d38·3033·3322·2074·6162··t="#idm8033"·tab
000422b0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="000422b0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
000422c0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp000422c0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
000422d0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti000422d0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
000422e0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to000422e0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
000422f0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#000422f0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00042300:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00042300:·2122·3e52·656d·6564·6961·7469·6f6e·204b··!">Remediation·K
00042310:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
00042320:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00042330:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00042340:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00042350:·643d·2269·646d·3830·3333·223e·3c74·6162··d="idm8033"><tab 
00042360:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
00042370:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
00042380:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
00042390:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
000423a0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00042310:·7562·6572·6e65·7465·7320·736e·6970·7065··ubernetes·snippe
 00042320:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 00042330:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 00042340:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 00042350:·2220·6964·3d22·6964·6d38·3033·3322·3e3c··"·id="idm8033"><
 00042360:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 00042370:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 00042380:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 00042390:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 000423a0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 000423b0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 000423c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 000423d0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
000423b0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t000423e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 000423f0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 00042400:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true<
000423c0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
000423d0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
000423e0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
000423f0:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
00042400:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
00042410:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00042410:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00042420:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00042420:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00042430:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></00042430:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
00042440:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>00042440:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 00042450:·653e·3c63·6f64·653e·2d2d·2d0a·6170·6956··e><code>---.apiV
 00042460:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec
 00042470:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope
 00042480:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin
 00042490:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig
 000424a0:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config:
 000424b0:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.·
 000424c0:·2020·2020·2076·6572·7369·6f6e·3a20·332e·······version:·3.
 000424d0:·312e·300a·2020·2020·7379·7374·656d·643a··1.0.····systemd:
 000424e0:·0a20·2020·2020·2075·6e69·7473·3a0a·2020··.······units:.··
 000424f0:·2020·2020·2020·2d20·6e61·6d65·3a20·636f········-·name:·co
 00042500:·6e66·6967·7572·652d·6372·7970·746f·2d70··nfigure-crypto-p
 00042510:·6f6c·6963·792e·7365·7276·6963·650a·2020··olicy.service.··
 00042520:·2020·2020·2020·2020·656e·6162·6c65·643a··········enabled:
 00042530:·2074·7275·650a·2020·2020·2020·2020·2020···true.··········
 00042540:·636f·6e74·656e·7473·3a20·7c0a·2020·2020··contents:·|.····
 00042550:·2020·2020·2020·2020·5b55·6e69·745d·0a20··········[Unit].·
 00042560:·2020·2020·2020·2020·2020·2042·6566·6f72·············Befor
 00042570:·653d·6b75·6265·6c65·742e·7365·7276·6963··e=kubelet.servic
 00042580:·650a·2020·2020·2020·2020·2020·2020·5b53··e.············[S
 00042590:·6572·7669·6365·5d0a·2020·2020·2020·2020··ervice].········
 000425a0:·2020·2020·5479·7065·3d6f·6e65·7368·6f74······Type=oneshot
 000425b0:·0a20·2020·2020·2020·2020·2020·2045·7865··.············Exe
 000425c0:·6353·7461·7274·3d75·7064·6174·652d·6372··cStart=update-cr
 000425d0:·7970·746f·2d70·6f6c·6963·6965·7320·2d2d··ypto-policies·--
 000425e0:·7365·7420·7b7b·2e76·6172·5f73·7973·7465··set·{{.var_syste
 000425f0:·6d5f·6372·7970·746f·5f70·6f6c·6963·797d··m_crypto_policy}
 00042600:·7d0a·2020·2020·2020·2020·2020·2020·5265··}.············Re
 00042610:·6d61·696e·4166·7465·7245·7869·743d·7965··mainAfterExit=ye
 00042620:·730a·2020·2020·2020·2020·2020·2020·5b49··s.············[I
 00042630:·6e73·7461·6c6c·5d0a·2020·2020·2020·2020··nstall].········
 00042640:·2020·2020·5761·6e74·6564·4279·3d6d·756c······WantedBy=mul
 00042650:·7469·2d75·7365·722e·7461·7267·6574·0a3c··ti-user.target.<
 00042660:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00042670:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00042680:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00042690:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 000426a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000426b0:·2223·6964·6d38·3033·3422·2074·6162·696e··"#idm8034"·tabin
 000426c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 000426d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 000426e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 000426f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00042700:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00042710:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
 00042720:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
 00042730:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00042740:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00042750:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00042760:·2269·646d·3830·3334·223e·3c74·6162·6c65··"idm8034"><table
 00042770:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00042780:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00042790:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 000427a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 000427b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 000427c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 000427d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 000427e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 000427f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00042800:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00042810:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 00042820:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 00042830:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
 00042840:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr
 00042850:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
00042450:·3c63·6f64·653e·2d20·6e61·6d65·3a20·5843··<code>-·name:·XC00042860:·6f64·653e·2d20·6e61·6d65·3a20·5843·4344··ode>-·name:·XCCD
00042460:·4344·4620·5661·6c75·6520·7661·725f·7379··CDF·Value·var_sy00042870:·4620·5661·6c75·6520·7661·725f·7379·7374··F·Value·var_syst
00042470:·7374·656d·5f63·7279·7074·6f5f·706f·6c69··stem_crypto_poli00042880:·656d·5f63·7279·7074·6f5f·706f·6c69·6379··em_crypto_policy
00042480:·6379·2023·2070·726f·6d6f·7465·2074·6f20··cy·#·promote·to·00042890:·2023·2070·726f·6d6f·7465·2074·6f20·7661···#·promote·to·va
00042490:·7661·7269·6162·6c65·0a20·2073·6574·5f66··variable.··set_f000428a0:·7269·6162·6c65·0a20·2073·6574·5f66·6163··riable.··set_fac
000424a0:·6163·743a·0a20·2020·2076·6172·5f73·7973··act:.····var_sys000428b0:·743a·0a20·2020·2076·6172·5f73·7973·7465··t:.····var_syste
000424b0:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic000428c0:·6d5f·6372·7970·746f·5f70·6f6c·6963·793a··m_crypto_policy:
000424c0:·793a·2021·2173·7472·203c·6162·6272·2074··y:·!!str·<abbr·t000428d0:·2021·2173·7472·203c·6162·6272·2074·6974···!!str·<abbr·tit
000424d0:·6974·6c65·3d22·6672·6f6d·2042·656e·6368··itle="from·Bench000428e0:·6c65·3d22·6672·6f6d·2042·656e·6368·6d61··le="from·Benchma
000424e0:·6d61·726b·2f56·616c·7565·3a20·7863·6364··mark/Value:·xccd000428f0:·726b·2f56·616c·7565·3a20·7863·6364·665f··rk/Value:·xccdf_
000424f0:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00042900:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00042500:·2e63·6f6e·7465·6e74·5f76·616c·7565·5f76··.content_value_v00042910:·6f6e·7465·6e74·5f76·616c·7565·5f76·6172··ontent_value_var
00042510:·6172·5f73·7973·7465·6d5f·6372·7970·746f··ar_system_crypto00042920:·5f73·7973·7465·6d5f·6372·7970·746f·5f70··_system_crypto_p
00042520:·5f70·6f6c·6963·7922·3e44·4546·4155·4c54··_policy">DEFAULT00042930:·6f6c·6963·7922·3e44·4546·4155·4c54·3c2f··olicy">DEFAULT</
00042530:·3c2f·6162·6272·3e0a·2020·7461·6773·3a0a··</abbr>.··tags:.00042940:·6162·6272·3e0a·2020·7461·6773·3a0a·2020··abbr>.··tags:.··
00042540:·2020·2020·2d20·616c·7761·7973·0a0a·2d20······-·always..-·00042950:·2020·2d20·616c·7761·7973·0a0a·2d20·6e61····-·always..-·na
00042550:·6e61·6d65·3a20·436f·6e66·6967·7572·6520··name:·Configure·00042960:·6d65·3a20·436f·6e66·6967·7572·6520·5379··me:·Configure·Sy
00042560:·5379·7374·656d·2043·7279·7074·6f67·7261··System·Cryptogra00042970:·7374·656d·2043·7279·7074·6f67·7261·7068··stem·Cryptograph
00042570:·7068·7920·506f·6c69·6379·0a20·206c·696e··phy·Policy.··lin00042980:·7920·506f·6c69·6379·0a20·206c·696e·6569··y·Policy.··linei
00042580:·6569·6e66·696c·653a·0a20·2020·2070·6174··einfile:.····pat00042990:·6e66·696c·653a·0a20·2020·2070·6174·683a··nfile:.····path:
Max diff block lines reached; 2327135/2350761 bytes (98.99%) of diff not shown.
185 KB
html2text {}
    
Offset 545, 14 lines modifiedOffset 545, 39 lines modified
545 »       echo·"to·see·what·package·to·(re)install"·>&2545 »       echo·"to·see·what·package·to·(re)install"·>&2
  
546 »       false··#·end·with·an·error·code546 »       false··#·end·with·an·error·code
547 elif·test·"$rc"·!=·0;·then547 elif·test·"$rc"·!=·0;·then
548 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2548 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
549 »       false··#·end·with·an·error·code549 »       false··#·end·with·an·error·code
550 fi550 fi
 551 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 552 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 553 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 554 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 555 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 556 ---
 557 apiVersion:·machineconfiguration.openshift.io/v1
 558 kind:·MachineConfig
 559 spec:
 560 ··config:
 561 ····ignition:
 562 ······version:·3.1.0
 563 ····systemd:
 564 ······units:
 565 ········-·name:·configure-crypto-policy.service
 566 ··········enabled:·true
 567 ··········contents:·|
 568 ············[Unit]
 569 ············Before=kubelet.service
 570 ············[Service]
 571 ············Type=oneshot
 572 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 573 ············RemainAfterExit=yes
 574 ············[Install]
 575 ············WantedBy=multi-user.target
551 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8576 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
552 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low577 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
553 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low578 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
554 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false579 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
555 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict580 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
556 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable581 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
557 ··set_fact:582 ··set_fact:
Offset 599, 39 lines modifiedOffset 624, 14 lines modified
599 ··-·PCI-DSSv4-2.2.7624 ··-·PCI-DSSv4-2.2.7
600 ··-·configure_crypto_policy625 ··-·configure_crypto_policy
601 ··-·high_severity626 ··-·high_severity
602 ··-·low_complexity627 ··-·low_complexity
603 ··-·low_disruption628 ··-·low_disruption
604 ··-·no_reboot_needed629 ··-·no_reboot_needed
605 ··-·restrict_strategy630 ··-·restrict_strategy
606 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
607 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
608 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
609 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
610 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
611 --- 
612 apiVersion:·machineconfiguration.openshift.io/v1 
613 kind:·MachineConfig 
614 spec: 
615 ··config: 
616 ····ignition: 
617 ······version:·3.1.0 
618 ····systemd: 
619 ······units: 
620 ········-·name:·configure-crypto-policy.service 
621 ··········enabled:·true 
622 ··········contents:·| 
623 ············[Unit] 
624 ············Before=kubelet.service 
625 ············[Service] 
626 ············Type=oneshot 
627 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
628 ············RemainAfterExit=yes 
629 ············[Install] 
630 ············WantedBy=multi-user.target 
631 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*631 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
632 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.632 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
633 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.633 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
634 Severity: ···medium634 Severity: ···medium
635 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy635 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
636 Identifiers:·CCE-88557-4636 Identifiers:·CCE-88557-4
637 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453637 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
Offset 724, 29 lines modifiedOffset 724, 29 lines modified
724 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)724 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4,·SC-5(2)
725 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4725 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.DS-4,·PR.PT-1,·PR.PT-4
726 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1726 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1
727 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227727 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000341-GPOS-00132,·SRG-OS-000480-GPOS-00227
728 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800728 ·············_\x8a_\x8p_\x8p_\x8-_\x8s_\x8r_\x8g_\x8-_\x8c_\x8t_\x8r····SRG-APP-000357-CTR-000800
729 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71729 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
730 ·············_\x8c_\x8i_\x8s············1.1.2.7.1730 ·············_\x8c_\x8i_\x8s············1.1.2.7.1
731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
732 [[customizations.filesystem]] 
733 mountpoint·=·"/var/log/audit" 
734 size·=·10737418240 
735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8731 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
736 logvol·/var/log/audit·10240732 logvol·/var/log/audit·10240
737 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8733 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
738 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low734 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
739 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high735 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
740 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false736 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
741 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable737 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
742 part·/var/log/audit738 part·/var/log/audit
 739 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 740 [[customizations.filesystem]]
 741 mountpoint·=·"/var/log/audit"
 742 size·=·10737418240
743 Group  ·GNOME·Desktop·Environment·  Group·contains·1·rule743 Group  ·GNOME·Desktop·Environment·  Group·contains·1·rule
744 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.744 _\x8[_\x8r_\x8e_\x8f_\x8]  ·GNOME·is·a·graphical·desktop·environment·bundled·with·many·Linux·distributions·that·allow·users·to·easily·interact·with·the·operating·system·graphically·rather·than·textually.·The·GNOME·Graphical·Display·Manager·(GDM)·provides·login,·logout,·and·user·switching·contexts·as·well·as·display·server·management.
  
745 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.745 GNOME·is·developed·by·the·GNOME·Project·and·is·considered·the·default·Red·Hat·Graphical·environment.
  
746 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.746 For·more·information·on·GNOME·and·the·GNOME·Project,·see·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8w\x8w_\x8w\x8w_\x8w\x8w_\x8.\x8._\x8g\x8g_\x8n\x8n_\x8o\x8o_\x8m\x8m_\x8e\x8e_\x8.\x8._\x8o\x8o_\x8r\x8r_\x8g\x8g.
747 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*747 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·M\x8Ma\x8ak\x8ke\x8e·s\x8su\x8ur\x8re\x8e·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·d\x8dc\x8co\x8on\x8nf\x8f·d\x8da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8es\x8s·a\x8ar\x8re\x8e·u\x8up\x8p-\x8-t\x8to\x8o-\x8-d\x8da\x8at\x8te\x8e·w\x8wi\x8it\x8th\x8h·r\x8re\x8eg\x8ga\x8ar\x8rd\x8ds\x8s·t\x8to\x8o·r\x8re\x8es\x8sp\x8pe\x8ec\x8ct\x8ti\x8iv\x8ve\x8e·k\x8ke\x8ey\x8yf\x8fi\x8il\x8le\x8es\x8s·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 1354, 18 lines modifiedOffset 1354, 21 lines modified
1354 Identifiers:·CCE-90212-21354 Identifiers:·CCE-90212-2
1355 ·············_\x8c_\x8u_\x8i····3.4.51355 ·············_\x8c_\x8u_\x8i····3.4.5
1356 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-0022351356 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
1357 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1357 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1358 ·············_\x8n_\x8i_\x8s_\x8t···CM-61358 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
1359 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.11359 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
1360 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271360 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1362 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1363 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1364 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1365 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
Max diff block lines reached; 182962/189178 bytes (96.71%) of diff not shown.
2.71 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ism_o.html
    
Offset 15120, 281 lines modifiedOffset 15120, 281 lines modified
0003b0f0:·6172·6765·743d·2223·6964·6d37·3330·3722··arget="#idm7307"0003b0f0:·6172·6765·743d·2223·6964·6d37·3330·3722··arget="#idm7307"
0003b100:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b100:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b110:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b110:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b120:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b120:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b130:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b130:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b140:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b140:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b150:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b150:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003b160:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003b170:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003b180:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b190:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b1a0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b1b0:·2269·646d·3733·3037·223e·3c70·7265·3e3c··"idm7307"><pre>< 
0003b1c0:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003b1d0:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003b1e0:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003b1f0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b200:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b210:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b220:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b230:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b240:·2223·6964·6d37·3330·3822·2074·6162·696e··"#idm7308"·tabin 
0003b250:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b260:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b270:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b280:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b290:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b2a0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b2b0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a0003b160:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a
0003b2c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b170:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b2d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b180:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b2e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b190:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b2f0:·6d37·3330·3822·3e3c·7461·626c·6520·636c··m7308"><table·cl0003b1a0:·6d37·3330·3722·3e3c·7461·626c·6520·636c··m7307"><table·cl
0003b300:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b1b0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b310:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b1c0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b320:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b1d0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b330:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b1e0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b340:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b1f0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b350:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b200:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b360:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b210:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b370:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003b220:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003b380:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b230:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b390:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b240:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b3a0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003b250:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003b3b0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b260:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003b3c0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003b270:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003b3d0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003b280:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003b3e0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#0003b290:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003b2a0:·7061·636b·6167·6520·696e·7374·616c·6c20··package·install·
0003b3f0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b400:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b410:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b420:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu 
0003b430:·6965·7420·2d71·206b·6572·6e65·6c3b·2074··iet·-q·kernel;·t 
0003b440:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q 
0003b450:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"· 
0003b460:·3b20·7468·656e·0a20·2020·2064·6e66·2069··;·then.····dnf·i 
0003b470:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003b480:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g 
0003b490:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003b4a0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003b4b0:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003b4c0:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003b4d0:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>0003b2b0:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr
0003b4e0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003b2c0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003b4f0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003b2d0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003b500:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003b2e0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003b510:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003b2f0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003b520:·6765·743d·2223·6964·6d37·3330·3922·2074··get="#idm7309"·t0003b300:·6172·6765·743d·2223·6964·6d37·3330·3822··arget="#idm7308"
0003b530:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b310:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b540:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b320:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b550:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b330:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b560:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b340:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b570:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b350:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b580:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b360:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
 0003b370:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
0003b590:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003b5a0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b5b0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b5c0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b5d0:·2069·643d·2269·646d·3733·3039·223e·3c74···id="idm7309"><t 
0003b5e0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b5f0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b600:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b610:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b620:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b630:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b640:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b650:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b660:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b670:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b680:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b690:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b6a0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003b6b0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003b6c0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b6d0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4761··<code>-·name:·Ga 
0003b6e0:·7468·6572·2074·6865·2070·6163·6b61·6765··ther·the·package 
0003b6f0:·2066·6163·7473·0a20·2070·6163·6b61·6765···facts.··package 
0003b700:·5f66·6163·7473·3a0a·2020·2020·6d61·6e61··_facts:.····mana 
0003b710:·6765·723a·2061·7574·6f0a·2020·7461·6773··ger:·auto.··tags 
0003b720:·3a0a·2020·2d20·4343·452d·3930·3437·372d··:.··-·CCE-90477- 
0003b730:·310a·2020·2d20·434a·4953·2d35·2e31·302e··1.··-·CJIS-5.10. 
0003b740:·312e·330a·2020·2d20·4e49·5354·2d38·3030··1.3.··-·NIST-800 
0003b750:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-· 
0003b760:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.5 
0003b770:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1 
0003b780:·312e·352e·320a·2020·2d20·656e·6162·6c65··1.5.2.··-·enable 
0003b790:·5f73·7472·6174·6567·790a·2020·2d20·6c6f··_strategy.··-·lo 
0003b7a0:·775f·636f·6d70·6c65·7869·7479·0a20·202d··w_complexity.··- 
0003b7b0:·206c·6f77·5f64·6973·7275·7074·696f·6e0a···low_disruption. 
0003b7c0:·2020·2d20·6d65·6469·756d·5f73·6576·6572····-·medium_sever 
0003b7d0:·6974·790a·2020·2d20·6e6f·5f72·6562·6f6f··ity.··-·no_reboo 
0003b7e0:·745f·6e65·6564·6564·0a20·202d·2070·6163··t_needed.··-·pac 
0003b7f0:·6b61·6765·5f61·6964·655f·696e·7374·616c··kage_aide_instal 
0003b800:·6c65·640a·0a2d·206e·616d·653a·2045·6e73··led..-·name:·Ens 
0003b810:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst 
0003b820:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package: 
0003b830:·0a20·2020·206e·616d·653a·2061·6964·650a··.····name:·aide. 
0003b840:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese 
0003b850:·6e74·0a20·2077·6865·6e3a·2027·226b·6572··nt.··when:·'"ker 
0003b860:·6e65·6c22·2069·6e20·616e·7369·626c·655f··nel"·in·ansible_ 
0003b870:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
0003b880:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE- 
0003b890:·3930·3437·372d·310a·2020·2d20·434a·4953··90477-1.··-·CJIS 
0003b8a0:·2d35·2e31·302e·312e·330a·2020·2d20·4e49··-5.10.1.3.··-·NI 
0003b8b0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a 
Max diff block lines reached; 2564406/2601832 bytes (98.56%) of diff not shown.
233 KB
html2text {}
    
Offset 105, 19 lines modifiedOffset 105, 21 lines modified
105 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)105 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
106 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3106 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
108 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199108 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
109 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79109 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
110 ·············_\x8c_\x8i_\x8s············6.1.1110 ·············_\x8c_\x8i_\x8s············6.1.1
111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 117 package·install·aide
113 [[packages]] 
114 name·=·"aide" 
115 version·=·"*" 
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
121 #·Remediation·is·applicable·only·in·certain·platforms123 #·Remediation·is·applicable·only·in·certain·platforms
122 if·rpm·--quiet·-q·kernel;·then124 if·rpm·--quiet·-q·kernel;·then
Offset 163, 14 lines modifiedOffset 165, 26 lines modified
163 ··-·PCI-DSSv4-11.5.2165 ··-·PCI-DSSv4-11.5.2
164 ··-·enable_strategy166 ··-·enable_strategy
165 ··-·low_complexity167 ··-·low_complexity
166 ··-·low_disruption168 ··-·low_disruption
167 ··-·medium_severity169 ··-·medium_severity
168 ··-·no_reboot_needed170 ··-·no_reboot_needed
169 ··-·package_aide_installed171 ··-·package_aide_installed
 172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 177 package·--add=aide
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 179 [[packages]]
 180 name·=·"aide"
 181 version·=·"*"
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
175 dnf·install·aide187 dnf·install·aide
Offset 182, 28 lines modifiedOffset 196, 14 lines modified
182 include·install_aide196 include·install_aide
  
183 class·install_aide·{197 class·install_aide·{
184 ··package·{·'aide':198 ··package·{·'aide':
185 ····ensure·=>·'installed',199 ····ensure·=>·'installed',
186 ··}200 ··}
187 }201 }
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
193 package·install·aide 
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
199 package·--add=aide 
200 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules202 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
201 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.203 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
202 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.204 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
203 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.205 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 220, 31 lines modifiedOffset 220, 31 lines modified
220 Identifiers:·CCE-86982-6220 Identifiers:·CCE-86982-6
221 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877221 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
222 ·············_\x8i_\x8s_\x8m······1446222 ·············_\x8i_\x8s_\x8m······1446
223 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1223 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
224 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12224 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
225 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1225 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
226 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176226 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
228 [customizations] 
229 fips·=·true 
230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
231 #·Remediation·is·applicable·only·in·certain·platforms228 #·Remediation·is·applicable·only·in·certain·platforms
232 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then229 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
233 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then230 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
234 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF231 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
235 kargs·=·["fips=1"]232 kargs·=·["fips=1"]
236 EOF233 EOF
237 fi234 fi
  
238 else235 else
239 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'236 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
240 fi237 fi
 238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 239 [customizations]
 240 fips·=·true
241 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*241 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
242 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:242 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
243 #·cat·/proc/sys/crypto/fips_enabled243 #·cat·/proc/sys/crypto/fips_enabled
244 1244 1
245 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.245 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
246 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.246 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
247 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.247 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 298, 14 lines modifiedOffset 298, 39 lines modified
298 »       echo·"to·see·what·package·to·(re)install"·>&2298 »       echo·"to·see·what·package·to·(re)install"·>&2
  
299 »       false··#·end·with·an·error·code299 »       false··#·end·with·an·error·code
300 elif·test·"$rc"·!=·0;·then300 elif·test·"$rc"·!=·0;·then
301 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2301 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
302 »       false··#·end·with·an·error·code302 »       false··#·end·with·an·error·code
303 fi303 fi
 304 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 305 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 306 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 229521/238149 bytes (96.38%) of diff not shown.
2.71 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ism_o_secret.html
    
Offset 15124, 281 lines modifiedOffset 15124, 281 lines modified
0003b130:·7267·6574·3d22·2369·646d·3733·3037·2220··rget="#idm7307"·0003b130:·7267·6574·3d22·2369·646d·3733·3037·2220··rget="#idm7307"·
0003b140:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b140:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b150:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b150:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b160:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b160:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b170:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b170:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b180:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b180:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b190:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b190:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003b1a0:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
0003b1b0:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
0003b1c0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b1d0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b1e0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b1f0:·6964·6d37·3330·3722·3e3c·7072·653e·3c63··idm7307"><pre><c 
0003b200:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
0003b210:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide". 
0003b220:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
0003b230:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
0003b240:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
0003b250:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
0003b260:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
0003b270:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
0003b280:·2369·646d·3733·3038·2220·7461·6269·6e64··#idm7308"·tabind 
0003b290:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
0003b2a0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
0003b2b0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
0003b2c0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
0003b2d0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
0003b2e0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
0003b2f0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>0003b1a0:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a>
0003b300:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="0003b1b0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b310:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c0003b1c0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003b320:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b1d0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b330:·3733·3038·223e·3c74·6162·6c65·2063·6c61··7308"><table·cla0003b1e0:·3733·3037·223e·3c74·6162·6c65·2063·6c61··7307"><table·cla
0003b340:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-0003b1f0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
0003b350:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo0003b200:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
0003b360:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con0003b210:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
0003b370:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>0003b220:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
0003b380:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>0003b230:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
0003b390:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003b240:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003b3a0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt0003b250:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003b3b0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low0003b260:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
0003b3c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b3d0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b3e0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b3f0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b400:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b410:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b420:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#· 
0003b430:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
0003b440:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003b450:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003b460:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui 
0003b470:·6574·202d·7120·6b65·726e·656c·3b20·7468··et·-q·kernel;·th 
0003b480:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
0003b490:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
0003b4a0:·2074·6865·6e0a·2020·2020·646e·6620·696e···then.····dnf·in 
0003b4b0:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
0003b4c0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003b4d0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003b4e0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003b4f0:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
0003b500:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
0003b510:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
0003b520:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003b530:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003b540:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003b550:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003b560:·6574·3d22·2369·646d·3733·3039·2220·7461··et="#idm7309"·ta 
0003b570:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003b580:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003b590:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003b5a0:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003b5b0:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003b5c0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003b5d0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
0003b5e0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003b5f0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003b600:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003b610:·6964·3d22·6964·6d37·3330·3922·3e3c·7461··id="idm7309"><ta 
0003b620:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003b630:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003b640:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003b650:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003b660:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003b670:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003b680:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b690:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003b6a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b6b0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003b6c0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003b6d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b6e0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003b6f0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003b700:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003b710:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat 
0003b720:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package· 
0003b730:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_ 
0003b740:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag 
0003b750:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags: 
0003b760:·0a20·202d·2043·4345·2d39·3034·3737·2d31··.··-·CCE-90477-1 
0003b770:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1 
0003b780:·2e33·0a20·202d·204e·4953·542d·3830·302d··.3.··-·NIST-800- 
0003b790:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
0003b7a0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
0003b7b0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
0003b7c0:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
0003b7d0:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
0003b7e0:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
0003b7f0:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
0003b800:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
0003b810:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
0003b820:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
0003b830:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
0003b840:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu 
0003b850:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
0003b860:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
0003b870:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
0003b880:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
0003b890:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern 
0003b8a0:·656c·2220·696e·2061·6e73·6962·6c65·5f66··el"·in·ansible_f 
0003b8b0:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
0003b8c0:·2074·6167·733a·0a20·202d·2043·4345·2d39···tags:.··-·CCE-9 
0003b8d0:·3034·3737·2d31·0a20·202d·2043·4a49·532d··0477-1.··-·CJIS- 
0003b8e0:·352e·3130·2e31·2e33·0a20·202d·204e·4953··5.10.1.3.··-·NIS 
0003b8f0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003b900:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003b910:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
Max diff block lines reached; 2564475/2601901 bytes (98.56%) of diff not shown.
233 KB
html2text {}
    
Offset 106, 19 lines modifiedOffset 106, 21 lines modified
106 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)106 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
107 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3107 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
109 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199109 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
110 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79110 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
111 ·············_\x8c_\x8i_\x8s············6.1.1111 ·············_\x8c_\x8i_\x8s············6.1.1
112 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2112 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 118 package·install·aide
114 [[packages]] 
115 name·=·"aide" 
116 version·=·"*" 
117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
122 #·Remediation·is·applicable·only·in·certain·platforms124 #·Remediation·is·applicable·only·in·certain·platforms
123 if·rpm·--quiet·-q·kernel;·then125 if·rpm·--quiet·-q·kernel;·then
Offset 164, 14 lines modifiedOffset 166, 26 lines modified
164 ··-·PCI-DSSv4-11.5.2166 ··-·PCI-DSSv4-11.5.2
165 ··-·enable_strategy167 ··-·enable_strategy
166 ··-·low_complexity168 ··-·low_complexity
167 ··-·low_disruption169 ··-·low_disruption
168 ··-·medium_severity170 ··-·medium_severity
169 ··-·no_reboot_needed171 ··-·no_reboot_needed
170 ··-·package_aide_installed172 ··-·package_aide_installed
 173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 178 package·--add=aide
 179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 180 [[packages]]
 181 name·=·"aide"
 182 version·=·"*"
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
176 dnf·install·aide188 dnf·install·aide
Offset 183, 28 lines modifiedOffset 197, 14 lines modified
183 include·install_aide197 include·install_aide
  
184 class·install_aide·{198 class·install_aide·{
185 ··package·{·'aide':199 ··package·{·'aide':
186 ····ensure·=>·'installed',200 ····ensure·=>·'installed',
187 ··}201 ··}
188 }202 }
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
194 package·install·aide 
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
200 package·--add=aide 
201 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules203 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
202 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.204 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
203 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.205 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
204 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.206 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*207 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 221, 31 lines modifiedOffset 221, 31 lines modified
221 Identifiers:·CCE-86982-6221 Identifiers:·CCE-86982-6
222 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877222 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
223 ·············_\x8i_\x8s_\x8m······1446223 ·············_\x8i_\x8s_\x8m······1446
224 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1224 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
225 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12225 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
226 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1226 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
227 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176227 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
229 [customizations] 
230 fips·=·true 
231 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8228 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
232 #·Remediation·is·applicable·only·in·certain·platforms229 #·Remediation·is·applicable·only·in·certain·platforms
233 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then230 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
234 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then231 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
235 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF232 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
236 kargs·=·["fips=1"]233 kargs·=·["fips=1"]
237 EOF234 EOF
238 fi235 fi
  
239 else236 else
240 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'237 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
241 fi238 fi
 239 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 240 [customizations]
 241 fips·=·true
242 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*242 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
243 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:243 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
244 #·cat·/proc/sys/crypto/fips_enabled244 #·cat·/proc/sys/crypto/fips_enabled
245 1245 1
246 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.246 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
247 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.247 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
248 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.248 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 299, 14 lines modifiedOffset 299, 39 lines modified
299 »       echo·"to·see·what·package·to·(re)install"·>&2299 »       echo·"to·see·what·package·to·(re)install"·>&2
  
300 »       false··#·end·with·an·error·code300 »       false··#·end·with·an·error·code
301 elif·test·"$rc"·!=·0;·then301 elif·test·"$rc"·!=·0;·then
302 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2302 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
303 »       false··#·end·with·an·error·code303 »       false··#·end·with·an·error·code
304 fi304 fi
 305 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 306 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 307 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 229521/238149 bytes (96.38%) of diff not shown.
2.71 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ism_o_top_secret.html
    
Offset 15121, 281 lines modifiedOffset 15121, 281 lines modified
0003b100:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b100:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b110:·646d·3733·3037·2220·7461·6269·6e64·6578··dm7307"·tabindex0003b110:·646d·3733·3037·2220·7461·6269·6e64·6578··dm7307"·tabindex
0003b120:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b120:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b130:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b130:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b140:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b140:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b150:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b150:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b160:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b160:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b170:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b170:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
0003b180:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b190:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b1a0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b1b0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b1c0:·7365·2220·6964·3d22·6964·6d37·3330·3722··se"·id="idm7307" 
0003b1d0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
0003b1e0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b1f0:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b200:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003b210:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b220:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b230:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b240:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b250:·7461·7267·6574·3d22·2369·646d·3733·3038··target="#idm7308 
0003b260:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b270:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b280:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b290:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b2a0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b2b0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b2c0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b2d0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b180:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b2e0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b190:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b2f0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b1a0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b300:·2069·643d·2269·646d·3733·3038·223e·3c74···id="idm7308"><t0003b1b0:·2069·643d·2269·646d·3733·3037·223e·3c74···id="idm7307"><t
0003b310:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b1c0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b320:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b1d0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b330:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b1e0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b340:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b1f0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b350:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b200:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b360:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003b210:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003b370:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b220:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b380:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003b230:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b390:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b240:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b3a0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b250:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b3b0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b260:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b3c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b270:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b3d0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b280:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b3e0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b290:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003b3f0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b2a0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b2b0:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i
 0003b2c0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co
0003b400:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b410:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b420:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b430:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r 
0003b440:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003b450:·726e·656c·3b20·7468·656e·0a0a·6966·2021··rnel;·then..if·! 
0003b460:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003b470:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003b480:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y 
0003b490:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003b4a0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b4b0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b4c0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b4d0:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b4e0:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b4f0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003b2d0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003b500:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003b2e0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003b510:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003b2f0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003b520:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003b300:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003b530:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b310:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b540:·3733·3039·2220·7461·6269·6e64·6578·3d22··7309"·tabindex="0003b320:·646d·3733·3038·2220·7461·6269·6e64·6578··dm7308"·tabindex
0003b550:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b330:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b560:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b340:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b570:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b350:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b580:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b360:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b590:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b370:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003b380:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003b5a0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible· 
0003b5b0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b5c0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b5d0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b5e0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b5f0:·3330·3922·3e3c·7461·626c·6520·636c·6173··309"><table·clas 
0003b600:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b610:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b620:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b630:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b640:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b650:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b660:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b670:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b680:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b690:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b6a0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b6b0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b6c0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b6d0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b6e0:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n 
0003b6f0:·616d·653a·2047·6174·6865·7220·7468·6520··ame:·Gather·the· 
0003b700:·7061·636b·6167·6520·6661·6374·730a·2020··package·facts.·· 
0003b710:·7061·636b·6167·655f·6661·6374·733a·0a20··package_facts:.· 
0003b720:·2020·206d·616e·6167·6572·3a20·6175·746f·····manager:·auto 
0003b730:·0a20·2074·6167·733a·0a20·202d·2043·4345··.··tags:.··-·CCE 
0003b740:·2d39·3034·3737·2d31·0a20·202d·2043·4a49··-90477-1.··-·CJI 
0003b750:·532d·352e·3130·2e31·2e33·0a20·202d·204e··S-5.10.1.3.··-·N 
0003b760:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003b770:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003b780:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003b790:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003b7a0:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003b7b0:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003b7c0:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003b7d0:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
0003b7e0:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n 
0003b7f0:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed. 
0003b800:·2020·2d20·7061·636b·6167·655f·6169·6465····-·package_aide 
0003b810:·5f69·6e73·7461·6c6c·6564·0a0a·2d20·6e61··_installed..-·na 
0003b820:·6d65·3a20·456e·7375·7265·2061·6964·6520··me:·Ensure·aide· 
0003b830:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p 
0003b840:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name 
0003b850:·3a20·6169·6465·0a20·2020·2073·7461·7465··:·aide.····state 
0003b860:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when 
0003b870:·3a20·2722·6b65·726e·656c·2220·696e·2061··:·'"kernel"·in·a 
0003b880:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
0003b890:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.· 
0003b8a0:·202d·2043·4345·2d39·3034·3737·2d31·0a20···-·CCE-90477-1.· 
0003b8b0:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
Max diff block lines reached; 2564682/2602108 bytes (98.56%) of diff not shown.
233 KB
html2text {}
    
Offset 105, 19 lines modifiedOffset 105, 21 lines modified
105 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)105 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
106 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3106 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
108 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199108 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
109 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79109 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
110 ·············_\x8c_\x8i_\x8s············6.1.1110 ·············_\x8c_\x8i_\x8s············6.1.1
111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 117 package·install·aide
113 [[packages]] 
114 name·=·"aide" 
115 version·=·"*" 
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
121 #·Remediation·is·applicable·only·in·certain·platforms123 #·Remediation·is·applicable·only·in·certain·platforms
122 if·rpm·--quiet·-q·kernel;·then124 if·rpm·--quiet·-q·kernel;·then
Offset 163, 14 lines modifiedOffset 165, 26 lines modified
163 ··-·PCI-DSSv4-11.5.2165 ··-·PCI-DSSv4-11.5.2
164 ··-·enable_strategy166 ··-·enable_strategy
165 ··-·low_complexity167 ··-·low_complexity
166 ··-·low_disruption168 ··-·low_disruption
167 ··-·medium_severity169 ··-·medium_severity
168 ··-·no_reboot_needed170 ··-·no_reboot_needed
169 ··-·package_aide_installed171 ··-·package_aide_installed
 172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 177 package·--add=aide
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 179 [[packages]]
 180 name·=·"aide"
 181 version·=·"*"
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
175 dnf·install·aide187 dnf·install·aide
Offset 182, 28 lines modifiedOffset 196, 14 lines modified
182 include·install_aide196 include·install_aide
  
183 class·install_aide·{197 class·install_aide·{
184 ··package·{·'aide':198 ··package·{·'aide':
185 ····ensure·=>·'installed',199 ····ensure·=>·'installed',
186 ··}200 ··}
187 }201 }
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
193 package·install·aide 
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
199 package·--add=aide 
200 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules202 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
201 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.203 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
202 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.204 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·10.
  
203 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.205 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*206 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 220, 31 lines modifiedOffset 220, 31 lines modified
220 Identifiers:·CCE-86982-6220 Identifiers:·CCE-86982-6
221 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877221 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
222 ·············_\x8i_\x8s_\x8m······1446222 ·············_\x8i_\x8s_\x8m······1446
223 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1223 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
224 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12224 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
225 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1225 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
226 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176226 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
228 [customizations] 
229 fips·=·true 
230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
231 #·Remediation·is·applicable·only·in·certain·platforms228 #·Remediation·is·applicable·only·in·certain·platforms
232 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then229 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
233 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then230 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
234 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF231 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
235 kargs·=·["fips=1"]232 kargs·=·["fips=1"]
236 EOF233 EOF
237 fi234 fi
  
238 else235 else
239 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'236 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
240 fi237 fi
 238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 239 [customizations]
 240 fips·=·true
241 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*241 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·V\x8Ve\x8er\x8ri\x8if\x8fy\x8y·t\x8th\x8ha\x8at\x8t·t\x8th\x8he\x8e·s\x8sy\x8ys\x8st\x8te\x8em\x8m·w\x8wa\x8as\x8s·b\x8bo\x8oo\x8ot\x8te\x8ed\x8d·w\x8wi\x8it\x8th\x8h·f\x8fi\x8ip\x8ps\x8s=\x8=1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
242 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:242 On·a·system·where·FIPS·140·mode·is·enabled,·the·system·must·be·booted·with·the·The·file·/proc/sys/crypto/fips_enabled·must·have·the·contents·of·1·To·verify·the·system·has·been·booted·in·FIPS·mode,·run·the·following·command:
243 #·cat·/proc/sys/crypto/fips_enabled243 #·cat·/proc/sys/crypto/fips_enabled
244 1244 1
245 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.245 Warning: ·To·configure·Red·Hat·Enterprise·Linux·10·to·run·in·FIPS·140·mode,·the·kernel·parameter·"fips=1"·needs·to·be·added·during·its·installation.·Only·enabling·FIPS·140·mode·during·the·Red·Hat·Enterprise·Linux·10·installation·ensures·that·the·system·generates·all·keys·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.·Enabling·FIPS·mode·on·a·preexisting·system·involves·a·number·of·modifications·to·it·and·therefore·is·not·supported.
246 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.246 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x83\x83_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
247 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.247 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
Offset 298, 14 lines modifiedOffset 298, 39 lines modified
298 »       echo·"to·see·what·package·to·(re)install"·>&2298 »       echo·"to·see·what·package·to·(re)install"·>&2
  
299 »       false··#·end·with·an·error·code299 »       false··#·end·with·an·error·code
300 elif·test·"$rc"·!=·0;·then300 elif·test·"$rc"·!=·0;·then
301 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2301 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
302 »       false··#·end·with·an·error·code302 »       false··#·end·with·an·error·code
303 fi303 fi
 304 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 305 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 306 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 229521/238149 bytes (96.38%) of diff not shown.
3.16 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-ospp.html
    
Offset 15073, 62 lines modifiedOffset 15073, 62 lines modified
0003ae00:·6172·6765·743d·2223·6964·6d37·3832·3622··arget="#idm7826"0003ae00:·6172·6765·743d·2223·6964·6d37·3832·3622··arget="#idm7826"
0003ae10:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003ae10:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003ae20:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003ae20:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003ae30:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003ae30:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003ae40:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003ae40:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003ae50:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003ae50:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003ae60:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003ae60:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003ae70:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003ae80:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003ae90:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003aea0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003aeb0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003aec0:·2269·646d·3738·3236·223e·3c70·7265·3e3c··"idm7826"><pre>< 
0003aed0:·636f·6465·3e0a·5b63·7573·746f·6d69·7a61··code>.[customiza 
0003aee0:·7469·6f6e·735d·0a66·6970·7320·3d20·7472··tions].fips·=·tr 
0003aef0:·7565·0a3c·2f63·6f64·653e·3c2f·7072·653e··ue.</code></pre> 
0003af00:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003af10:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003af20:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003af30:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003af40:·6765·743d·2223·6964·6d37·3832·3722·2074··get="#idm7827"·t 
0003af50:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003af60:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003af70:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003af80:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003af90:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003afa0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003afb0:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..0003ae70:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
0003afc0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003ae80:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003afd0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003ae90:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003afe0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003aea0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003aff0:·3d22·6964·6d37·3832·3722·3e3c·7072·653e··="idm7827"><pre>0003aeb0:·6964·3d22·6964·6d37·3832·3622·3e3c·7072··id="idm7826"><pr
0003b000:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat0003aec0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
0003b010:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl0003aed0:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
0003b020:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai0003aee0:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
0003b030:·6e20·706c·6174·666f·726d·730a·6966·2028··n·platforms.if·(0003aef0:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
0003b040:·2021·2028·205b·2022·247b·636f·6e74·6169···!·(·[·"${contai0003af00:·2028·2021·2028·205b·2022·247b·636f·6e74···(·!·(·[·"${cont
0003b050:·6e65·723a·2d7d·2220·3d3d·2022·6277·7261··ner:-}"·==·"bwra0003af10:·6169·6e65·723a·2d7d·2220·3d3d·2022·6277··ainer:-}"·==·"bw
0003b060:·702d·6f73·6275·696c·6422·205d·2029·2026··p-osbuild"·]·)·&0003af20:·7261·702d·6f73·6275·696c·6422·205d·2029··rap-osbuild"·]·)
0003b070:·616d·703b·2661·6d70·3b20·7270·6d20·2d2d··amp;&amp;·rpm·--0003af30:·2026·616d·703b·2661·6d70·3b20·7270·6d20···&amp;&amp;·rpm·
0003b080:·7175·6965·7420·2d71·206b·6572·6e65·6c20··quiet·-q·kernel·0003af40:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
0003b090:·293b·2074·6865·6e0a·0a69·6620·5b5b·2022··);·then..if·[[·"0003af50:·6c20·293b·2074·6865·6e0a·0a69·6620·5b5b··l·);·then..if·[[
0003b0a0:·244f·5343·4150·5f42·4f4f·5443·5f42·5549··$OSCAP_BOOTC_BUI0003af60:·2022·244f·5343·4150·5f42·4f4f·5443·5f42···"$OSCAP_BOOTC_B
0003b0b0:·4c44·2220·3d3d·2022·5945·5322·205d·5d3b··LD"·==·"YES"·]];0003af70:·5549·4c44·2220·3d3d·2022·5945·5322·205d··UILD"·==·"YES"·]
0003b0c0:·2074·6865·6e0a·0963·6174·2026·6774·3b20···then..cat·&gt;·0003af80:·5d3b·2074·6865·6e0a·0963·6174·2026·6774··];·then..cat·&gt
0003b0d0:·2f75·7372·2f6c·6962·2f62·6f6f·7463·2f6b··/usr/lib/bootc/k0003af90:·3b20·2f75·7372·2f6c·6962·2f62·6f6f·7463··;·/usr/lib/bootc
0003b0e0:·6172·6773·2e64·2f30·312d·6669·7073·2e74··args.d/01-fips.t0003afa0:·2f6b·6172·6773·2e64·2f30·312d·6669·7073··/kargs.d/01-fips
0003b0f0:·6f6d·6c20·266c·743b·266c·743b·2045·4f46··oml·&lt;&lt;·EOF0003afb0:·2e74·6f6d·6c20·266c·743b·266c·743b·2045··.toml·&lt;&lt;·E
0003b100:·0a6b·6172·6773·203d·205b·2266·6970·733d··.kargs·=·["fips=0003afc0:·4f46·0a6b·6172·6773·203d·205b·2266·6970··OF.kargs·=·["fip
0003b110:·3122·5d0a·454f·460a·6669·0a0a·656c·7365··1"].EOF.fi..else0003afd0:·733d·3122·5d0a·454f·460a·6669·0a0a·656c··s=1"].EOF.fi..el
0003b120:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2·0003afe0:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp;
0003b130:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio0003aff0:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat
0003b140:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica0003b000:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli
0003b150:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was0003b010:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w
0003b160:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code0003b020:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co
 0003b030:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003b040:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b050:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
 0003b060:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
 0003b070:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
 0003b080:·646d·3738·3237·2220·7461·6269·6e64·6578··dm7827"·tabindex
 0003b090:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
 0003b0a0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
 0003b0b0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
 0003b0c0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
 0003b0d0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
 0003b0e0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil
 0003b0f0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip
 0003b100:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br><
 0003b110:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 0003b120:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 0003b130:·7365·2220·6964·3d22·6964·6d37·3832·3722··se"·id="idm7827"
 0003b140:·3e3c·7072·653e·3c63·6f64·653e·0a5b·6375··><pre><code>.[cu
 0003b150:·7374·6f6d·697a·6174·696f·6e73·5d0a·6669··stomizations].fi
 0003b160:·7073·203d·2074·7275·650a·3c2f·636f·6465··ps·=·true.</code
0003b170:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d0003b170:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·2f64··></pre></div></d
0003b180:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t0003b180:·6976·3e3c·2f74·643e·3c2f·7472·3e3c·2f74··iv></td></tr></t
0003b190:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t0003b190:·626f·6479·3e3c·2f74·6162·6c65·3e3c·2f74··body></table></t
0003b1a0:·643e·3c2f·7472·3e3c·7472·2064·6174·612d··d></tr><tr·data-0003b1a0:·643e·3c2f·7472·3e3c·7472·2064·6174·612d··d></tr><tr·data-
0003b1b0:·7474·2d69·643d·2263·6869·6c64·7265·6e2d··tt-id="children-0003b1b0:·7474·2d69·643d·2263·6869·6c64·7265·6e2d··tt-id="children-
0003b1c0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro0003b1c0:·7863·6364·665f·6f72·672e·7373·6770·726f··xccdf_org.ssgpro
0003b1d0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro0003b1d0:·6a65·6374·2e63·6f6e·7465·6e74·5f67·726f··ject.content_gro
Offset 15425, 252 lines modifiedOffset 15425, 252 lines modified
0003c400:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003c400:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003c410:·6d37·3934·3522·2074·6162·696e·6465·783d··m7945"·tabindex=0003c410:·6d37·3934·3522·2074·6162·696e·6465·783d··m7945"·tabindex=
0003c420:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003c420:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003c430:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003c430:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003c440:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003c440:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003c450:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003c450:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003c460:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003c460:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003c470:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script·
 0003c480:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003c490:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003c4a0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003c4b0:·6964·3d22·6964·6d37·3934·3522·3e3c·7461··id="idm7945"><ta
 0003c4c0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003c4d0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003c4e0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003c4f0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003c500:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003c510:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003c520:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003c530:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003c470:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0003c480:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003c490:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003c4a0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c4b0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c4c0:·6522·2069·643d·2269·646d·3739·3435·223e··e"·id="idm7945"> 
0003c4d0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003c4e0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003c4f0:·2263·7279·7074·6f2d·706f·6c69·6369·6573··"crypto-policies 
0003c500:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003c510:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003c520:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003c530:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003c540:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003c550:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003c560:·3d22·2369·646d·3739·3436·2220·7461·6269··="#idm7946"·tabi 
0003c570:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003c580:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003c590:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003c5a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003c5b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003c5c0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003c5d0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</ 
0003c5e0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
Max diff block lines reached; 2909647/2950687 bytes (98.61%) of diff not shown.
350 KB
html2text {}
    
Offset 92, 31 lines modifiedOffset 92, 31 lines modified
92 Identifiers:·CCE-86982-692 Identifiers:·CCE-86982-6
93 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-00087793 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
94 ·············_\x8i_\x8s_\x8m······144694 ·············_\x8i_\x8s_\x8m······1446
95 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.195 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
96 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-1296 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
97 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.197 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
98 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-0017698 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
99 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
100 [customizations] 
101 fips·=·true 
102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
103 #·Remediation·is·applicable·only·in·certain·platforms100 #·Remediation·is·applicable·only·in·certain·platforms
104 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then101 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
105 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then102 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
106 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF103 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
107 kargs·=·["fips=1"]104 kargs·=·["fips=1"]
108 EOF105 EOF
109 fi106 fi
  
110 else107 else
111 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'108 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
112 fi109 fi
 110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 111 [customizations]
 112 fips·=·true
113 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules113 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules
114 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:114 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
115 ····*·GnuTLS·library115 ····*·GnuTLS·library
116 ····*·OpenSSL·library116 ····*·OpenSSL·library
117 ····*·NSS·library117 ····*·NSS·library
118 ····*·OpenJDK118 ····*·OpenJDK
119 ····*·Libkrb5119 ····*·Libkrb5
Offset 129, 19 lines modifiedOffset 129, 21 lines modified
129 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.129 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
130 Severity: ···medium130 Severity: ···medium
131 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed131 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
132 Identifiers:·CCE-89668-8132 Identifiers:·CCE-89668-8
133 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123133 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
134 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1134 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
135 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174135 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 141 package·install·crypto-policies
137 [[packages]] 
138 name·=·"crypto-policies" 
139 version·=·"*" 
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
145 if·!·rpm·-q·--quiet·"crypto-policies"·;·then147 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 160, 14 lines modifiedOffset 162, 26 lines modified
160 ··-·CCE-89668-8162 ··-·CCE-89668-8
161 ··-·enable_strategy163 ··-·enable_strategy
162 ··-·low_complexity164 ··-·low_complexity
163 ··-·low_disruption165 ··-·low_disruption
164 ··-·medium_severity166 ··-·medium_severity
165 ··-·no_reboot_needed167 ··-·no_reboot_needed
166 ··-·package_crypto-policies_installed168 ··-·package_crypto-policies_installed
 169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 174 package·--add=crypto-policies
 175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 176 [[packages]]
 177 name·=·"crypto-policies"
 178 version·=·"*"
167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
172 dnf·install·crypto-policies184 dnf·install·crypto-policies
Offset 179, 28 lines modifiedOffset 193, 14 lines modified
179 include·install_crypto-policies193 include·install_crypto-policies
  
180 class·install_crypto-policies·{194 class·install_crypto-policies·{
181 ··package·{·'crypto-policies':195 ··package·{·'crypto-policies':
182 ····ensure·=>·'installed',196 ····ensure·=>·'installed',
183 ··}197 ··}
184 }198 }
185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
190 package·install·crypto-policies 
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
196 package·--add=crypto-policies 
197 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
198 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:200 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
199 $·sudo·update-crypto-policies·--set·FIPS:OSPP201 $·sudo·update-crypto-policies·--set·FIPS:OSPP
200 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.202 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
201 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.203 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
202 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.204 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
203 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.205 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 231, 14 lines modifiedOffset 231, 39 lines modified
231 »       echo·"to·see·what·package·to·(re)install"·>&2231 »       echo·"to·see·what·package·to·(re)install"·>&2
  
232 »       false··#·end·with·an·error·code232 »       false··#·end·with·an·error·code
233 elif·test·"$rc"·!=·0;·then233 elif·test·"$rc"·!=·0;·then
234 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2234 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
235 »       false··#·end·with·an·error·code235 »       false··#·end·with·an·error·code
236 fi236 fi
 237 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 238 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 239 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 349797/358313 bytes (97.62%) of diff not shown.
2.71 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-pci-dss.html
    
Offset 16701, 281 lines modifiedOffset 16701, 281 lines modified
000413c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm000413c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
000413d0:·3733·3037·2220·7461·6269·6e64·6578·3d22··7307"·tabindex="000413d0:·3733·3037·2220·7461·6269·6e64·6578·3d22··7307"·tabindex="
000413e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"000413e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
000413f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="000413f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00041400:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00041400:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00041410:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00041410:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00041420:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00041420:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00041430:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·00041430:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
00041440:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
00041450:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00041460:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00041470:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00041480:·2220·6964·3d22·6964·6d37·3330·3722·3e3c··"·id="idm7307">< 
00041490:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
000414a0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
000414b0:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=· 
000414c0:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
000414d0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
000414e0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
000414f0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
00041500:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
00041510:·7267·6574·3d22·2369·646d·3733·3038·2220··rget="#idm7308"· 
00041520:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
00041530:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
00041540:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
00041550:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
00041560:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
00041570:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
00041580:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
00041590:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c00041440:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
000415a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll00041450:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
000415b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i00041460:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
000415c0:·643d·2269·646d·3733·3038·223e·3c74·6162··d="idm7308"><tab00041470:·643d·2269·646d·3733·3037·223e·3c74·6162··d="idm7307"><tab
000415d0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·00041480:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
000415e0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta00041490:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
000415f0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab000414a0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
00041600:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t000414b0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
00041610:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity000414c0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
00041620:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t000414d0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
00041630:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D000414e0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
00041640:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><000414f0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
00041650:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>00041500:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
00041660:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<00041510:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
00041670:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t00041520:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
00041680:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00041530:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
00041690:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00041540:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
000416a0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr00041550:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
000416b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c00041560:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00041570:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins
 00041580:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code
000416c0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
000416d0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
000416e0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
000416f0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm 
00041700:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern 
00041710:·656c·3b20·7468·656e·0a0a·6966·2021·2072··el;·then..if·!·r 
00041720:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
00041730:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
00041740:·646e·6620·696e·7374·616c·6c20·2d79·2022··dnf·install·-y·" 
00041750:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
00041760:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
00041770:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
00041780:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
00041790:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
000417a0:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
000417b0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl00041590:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
000417c0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc000415a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
000417d0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl000415b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
000417e0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat000415c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
000417f0:·612d·7461·7267·6574·3d22·2369·646d·3733··a-target="#idm73000415d0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00041800:·3039·2220·7461·6269·6e64·6578·3d22·3022··09"·tabindex="0"000415e0:·3733·3038·2220·7461·6269·6e64·6578·3d22··7308"·tabindex="
00041810:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a000415f0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00041820:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00041600:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00041830:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00041610:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00041840:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00041620:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00041850:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00041630:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00041640:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 00041650:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 00041660:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00041670:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00041680:·7073·6522·2069·643d·2269·646d·3733·3038··pse"·id="idm7308
 00041690:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 000416a0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
00041860:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
00041870:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
00041880:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00041890:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
000418a0:·6170·7365·2220·6964·3d22·6964·6d37·3330··apse"·id="idm730 
000418b0:·3922·3e3c·7461·626c·6520·636c·6173·733d··9"><table·class= 
000418c0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
000418d0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
000418e0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden000416b0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
000418f0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
00041900:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
00041910:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
00041920:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00041930:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00041940:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
00041950:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f000416c0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 000416d0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 000416e0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 000416f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00041700:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00041710:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00041720:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00041730:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00041740:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00041750:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00041760:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00041770:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 00041780:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 00041790:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 000417a0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 000417b0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 000417c0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 000417d0:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then..
 000417e0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 000417f0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 00041800:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal
 00041810:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 00041820:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 00041830:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 00041840:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 00041850:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 00041860:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 00041870:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 00041880:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
Max diff block lines reached; 2582609/2620035 bytes (98.57%) of diff not shown.
221 KB
html2text {}
    
Offset 511, 19 lines modifiedOffset 511, 21 lines modified
511 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)511 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
512 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3512 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
513 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5513 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
514 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199514 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
515 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79515 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
516 ·············_\x8c_\x8i_\x8s············6.1.1516 ·············_\x8c_\x8i_\x8s············6.1.1
517 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2517 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
518 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8518 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 519 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 520 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 521 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 522 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 523 package·install·aide
519 [[packages]] 
520 name·=·"aide" 
521 version·=·"*" 
522 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
523 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low525 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
524 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low526 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
525 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false527 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
526 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable528 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
527 #·Remediation·is·applicable·only·in·certain·platforms529 #·Remediation·is·applicable·only·in·certain·platforms
528 if·rpm·--quiet·-q·kernel;·then530 if·rpm·--quiet·-q·kernel;·then
Offset 569, 14 lines modifiedOffset 571, 26 lines modified
569 ··-·PCI-DSSv4-11.5.2571 ··-·PCI-DSSv4-11.5.2
570 ··-·enable_strategy572 ··-·enable_strategy
571 ··-·low_complexity573 ··-·low_complexity
572 ··-·low_disruption574 ··-·low_disruption
573 ··-·medium_severity575 ··-·medium_severity
574 ··-·no_reboot_needed576 ··-·no_reboot_needed
575 ··-·package_aide_installed577 ··-·package_aide_installed
 578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 579 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 580 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 581 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 582 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 583 package·--add=aide
 584 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 585 [[packages]]
 586 name·=·"aide"
 587 version·=·"*"
576 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8588 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
577 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low589 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
578 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low590 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
579 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false591 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
580 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable592 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
581 dnf·install·aide593 dnf·install·aide
Offset 588, 28 lines modifiedOffset 602, 14 lines modified
588 include·install_aide602 include·install_aide
  
589 class·install_aide·{603 class·install_aide·{
590 ··package·{·'aide':604 ··package·{·'aide':
591 ····ensure·=>·'installed',605 ····ensure·=>·'installed',
592 ··}606 ··}
593 }607 }
594 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
595 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
596 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
597 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
598 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
599 package·install·aide 
600 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
601 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
602 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
603 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
604 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
605 package·--add=aide 
606 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*608 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
607 Run·the·following·command·to·generate·a·new·database:609 Run·the·following·command·to·generate·a·new·database:
608 $·sudo·/usr/sbin/aide·--init610 $·sudo·/usr/sbin/aide·--init
609 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:611 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
610 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz612 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
611 To·initiate·a·manual·check,·run·the·following·command:613 To·initiate·a·manual·check,·run·the·following·command:
612 $·sudo·/usr/sbin/aide·--check614 $·sudo·/usr/sbin/aide·--check
Offset 963, 14 lines modifiedOffset 963, 39 lines modified
963 »       echo·"to·see·what·package·to·(re)install"·>&2963 »       echo·"to·see·what·package·to·(re)install"·>&2
  
964 »       false··#·end·with·an·error·code964 »       false··#·end·with·an·error·code
965 elif·test·"$rc"·!=·0;·then965 elif·test·"$rc"·!=·0;·then
966 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2966 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
967 »       false··#·end·with·an·error·code967 »       false··#·end·with·an·error·code
968 fi968 fi
 969 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 970 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 971 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 972 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 973 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 974 ---
 975 apiVersion:·machineconfiguration.openshift.io/v1
 976 kind:·MachineConfig
 977 spec:
 978 ··config:
 979 ····ignition:
 980 ······version:·3.1.0
 981 ····systemd:
 982 ······units:
 983 ········-·name:·configure-crypto-policy.service
 984 ··········enabled:·true
 985 ··········contents:·|
 986 ············[Unit]
 987 ············Before=kubelet.service
 988 ············[Service]
 989 ············Type=oneshot
 990 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 991 ············RemainAfterExit=yes
 992 ············[Install]
 993 ············WantedBy=multi-user.target
969 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8994 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
970 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low995 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
971 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low996 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
972 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false997 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
973 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict998 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
974 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable999 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
975 ··set_fact:1000 ··set_fact:
Offset 1017, 39 lines modifiedOffset 1042, 14 lines modified
1017 ··-·PCI-DSSv4-2.2.71042 ··-·PCI-DSSv4-2.2.7
1018 ··-·configure_crypto_policy1043 ··-·configure_crypto_policy
1019 ··-·high_severity1044 ··-·high_severity
1020 ··-·low_complexity1045 ··-·low_complexity
1021 ··-·low_disruption1046 ··-·low_disruption
1022 ··-·no_reboot_needed1047 ··-·no_reboot_needed
Max diff block lines reached; 221128/226016 bytes (97.84%) of diff not shown.
4.53 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-stig.html
    
Offset 15128, 281 lines modifiedOffset 15128, 281 lines modified
0003b170:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b170:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b180:·3d22·2369·646d·3733·3037·2220·7461·6269··="#idm7307"·tabi0003b180:·3d22·2369·646d·3733·3037·2220·7461·6269··="#idm7307"·tabi
0003b190:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b190:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b1a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b1a0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b1b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b1b0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b1c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b1c0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b1d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b1d0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b1e0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003b1e0:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
0003b1f0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003b200:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b210:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b220:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b230:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b240:·3330·3722·3e3c·7072·653e·3c63·6f64·653e··307"><pre><code> 
0003b250:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003b260:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003b270:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003b280:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b290:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b2a0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b2b0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b2c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b2d0:·3733·3038·2220·7461·6269·6e64·6578·3d22··7308"·tabindex=" 
0003b2e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b2f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b300:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b310:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b320:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b330:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b340:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0003b1f0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
0003b350:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b200:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003b360:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b210:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003b370:·7073·6522·2069·643d·2269·646d·3733·3038··pse"·id="idm73080003b220:·7073·6522·2069·643d·2269·646d·3733·3037··pse"·id="idm7307
0003b380:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b230:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003b390:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b240:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003b3a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b250:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003b3b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b260:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003b3c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b270:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003b3d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b280:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003b3e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b290:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003b3f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b2a0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003b400:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b2b0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003b410:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b2c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003b420:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b2d0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003b430:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b2e0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003b440:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003b2f0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003b450:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003b300:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003b460:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003b310:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003b470:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme0003b320:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003b330:·6765·2069·6e73·7461·6c6c·2061·6964·650a··ge·install·aide.
0003b480:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b490:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b4a0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b4b0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003b4c0:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then.. 
0003b4d0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003b4e0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003b4f0:·6e0a·2020·2020·646e·6620·696e·7374·616c··n.····dnf·instal 
0003b500:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003b510:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003b520:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003b530:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003b540:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003b550:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003b560:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003b340:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003b570:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003b350:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003b580:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003b360:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003b590:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003b370:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003b5a0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b380:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b5b0:·2369·646d·3733·3039·2220·7461·6269·6e64··#idm7309"·tabind0003b390:·3d22·2369·646d·3733·3038·2220·7461·6269··="#idm7308"·tabi
0003b5c0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b3a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b5d0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b3b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b5e0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b3c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b5f0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b3d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b600:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b3e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b610:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003b3f0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
0003b620:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003b630:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003b640:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003b650:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003b660:·6964·6d37·3330·3922·3e3c·7461·626c·6520··idm7309"><table· 
0003b670:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003b680:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003b690:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table- 
0003b6a0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003b6b0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003b6c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b6d0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003b6e0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003b6f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b700:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003b710:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003b720:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003b730:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003b740:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003b750:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003b760:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather· 
0003b770:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact 
0003b780:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact 
0003b790:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:· 
0003b7a0:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··- 
0003b7b0:·2043·4345·2d39·3034·3737·2d31·0a20·202d···CCE-90477-1.··- 
0003b7c0:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003b7d0:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0003b7e0:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D 
0003b7f0:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-· 
0003b800:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2 
0003b810:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0003b820:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0003b830:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
0003b840:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m 
0003b850:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.· 
0003b860:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
0003b870:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_ 
0003b880:·6169·6465·5f69·6e73·7461·6c6c·6564·0a0a··aide_installed.. 
0003b890:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a 
0003b8a0:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed 
0003b8b0:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.···· 
0003b8c0:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s 
0003b8d0:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.·· 
0003b8e0:·7768·656e·3a20·2722·6b65·726e·656c·2220··when:·'"kernel"· 
0003b8f0:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
0003b900:·2e70·6163·6b61·6765·7327·0a20·2074·6167··.packages'.··tag 
0003b910:·733a·0a20·202d·2043·4345·2d39·3034·3737··s:.··-·CCE-90477 
0003b920:·2d31·0a20·202d·2043·4a49·532d·352e·3130··-1.··-·CJIS-5.10 
0003b930:·2e31·2e33·0a20·202d·204e·4953·542d·3830··.1.3.··-·NIST-80 
0003b940:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
Max diff block lines reached; 4257309/4294735 bytes (99.13%) of diff not shown.
442 KB
html2text {}
    
Offset 105, 19 lines modifiedOffset 105, 21 lines modified
105 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)105 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
106 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3106 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
108 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199108 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
109 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79109 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
110 ·············_\x8c_\x8i_\x8s············6.1.1110 ·············_\x8c_\x8i_\x8s············6.1.1
111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 117 package·install·aide
113 [[packages]] 
114 name·=·"aide" 
115 version·=·"*" 
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
121 #·Remediation·is·applicable·only·in·certain·platforms123 #·Remediation·is·applicable·only·in·certain·platforms
122 if·rpm·--quiet·-q·kernel;·then124 if·rpm·--quiet·-q·kernel;·then
Offset 163, 14 lines modifiedOffset 165, 26 lines modified
163 ··-·PCI-DSSv4-11.5.2165 ··-·PCI-DSSv4-11.5.2
164 ··-·enable_strategy166 ··-·enable_strategy
165 ··-·low_complexity167 ··-·low_complexity
166 ··-·low_disruption168 ··-·low_disruption
167 ··-·medium_severity169 ··-·medium_severity
168 ··-·no_reboot_needed170 ··-·no_reboot_needed
169 ··-·package_aide_installed171 ··-·package_aide_installed
 172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 177 package·--add=aide
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 179 [[packages]]
 180 name·=·"aide"
 181 version·=·"*"
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
175 dnf·install·aide187 dnf·install·aide
Offset 182, 28 lines modifiedOffset 196, 14 lines modified
182 include·install_aide196 include·install_aide
  
183 class·install_aide·{197 class·install_aide·{
184 ··package·{·'aide':198 ··package·{·'aide':
185 ····ensure·=>·'installed',199 ····ensure·=>·'installed',
186 ··}200 ··}
187 }201 }
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
193 package·install·aide 
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
199 package·--add=aide 
200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
201 Run·the·following·command·to·generate·a·new·database:203 Run·the·following·command·to·generate·a·new·database:
202 $·sudo·/usr/sbin/aide·--init204 $·sudo·/usr/sbin/aide·--init
203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:205 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz206 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
205 To·initiate·a·manual·check,·run·the·following·command:207 To·initiate·a·manual·check,·run·the·following·command:
206 $·sudo·/usr/sbin/aide·--check208 $·sudo·/usr/sbin/aide·--check
Offset 2028, 31 lines modifiedOffset 2028, 31 lines modified
2028 Identifiers:·CCE-86982-62028 Identifiers:·CCE-86982-6
2029 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008772029 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
2030 ·············_\x8i_\x8s_\x8m······14462030 ·············_\x8i_\x8s_\x8m······1446
2031 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.12031 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
2032 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-122032 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
2033 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.12033 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
2034 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001762034 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
2035 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2036 [customizations] 
2037 fips·=·true 
2038 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82035 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2039 #·Remediation·is·applicable·only·in·certain·platforms2036 #·Remediation·is·applicable·only·in·certain·platforms
2040 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then2037 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
2041 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then2038 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
2042 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF2039 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
2043 kargs·=·["fips=1"]2040 kargs·=·["fips=1"]
2044 EOF2041 EOF
2045 fi2042 fi
  
2046 else2043 else
2047 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2044 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2048 fi2045 fi
 2046 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2047 [customizations]
 2048 fips·=·true
2049 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2049 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2050 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·10·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.2050 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·10·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
2051 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.2051 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
2052 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.2052 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
2053 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.2053 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
2054 Severity: ···high2054 Severity: ···high
2055 Rule·ID:·····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled2055 Rule·ID:·····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled
Offset 2090, 19 lines modifiedOffset 2090, 21 lines modified
2090 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.2090 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
2091 Severity: ···medium2091 Severity: ···medium
2092 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed2092 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
2093 Identifiers:·CCE-89668-82093 Identifiers:·CCE-89668-8
2094 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-0031232094 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
2095 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.12095 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
2096 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001742096 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
2097 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82097 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 2098 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2099 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 444328/452637 bytes (98.16%) of diff not shown.
4.43 MB
./usr/share/doc/ssg-nondebian/ssg-rhel10-guide-stig_gui.html
    
Offset 15124, 280 lines modifiedOffset 15124, 280 lines modified
0003b130:·6574·3d22·2369·646d·3733·3037·2220·7461··et="#idm7307"·ta0003b130:·6574·3d22·2369·646d·3733·3037·2220·7461··et="#idm7307"·ta
0003b140:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b140:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b150:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b150:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b160:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b160:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b170:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b170:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b180:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b180:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b190:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b190:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b1a0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003b1b0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003b1c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b1d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b1e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b1f0:·6d37·3330·3722·3e3c·7072·653e·3c63·6f64··m7307"><pre><cod 
0003b200:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003b210:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003b220:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003b230:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b240:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b250:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b260:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b270:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b280:·646d·3733·3038·2220·7461·6269·6e64·6578··dm7308"·tabindex 
0003b290:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b2a0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b2b0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b2c0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b2d0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b2e0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b2f0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b0003b1a0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
0003b300:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003b1b0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b310:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003b1c0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b320:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm730003b1d0:·6c61·7073·6522·2069·643d·2269·646d·3733··lapse"·id="idm73
0003b330:·3038·223e·3c74·6162·6c65·2063·6c61·7373··08"><table·class0003b1e0:·3037·223e·3c74·6162·6c65·2063·6c61·7373··07"><table·class
0003b340:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003b1f0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b350:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003b200:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b360:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003b210:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b370:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003b220:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b380:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003b230:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b390:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b240:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b3a0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b250:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b3b0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003b260:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b3c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003b3d0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003b3e0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003b3f0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b400:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b410:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b420:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
0003b430:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b440:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b450:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b460:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
0003b470:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
0003b480:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b490:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b4a0:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
0003b4b0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b4c0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b4d0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b4e0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b4f0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b500:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b510:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b520:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b530:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b540:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b550:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b560:·3d22·2369·646d·3733·3039·2220·7461·6269··="#idm7309"·tabi 
0003b570:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b580:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b590:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b5a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b5b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b5c0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003b5d0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b5e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b5f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b600:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b610:·3d22·6964·6d37·3330·3922·3e3c·7461·626c··="idm7309"><tabl 
0003b620:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b630:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b640:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b650:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b660:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b670:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b680:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b690:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b6a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b6b0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b6c0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b6d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b6e0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b6f0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b700:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b710:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
0003b720:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
0003b730:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
0003b740:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
0003b750:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
0003b760:·202d·2043·4345·2d39·3034·3737·2d31·0a20···-·CCE-90477-1.· 
0003b770:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003b780:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003b790:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI 
0003b7a0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.·· 
0003b7b0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5 
0003b7c0:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st 
0003b7d0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c 
0003b7e0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo 
0003b7f0:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··- 
0003b800:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity 
0003b810:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n 
0003b820:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag 
0003b830:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed 
0003b840:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure 
0003b850:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install 
0003b860:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.·· 
0003b870:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.··· 
0003b880:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present. 
0003b890:·2020·7768·656e·3a20·2722·6b65·726e·656c····when:·'"kernel 
0003b8a0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
0003b8b0:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t 
0003b8c0:·6167·733a·0a20·202d·2043·4345·2d39·3034··ags:.··-·CCE-904 
0003b8d0:·3737·2d31·0a20·202d·2043·4a49·532d·352e··77-1.··-·CJIS-5. 
0003b8e0:·3130·2e31·2e33·0a20·202d·204e·4953·542d··10.1.3.··-·NIST- 
0003b8f0:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
0003b900:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
0003b910:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
Max diff block lines reached; 4168694/4205982 bytes (99.11%) of diff not shown.
433 KB
html2text {}
    
Offset 104, 19 lines modifiedOffset 104, 21 lines modified
104 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)104 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
105 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3105 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
106 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5106 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
108 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79108 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
109 ·············_\x8c_\x8i_\x8s············6.1.1109 ·············_\x8c_\x8i_\x8s············6.1.1
110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 116 package·install·aide
112 [[packages]] 
113 name·=·"aide" 
114 version·=·"*" 
115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
120 #·Remediation·is·applicable·only·in·certain·platforms122 #·Remediation·is·applicable·only·in·certain·platforms
121 if·rpm·--quiet·-q·kernel;·then123 if·rpm·--quiet·-q·kernel;·then
Offset 162, 14 lines modifiedOffset 164, 26 lines modified
162 ··-·PCI-DSSv4-11.5.2164 ··-·PCI-DSSv4-11.5.2
163 ··-·enable_strategy165 ··-·enable_strategy
164 ··-·low_complexity166 ··-·low_complexity
165 ··-·low_disruption167 ··-·low_disruption
166 ··-·medium_severity168 ··-·medium_severity
167 ··-·no_reboot_needed169 ··-·no_reboot_needed
168 ··-·package_aide_installed170 ··-·package_aide_installed
 171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 176 package·--add=aide
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 178 [[packages]]
 179 name·=·"aide"
 180 version·=·"*"
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
174 dnf·install·aide186 dnf·install·aide
Offset 181, 28 lines modifiedOffset 195, 14 lines modified
181 include·install_aide195 include·install_aide
  
182 class·install_aide·{196 class·install_aide·{
183 ··package·{·'aide':197 ··package·{·'aide':
184 ····ensure·=>·'installed',198 ····ensure·=>·'installed',
185 ··}199 ··}
186 }200 }
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
192 package·install·aide 
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
198 package·--add=aide 
199 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*201 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
200 Run·the·following·command·to·generate·a·new·database:202 Run·the·following·command·to·generate·a·new·database:
201 $·sudo·/usr/sbin/aide·--init203 $·sudo·/usr/sbin/aide·--init
202 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:204 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
203 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz205 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
204 To·initiate·a·manual·check,·run·the·following·command:206 To·initiate·a·manual·check,·run·the·following·command:
205 $·sudo·/usr/sbin/aide·--check207 $·sudo·/usr/sbin/aide·--check
Offset 2027, 31 lines modifiedOffset 2027, 31 lines modified
2027 Identifiers:·CCE-86982-62027 Identifiers:·CCE-86982-6
2028 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008772028 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
2029 ·············_\x8i_\x8s_\x8m······14462029 ·············_\x8i_\x8s_\x8m······1446
2030 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.12030 References:··_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
2031 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-122031 ·············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
2032 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.12032 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
2033 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001762033 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
2034 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2035 [customizations] 
2036 fips·=·true 
2037 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82034 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2038 #·Remediation·is·applicable·only·in·certain·platforms2035 #·Remediation·is·applicable·only·in·certain·platforms
2039 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then2036 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
2040 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then2037 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
2041 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF2038 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
2042 kargs·=·["fips=1"]2039 kargs·=·["fips=1"]
2043 EOF2040 EOF
2044 fi2041 fi
  
2045 else2042 else
2046 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2043 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2047 fi2044 fi
 2045 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2046 [customizations]
 2047 fips·=·true
2048 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*2048 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
2049 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·10·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.2049 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·10·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
2050 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.2050 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
2051 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.2051 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
2052 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.2052 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
2053 Severity: ···high2053 Severity: ···high
2054 Rule·ID:·····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled2054 Rule·ID:·····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled
Offset 2089, 19 lines modifiedOffset 2089, 21 lines modified
2089 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.2089 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
2090 Severity: ···medium2090 Severity: ···medium
2091 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed2091 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
2092 Identifiers:·CCE-89668-82092 Identifiers:·CCE-89668-8
2093 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-0031232093 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
2094 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.12094 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
2095 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-001742095 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
2096 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x82096 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 2097 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2098 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 435102/443411 bytes (98.13%) of diff not shown.
3.07 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_enhanced.html
    
Offset 15247, 284 lines modifiedOffset 15247, 284 lines modified
0003b8e0:·6765·743d·2223·6964·6d37·3939·3022·2074··get="#idm7990"·t0003b8e0:·6765·743d·2223·6964·6d37·3939·3022·2074··get="#idm7990"·t
0003b8f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b8f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b900:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b900:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b910:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b910:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b920:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b920:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b930:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b930:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b940:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b940:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b950:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003b960:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003b970:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b980:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b990:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b9a0:·646d·3739·3930·223e·3c70·7265·3e3c·636f··dm7990"><pre><co 
0003b9b0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003b9c0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003b9d0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003b9e0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b9f0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003ba00:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003ba10:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003ba20:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003ba30:·6964·6d37·3939·3122·2074·6162·696e·6465··idm7991"·tabinde 
0003ba40:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003ba50:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003ba60:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003ba70:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003ba80:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003ba90:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003baa0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><0003b950:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003bab0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b960:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003bac0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b970:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003bad0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm70003b980:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7
0003bae0:·3939·3122·3e3c·7461·626c·6520·636c·6173··991"><table·clas0003b990:·3939·3022·3e3c·7461·626c·6520·636c·6173··990"><table·clas
0003baf0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b9a0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003bb00:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003b9b0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
0003bb10:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b9c0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
0003bb20:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003b9d0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
0003bb30:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003b9e0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
0003bb40:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003b9f0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003bb50:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003ba00:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
0003bb60:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003ba10:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
0003bb70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003ba20:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003bb80:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003ba30:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
0003bb90:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003ba40:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
0003bba0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy0003ba50:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
0003bbb0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable0003ba60:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
0003bbc0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl0003ba70:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003bbd0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R0003ba80:·653e·3c70·7265·3e3c·636f·6465·3e0a·7061··e><pre><code>.pa
 0003ba90:·636b·6167·6520·696e·7374·616c·6c20·6169··ckage·install·ai
0003bbe0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003bbf0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003bc00:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003bc10:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003bc20:·7420·2d71·206b·6572·6e65·6c3b·2074·6865··t·-q·kernel;·the 
0003bc30:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003bc40:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003bc50:·7468·656e·0a20·2020·2079·756d·2069·6e73··then.····yum·ins 
0003bc60:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003bc70:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003bc80:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003bc90:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003bca0:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003bcb0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003bcc0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003baa0:·6465·0a3c·2f63·6f64·653e·3c2f·7072·653e··de.</code></pre>
0003bcd0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt0003bab0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003bce0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d0003bac0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003bcf0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll0003bad0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003bd00:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003bae0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003bd10:·743d·2223·6964·6d37·3939·3222·2074·6162··t="#idm7992"·tab0003baf0:·6765·743d·2223·6964·6d37·3939·3122·2074··get="#idm7991"·t
0003bd20:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003bb00:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003bd30:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003bb10:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003bd40:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003bb20:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003bd50:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003bb30:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003bd60:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003bb40:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003bd70:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003bb50:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003bb60:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003bb70:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003bb80:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003bb90:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003bba0:·3d22·6964·6d37·3939·3122·3e3c·7461·626c··="idm7991"><tabl
 0003bbb0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003bbc0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003bbd0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003bbe0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003bbf0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003bc00:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003bc10:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003bc20:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
0003bd80:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003bd90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003bda0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003bdb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003bdc0:·643d·2269·646d·3739·3932·223e·3c74·6162··d="idm7992"><tab 
0003bdd0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003bde0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003bdf0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003be00:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003be10:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003be20:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003be30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003be40:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003be50:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003be60:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003be70:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003be80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003be90:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003bea0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003beb0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003bec0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003bed0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f 
0003bee0:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f 
0003bef0:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage 
0003bf00:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:. 
0003bf10:·2020·2d20·4343·452d·3830·3834·342d·340a····-·CCE-80844-4. 
0003bf20:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003bf30:·330a·2020·2d20·4449·5341·2d53·5449·472d··3.··-·DISA-STIG- 
0003bf40:·5248·454c·2d30·382d·3031·3033·3539·0a20··RHEL-08-010359.· 
0003bf50:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0003bf60:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D 
0003bf70:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-· 
0003bf80:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2 
0003bf90:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0003bfa0:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0003bfb0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
0003bfc0:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m 
0003bfd0:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.· 
0003bfe0:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
Max diff block lines reached; 2956458/2994298 bytes (98.74%) of diff not shown.
223 KB
html2text {}
    
Offset 115, 19 lines modifiedOffset 115, 21 lines modified
115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
116 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199116 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
117 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359117 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
118 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79118 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
119 ·············_\x8c_\x8i_\x8s············5.3.1119 ·············_\x8c_\x8i_\x8s············5.3.1
120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
121 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule121 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 127 package·install·aide
123 [[packages]] 
124 name·=·"aide" 
125 version·=·"*" 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
131 #·Remediation·is·applicable·only·in·certain·platforms133 #·Remediation·is·applicable·only·in·certain·platforms
132 if·rpm·--quiet·-q·kernel;·then134 if·rpm·--quiet·-q·kernel;·then
Offset 175, 14 lines modifiedOffset 177, 26 lines modified
175 ··-·PCI-DSSv4-11.5.2177 ··-·PCI-DSSv4-11.5.2
176 ··-·enable_strategy178 ··-·enable_strategy
177 ··-·low_complexity179 ··-·low_complexity
178 ··-·low_disruption180 ··-·low_disruption
179 ··-·medium_severity181 ··-·medium_severity
180 ··-·no_reboot_needed182 ··-·no_reboot_needed
181 ··-·package_aide_installed183 ··-·package_aide_installed
 184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 189 package·--add=aide
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 191 [[packages]]
 192 name·=·"aide"
 193 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
187 dnf·install·aide199 dnf·install·aide
Offset 194, 28 lines modifiedOffset 208, 14 lines modified
194 include·install_aide208 include·install_aide
  
195 class·install_aide·{209 class·install_aide·{
196 ··package·{·'aide':210 ··package·{·'aide':
197 ····ensure·=>·'installed',211 ····ensure·=>·'installed',
198 ··}212 ··}
199 }213 }
200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
205 package·install·aide 
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
211 package·--add=aide 
212 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
213 Run·the·following·command·to·generate·a·new·database:215 Run·the·following·command·to·generate·a·new·database:
214 $·sudo·/usr/sbin/aide·--init216 $·sudo·/usr/sbin/aide·--init
215 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
216 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
217 To·initiate·a·manual·check,·run·the·following·command:219 To·initiate·a·manual·check,·run·the·following·command:
218 $·sudo·/usr/sbin/aide·--check220 $·sudo·/usr/sbin/aide·--check
Offset 364, 26 lines modifiedOffset 364, 26 lines modified
364 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*364 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
365 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.365 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
366 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.366 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
367 Severity: ···medium367 Severity: ···medium
368 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot368 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
369 Identifiers:·CCE-83336-8369 Identifiers:·CCE-83336-8
370 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28370 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
371 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
372 [[customizations.filesystem]] 
373 mountpoint·=·"/boot" 
374 size·=·1073741824 
375 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8371 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
376 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low372 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
377 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high373 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
378 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false374 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
379 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable375 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
380 part·/boot376 part·/boot
 377 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 378 [[customizations.filesystem]]
 379 mountpoint·=·"/boot"
 380 size·=·1073741824
381 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*381 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
382 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.382 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
383 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.383 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
384 Severity: ···low384 Severity: ···low
385 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home385 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home
386 Identifiers:·CCE-81044-0386 Identifiers:·CCE-81044-0
387 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8387 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 394, 95 lines modifiedOffset 394, 95 lines modified
394 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)394 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
395 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4395 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
396 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227396 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
397 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800397 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
398 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28398 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
399 ·············_\x8c_\x8i_\x8s············1.1.2.3.1399 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
400 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule400 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
401 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
402 [[customizations.filesystem]] 
403 mountpoint·=·"/home" 
404 size·=·1073741824 
405 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8401 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 221722/228029 bytes (97.23%) of diff not shown.
3.19 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_high.html
    
Offset 15252, 284 lines modifiedOffset 15252, 284 lines modified
0003b930:·7461·7267·6574·3d22·2369·646d·3739·3930··target="#idm79900003b930:·7461·7267·6574·3d22·2369·646d·3739·3930··target="#idm7990
0003b940:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b940:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
0003b950:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b950:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
0003b960:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b960:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
0003b970:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b970:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
0003b980:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b980:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
0003b990:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b990:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
0003b9a0:·696f·6e20·4f53·4275·696c·6420·426c·7565··ion·OSBuild·Blue 
0003b9b0:·7072·696e·7420·736e·6970·7065·7420·e287··print·snippet·.. 
0003b9c0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b9d0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b9e0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b9f0:·3d22·6964·6d37·3939·3022·3e3c·7072·653e··="idm7990"><pre> 
0003ba00:·3c63·6f64·653e·0a5b·5b70·6163·6b61·6765··<code>.[[package 
0003ba10:·735d·5d0a·6e61·6d65·203d·2022·6169·6465··s]].name·=·"aide 
0003ba20:·220a·7665·7273·696f·6e20·3d20·222a·220a··".version·=·"*". 
0003ba30:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003ba40:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003ba50:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003ba60:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003ba70:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003ba80:·3d22·2369·646d·3739·3931·2220·7461·6269··="#idm7991"·tabi 
0003ba90:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003baa0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003bab0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003bac0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003bad0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003bae0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh 
0003baf0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</0003b9a0:·696f·6e20·7363·7269·7074·20e2·87b2·3c2f··ion·script·...</
0003bb00:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class0003b9b0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
0003bb10:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse0003b9c0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
0003bb20:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i0003b9d0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
0003bb30:·646d·3739·3931·223e·3c74·6162·6c65·2063··dm7991"><table·c0003b9e0:·646d·3739·3930·223e·3c74·6162·6c65·2063··dm7990"><table·c
0003bb40:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl0003b9f0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003bb50:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-0003ba00:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003bb60:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003ba10:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
0003bb70:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t0003ba20:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
0003bb80:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t0003ba30:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
0003bb90:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003bba0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003bbb0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003bbc0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003bbd0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003bbe0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003bbf0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003bc00:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003bc10:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003bc20:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003bc30:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is 
0003bc40:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only 
0003bc50:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat 
0003bc60:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q 
0003bc70:·7569·6574·202d·7120·6b65·726e·656c·3b20··uiet·-q·kernel;· 
0003bc80:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·- 
0003bc90:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide" 
0003bca0:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum· 
0003bcb0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide 
0003bcc0:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····& 
0003bcd0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·' 
0003bce0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n 
0003bcf0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n 
0003bd00:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done' 
0003bd10:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre 
0003bd20:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003bd30:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003bd40:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003bd50:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003bd60:·7267·6574·3d22·2369·646d·3739·3932·2220··rget="#idm7992"· 
0003bd70:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003bd80:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003bd90:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003bda0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003bdb0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003bdc0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003bdd0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe 
0003bde0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003bdf0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003be00:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003be10:·2220·6964·3d22·6964·6d37·3939·3222·3e3c··"·id="idm7992">< 
0003be20:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003be30:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003be40:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003be50:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003be60:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003be70:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003be80:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003be90:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003bea0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></0003ba40:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
0003beb0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo0003ba50:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
0003bec0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false0003ba60:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
0003bed0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t0003ba70:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bee0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003bef0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003bf00:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003bf10:·3e3c·636f·6465·3e2d·206e·616d·653a·2047··><code>-·name:·G 
0003bf20:·6174·6865·7220·7468·6520·7061·636b·6167··ather·the·packag0003ba80:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003ba90:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003baa0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003bab0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
 0003bac0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003bad0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003bae0:·0a70·6163·6b61·6765·2069·6e73·7461·6c6c··.package·install
 0003baf0:·2061·6964·650a·3c2f·636f·6465·3e3c·2f70···aide.</code></p
 0003bb00:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0003bb10:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0003bb20:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0003bb30:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0003bb40:·7461·7267·6574·3d22·2369·646d·3739·3931··target="#idm7991
 0003bb50:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r
 0003bb60:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari
 0003bb70:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals
 0003bb80:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa
 0003bb90:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr
 0003bba0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat
 0003bbb0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script
 0003bbc0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003bbd0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003bbe0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003bbf0:·2069·643d·2269·646d·3739·3931·223e·3c74···id="idm7991"><t
 0003bc00:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003bc10:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003bc20:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003bc30:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003bc40:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003bc50:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003bc60:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003bc70:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
Max diff block lines reached; 3067102/3104942 bytes (98.78%) of diff not shown.
231 KB
html2text {}
    
Offset 116, 19 lines modifiedOffset 116, 21 lines modified
116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
117 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199117 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
118 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359118 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
119 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ·············_\x8c_\x8i_\x8s············5.3.1120 ·············_\x8c_\x8i_\x8s············5.3.1
121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule122 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 128 package·install·aide
124 [[packages]] 
125 name·=·"aide" 
126 version·=·"*" 
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
132 #·Remediation·is·applicable·only·in·certain·platforms134 #·Remediation·is·applicable·only·in·certain·platforms
133 if·rpm·--quiet·-q·kernel;·then135 if·rpm·--quiet·-q·kernel;·then
Offset 176, 14 lines modifiedOffset 178, 26 lines modified
176 ··-·PCI-DSSv4-11.5.2178 ··-·PCI-DSSv4-11.5.2
177 ··-·enable_strategy179 ··-·enable_strategy
178 ··-·low_complexity180 ··-·low_complexity
179 ··-·low_disruption181 ··-·low_disruption
180 ··-·medium_severity182 ··-·medium_severity
181 ··-·no_reboot_needed183 ··-·no_reboot_needed
182 ··-·package_aide_installed184 ··-·package_aide_installed
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 190 package·--add=aide
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 192 [[packages]]
 193 name·=·"aide"
 194 version·=·"*"
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
188 dnf·install·aide200 dnf·install·aide
Offset 195, 28 lines modifiedOffset 209, 14 lines modified
195 include·install_aide209 include·install_aide
  
196 class·install_aide·{210 class·install_aide·{
197 ··package·{·'aide':211 ··package·{·'aide':
198 ····ensure·=>·'installed',212 ····ensure·=>·'installed',
199 ··}213 ··}
200 }214 }
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
206 package·install·aide 
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
212 package·--add=aide 
213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
214 Run·the·following·command·to·generate·a·new·database:216 Run·the·following·command·to·generate·a·new·database:
215 $·sudo·/usr/sbin/aide·--init217 $·sudo·/usr/sbin/aide·--init
216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
218 To·initiate·a·manual·check,·run·the·following·command:220 To·initiate·a·manual·check,·run·the·following·command:
219 $·sudo·/usr/sbin/aide·--check221 $·sudo·/usr/sbin/aide·--check
Offset 892, 26 lines modifiedOffset 892, 26 lines modified
892 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*892 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/b\x8bo\x8oo\x8ot\x8t·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
893 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.893 It·is·recommended·that·the·/boot·directory·resides·on·a·separate·partition.·This·makes·it·easier·to·apply·restrictions·e.g.·through·the·noexec·mount·option.·Eventually,·the·/boot·partition·can·be·configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
894 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.894 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition·should·be·restricted.
895 Severity: ···medium895 Severity: ···medium
896 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot896 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
897 Identifiers:·CCE-83336-8897 Identifiers:·CCE-83336-8
898 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28898 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
900 [[customizations.filesystem]] 
901 mountpoint·=·"/boot" 
902 size·=·1073741824 
903 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8899 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
904 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low900 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
905 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high901 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
906 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false902 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
907 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable903 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
908 part·/boot904 part·/boot
 905 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 906 [[customizations.filesystem]]
 907 mountpoint·=·"/boot"
 908 size·=·1073741824
909 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*909 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
910 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.910 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at·installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
911 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.911 Rationale:···Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
912 Severity: ···low912 Severity: ···low
913 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home913 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_home
914 Identifiers:·CCE-81044-0914 Identifiers:·CCE-81044-0
915 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8915 ·············_\x8c_\x8i_\x8s_\x8-_\x8c_\x8s_\x8c········12,·15,·8
Offset 922, 95 lines modifiedOffset 922, 95 lines modified
922 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)922 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
923 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4923 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
924 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227924 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
925 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800925 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
926 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28926 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
927 ·············_\x8c_\x8i_\x8s············1.1.2.3.1927 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
928 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule928 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
930 [[customizations.filesystem]] 
931 mountpoint·=·"/home" 
932 size·=·1073741824 
933 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 230136/236443 bytes (97.33%) of diff not shown.
1.87 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_intermediary.html
    
Offset 15242, 285 lines modifiedOffset 15242, 285 lines modified
0003b890:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b890:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b8a0:·3d22·2369·646d·3739·3930·2220·7461·6269··="#idm7990"·tabi0003b8a0:·3d22·2369·646d·3739·3930·2220·7461·6269··="#idm7990"·tabi
0003b8b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b8b0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b8c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b8c0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b8d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b8d0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b8e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b8e0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b8f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b8f0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b900:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003b900:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
0003b910:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003b920:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b930:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b940:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b950:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003b960:·3939·3022·3e3c·7072·653e·3c63·6f64·653e··990"><pre><code> 
0003b970:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003b980:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003b990:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003b9a0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b9b0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b9c0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b9d0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b9e0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b9f0:·3739·3931·2220·7461·6269·6e64·6578·3d22··7991"·tabindex=" 
0003ba00:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003ba10:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003ba20:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003ba30:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003ba40:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003ba50:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003ba60:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0003b910:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
0003ba70:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b920:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003ba80:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b930:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003ba90:·7073·6522·2069·643d·2269·646d·3739·3931··pse"·id="idm79910003b940:·7073·6522·2069·643d·2269·646d·3739·3930··pse"·id="idm7990
0003baa0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b950:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003bab0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003b960:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003bac0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003b970:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003bad0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003b980:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003bae0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003b990:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003baf0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003b9a0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003bb00:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003b9b0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bb10:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003b9c0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003bb20:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b9d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bb30:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003b9e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003bb40:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003b9f0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003bb50:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003ba00:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003bb60:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003ba10:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003bb70:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003ba20:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003bb80:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003ba30:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003bb90:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme0003ba40:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003ba50:·6765·2069·6e73·7461·6c6c·2061·6964·650a··ge·install·aide.
0003bba0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003bbb0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003bbc0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003bbd0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003bbe0:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then.. 
0003bbf0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003bc00:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003bc10:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal 
0003bc20:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003bc30:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003bc40:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003bc50:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003bc60:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003bc70:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003bc80:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003ba60:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003bc90:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003ba70:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003bca0:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003ba80:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003bcb0:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003ba90:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003bcc0:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003baa0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003bcd0:·2369·646d·3739·3932·2220·7461·6269·6e64··#idm7992"·tabind0003bab0:·3d22·2369·646d·3739·3931·2220·7461·6269··="#idm7991"·tabi
0003bce0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003bac0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003bcf0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003bad0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003bd00:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003bae0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003bd10:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003baf0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003bd20:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003bb00:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003bd30:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003bb10:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003bb20:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003bb30:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003bb40:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003bb50:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003bb60:·646d·3739·3931·223e·3c74·6162·6c65·2063··dm7991"><table·c
 0003bb70:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003bd40:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003bd50:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003bd60:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003bd70:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003bd80:·6964·6d37·3939·3222·3e3c·7461·626c·6520··idm7992"><table· 
0003bd90:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003bda0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003bdb0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003bb80:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003bdc0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003bdd0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003bde0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003bdf0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003be00:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003bb90:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003bba0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003bbb0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003bbc0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bbd0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003bbe0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003bbf0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bc00:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003bc10:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003bc20:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003bc30:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003be10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003bc40:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003be20:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003bc50:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003bc60:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003bc70:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003bc80:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003bc90:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q
 0003bca0:·7569·6574·202d·7120·6b65·726e·656c·3b20··uiet·-q·kernel;·
 0003bcb0:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·-
 0003bcc0:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide"
 0003bcd0:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum·
 0003bce0:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003bcf0:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 0003bd00:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 0003bd10:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 0003bd20:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 0003bd30:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 0003bd40:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
 0003bd50:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003bd60:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003bd70:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003bd80:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003bd90:·7267·6574·3d22·2369·646d·3739·3932·2220··rget="#idm7992"·
Max diff block lines reached; 1768176/1806154 bytes (97.90%) of diff not shown.
148 KB
html2text {}
    
Offset 131, 19 lines modifiedOffset 131, 21 lines modified
131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
132 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199132 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
133 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359133 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
134 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79134 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
135 ·············_\x8c_\x8i_\x8s············5.3.1135 ·············_\x8c_\x8i_\x8s············5.3.1
136 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2136 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
137 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule137 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 143 package·install·aide
139 [[packages]] 
140 name·=·"aide" 
141 version·=·"*" 
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8144 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low145 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low146 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false147 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable148 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 #·Remediation·is·applicable·only·in·certain·platforms149 #·Remediation·is·applicable·only·in·certain·platforms
148 if·rpm·--quiet·-q·kernel;·then150 if·rpm·--quiet·-q·kernel;·then
Offset 191, 14 lines modifiedOffset 193, 26 lines modified
191 ··-·PCI-DSSv4-11.5.2193 ··-·PCI-DSSv4-11.5.2
192 ··-·enable_strategy194 ··-·enable_strategy
193 ··-·low_complexity195 ··-·low_complexity
194 ··-·low_disruption196 ··-·low_disruption
195 ··-·medium_severity197 ··-·medium_severity
196 ··-·no_reboot_needed198 ··-·no_reboot_needed
197 ··-·package_aide_installed199 ··-·package_aide_installed
 200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 205 package·--add=aide
 206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 207 [[packages]]
 208 name·=·"aide"
 209 version·=·"*"
198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
203 dnf·install·aide215 dnf·install·aide
Offset 210, 28 lines modifiedOffset 224, 14 lines modified
210 include·install_aide224 include·install_aide
  
211 class·install_aide·{225 class·install_aide·{
212 ··package·{·'aide':226 ··package·{·'aide':
213 ····ensure·=>·'installed',227 ····ensure·=>·'installed',
214 ··}228 ··}
215 }229 }
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
221 package·install·aide 
222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
227 package·--add=aide 
228 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*230 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
229 Run·the·following·command·to·generate·a·new·database:231 Run·the·following·command·to·generate·a·new·database:
230 $·sudo·/usr/sbin/aide·--init232 $·sudo·/usr/sbin/aide·--init
231 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the233 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
232 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these234 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
233 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their235 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
234 integrity.·The·newly-generated·database·can·be·installed·as·follows:236 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 400, 26 lines modifiedOffset 400, 26 lines modified
400 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.400 configured·not·to·be·mounted·automatically·with·the·noauto·mount·option.
401 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition401 Rationale:···The·/boot·partition·contains·the·kernel·and·bootloader·files.·Access·to·this·partition
402 ·············should·be·restricted.402 ·············should·be·restricted.
403 Severity: ···medium403 Severity: ···medium
404 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot404 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_boot
405 Identifiers:·CCE-83336-8405 Identifiers:·CCE-83336-8
406 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28406 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
407 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
408 [[customizations.filesystem]] 
409 mountpoint·=·"/boot" 
410 size·=·1073741824 
411 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8407 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
412 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low408 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
413 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high409 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
414 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false410 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
415 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable411 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
416 part·/boot412 part·/boot
 413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 414 [[customizations.filesystem]]
 415 mountpoint·=·"/boot"
 416 size·=·1073741824
417 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*417 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/h\x8ho\x8om\x8me\x8e·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
418 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at418 If·user·home·directories·will·be·stored·locally,·create·a·separate·partition·for·/home·at
419 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such419 installation·time·(or·migrate·it·later·using·LVM).·If·/home·will·be·mounted·from·another·system·such
420 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the420 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
421 mountpoint·can·instead·be·configured·later.421 mountpoint·can·instead·be·configured·later.
422 ·············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more422 ·············Ensuring·that·/home·is·mounted·on·its·own·partition·enables·the·setting·of·more
423 Rationale:···restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill423 Rationale:···restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill
Offset 436, 105 lines modifiedOffset 436, 105 lines modified
436 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)436 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
437 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4437 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227438 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
439 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800439 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010800
440 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28440 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
441 ·············_\x8c_\x8i_\x8s············1.1.2.3.1441 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
442 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule442 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-230328r1017139_rule
443 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
444 [[customizations.filesystem]] 
445 mountpoint·=·"/home" 
446 size·=·1073741824 
447 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8443 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
Max diff block lines reached; 146278/151873 bytes (96.32%) of diff not shown.
504 KB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-anssi_bp28_minimal.html
    
Offset 14908, 296 lines modifiedOffset 14908, 296 lines modified
0003a3b0:·7461·7267·6574·3d22·2369·646d·3133·3432··target="#idm13420003a3b0:·7461·7267·6574·3d22·2369·646d·3133·3432··target="#idm1342
0003a3c0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·0003a3c0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
0003a3d0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003a3d0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003a3e0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003a3e0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003a3f0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003a3f0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003a400:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003a400:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003a410:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003a410:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0003a420:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...<
 0003a430:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003a440:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003a450:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003a460:·6964·6d31·3334·3231·223e·3c74·6162·6c65··idm13421"><table
0003a420:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003a430:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003a440:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003a450:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003a460:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003a470:·643d·2269·646d·3133·3432·3122·3e3c·7072··d="idm13421"><pr 
0003a480:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003a490:·6765·735d·5d0a·6e61·6d65·203d·2022·646e··ges]].name·=·"dn 
0003a4a0:·662d·6175·746f·6d61·7469·6322·0a76·6572··f-automatic".ver 
0003a4b0:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod 
0003a4c0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003a4d0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003a470:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003a480:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003a490:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003a4a0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003a4b0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003a4c0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003a4d0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003a4e0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003a4e0:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003a4f0:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003a500:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003a510:·6d31·3334·3232·2220·7461·6269·6e64·6578··m13422"·tabindex 
0003a520:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003a530:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003a540:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003a550:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003a560:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003a570:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003a580:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
0003a590:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003a5a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003a5b0:·6c61·7073·6522·2069·643d·2269·646d·3133··lapse"·id="idm13 
0003a5c0:·3432·3222·3e3c·7461·626c·6520·636c·6173··422"><table·clas 
0003a5d0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003a5e0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003a5f0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003a600:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003a610:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003a620:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003a4f0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003a630:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003a640:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003a500:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003a510:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003a650:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003a520:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003a660:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003a670:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003a680:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003a690:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003a6a0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003a6b0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003a6c0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003a6d0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003a6e0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003a6f0:·6d73·0a69·6620·2120·2820·7b20·7270·6d20··ms.if·!·(·{·rpm· 
0003a700:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003a710:·6c20·3b7d·2026·616d·703b·2661·6d70·3b20··l·;}·&amp;&amp;· 
0003a720:·7b20·7270·6d20·2d2d·7175·6965·7420·2d71··{·rpm·--quiet·-q 
0003a730:·2072·706d·2d6f·7374·7265·6520·3b7d·2026···rpm-ostree·;}·& 
0003a740:·616d·703b·2661·6d70·3b20·7b20·7270·6d20··amp;&amp;·{·rpm· 
0003a750:·2d2d·7175·6965·7420·2d71·2062·6f6f·7463··--quiet·-q·bootc 
0003a760:·203b·7d20·2661·6d70·3b26·616d·703b·207b···;}·&amp;&amp;·{ 
0003a770:·2021·2072·706d·202d·2d71·7569·6574·202d···!·rpm·--quiet·- 
0003a780:·7120·6f70·656e·7368·6966·742d·6b75·6265··q·openshift-kube 
0003a790:·6c65·7420·3b7d·2029·3b20·7468·656e·0a0a··let·;}·);·then.. 
0003a7a0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003a7b0:·6965·7420·2264·6e66·2d61·7574·6f6d·6174··iet·"dnf-automat 
0003a7c0:·6963·2220·3b20·7468·656e·0a20·2020·2079··ic"·;·then.····y 
0003a7d0:·756d·2069·6e73·7461·6c6c·202d·7920·2264··um·install·-y·"d 
0003a7e0:·6e66·2d61·7574·6f6d·6174·6963·220a·6669··nf-automatic".fi 
0003a7f0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003a800:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003a810:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003a820:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003a830:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003a840:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003a850:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003a860:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003a870:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003a880:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003a890:·3d22·2369·646d·3133·3432·3322·2074·6162··="#idm13423"·tab 
0003a8a0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003a8b0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003a8c0:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003a8d0:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003a8e0:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003a8f0:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003a900:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003a910:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003a920:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003a930:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003a940:·643d·2269·646d·3133·3432·3322·3e3c·7461··d="idm13423"><ta 
0003a950:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
0003a960:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
0003a970:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
0003a980:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
0003a990:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
0003a9a0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
0003a9b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003a9c0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
0003a9d0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003a9e0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
0003a9f0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
0003aa00:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003aa10:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003aa20:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003aa30:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003aa40:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat 
0003aa50:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package· 
0003aa60:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_ 
0003aa70:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag 
0003aa80:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags: 
0003aa90:·0a20·202d·2043·4345·2d38·3239·3835·2d33··.··-·CCE-82985-3 
0003aaa0:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0003aab0:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0003aac0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
Max diff block lines reached; 436030/475526 bytes (91.69%) of diff not shown.
39.3 KB
html2text {}
    
Offset 95, 19 lines modifiedOffset 95, 21 lines modified
95 ·············suitable·for·automatic,·regular·execution.95 ·············suitable·for·automatic,·regular·execution.
96 Severity: ···medium96 Severity: ···medium
97 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed97 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
98 Identifiers:·CCE-82985-398 Identifiers:·CCE-82985-3
99 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.299 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
100 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080100 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
101 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61101 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8102 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 103 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 104 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 105 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 106 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 107 package·install·dnf-automatic
103 [[packages]] 
104 name·=·"dnf-automatic" 
105 version·=·"*" 
106 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8108 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
107 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low109 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
108 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low110 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
109 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false111 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
110 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable112 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
111 #·Remediation·is·applicable·only·in·certain·platforms113 #·Remediation·is·applicable·only·in·certain·platforms
112 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc114 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc
Offset 149, 14 lines modifiedOffset 151, 26 lines modified
149 ··-·CCE-82985-3151 ··-·CCE-82985-3
150 ··-·enable_strategy152 ··-·enable_strategy
151 ··-·low_complexity153 ··-·low_complexity
152 ··-·low_disruption154 ··-·low_disruption
153 ··-·medium_severity155 ··-·medium_severity
154 ··-·no_reboot_needed156 ··-·no_reboot_needed
155 ··-·package_dnf-automatic_installed157 ··-·package_dnf-automatic_installed
 158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 163 package·--add=dnf-automatic
 164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 165 [[packages]]
 166 name·=·"dnf-automatic"
 167 version·=·"*"
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
161 dnf·install·dnf-automatic173 dnf·install·dnf-automatic
Offset 168, 28 lines modifiedOffset 182, 14 lines modified
168 include·install_dnf-automatic182 include·install_dnf-automatic
  
169 class·install_dnf-automatic·{183 class·install_dnf-automatic·{
170 ··package·{·'dnf-automatic':184 ··package·{·'dnf-automatic':
171 ····ensure·=>·'installed',185 ····ensure·=>·'installed',
172 ··}186 ··}
173 }187 }
174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
179 package·install·dnf-automatic 
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
185 package·--add=dnf-automatic 
186 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*188 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
187 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed189 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
188 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/190 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
189 automatic.conf.191 automatic.conf.
190 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation192 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
191 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and193 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
192 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in194 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10375, 14 lines modifiedOffset 10375, 21 lines modified
10375 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,10375 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
10376 ····························A.9.1.210376 ····························A.9.1.2
10377 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)10377 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
10378 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-310378 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
10379 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R6210379 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R62
10380 ·············_\x8c_\x8i_\x8s············2.2.310380 ·············_\x8c_\x8i_\x8s············2.2.3
10381 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.4,·2.210381 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.4,·2.2
 10382 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 10383 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10384 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10385 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10386 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10387 package·remove·dhcp-server
10382 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810388 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10383 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10389 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10384 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10390 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10385 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10391 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10386 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10392 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
10387 #·CAUTION:·This·remediation·script·will·remove·dhcp-server10393 #·CAUTION:·This·remediation·script·will·remove·dhcp-server
Offset 10412, 14 lines modifiedOffset 10419, 21 lines modified
10412 ··-·PCI-DSSv4-2.2.410419 ··-·PCI-DSSv4-2.2.4
10413 ··-·disable_strategy10420 ··-·disable_strategy
10414 ··-·low_complexity10421 ··-·low_complexity
10415 ··-·low_disruption10422 ··-·low_disruption
10416 ··-·medium_severity10423 ··-·medium_severity
10417 ··-·no_reboot_needed10424 ··-·no_reboot_needed
10418 ··-·package_dhcp_removed10425 ··-·package_dhcp_removed
 10426 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10427 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10428 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10429 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10430 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10431 package·--remove=dhcp-server
10419 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810432 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10420 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10433 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10421 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10434 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10422 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10435 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10423 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10436 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
10424 dnf·remove·dhcp-server10437 dnf·remove·dhcp-server
Offset 10431, 28 lines modifiedOffset 10445, 14 lines modified
10431 include·remove_dhcp-server10445 include·remove_dhcp-server
  
Max diff block lines reached; 35027/40192 bytes (87.15%) of diff not shown.
4.71 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis.html
    
Offset 15299, 285 lines modifiedOffset 15299, 285 lines modified
0003bc20:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003bc20:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003bc30:·2223·6964·6d37·3939·3022·2074·6162·696e··"#idm7990"·tabin0003bc30:·2223·6964·6d37·3939·3022·2074·6162·696e··"#idm7990"·tabin
0003bc40:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003bc40:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003bc50:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003bc50:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003bc60:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003bc60:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003bc70:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003bc70:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003bc80:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003bc80:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003bc90:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB 
0003bca0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003bcb0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003bcc0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003bcd0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003bce0:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
0003bcf0:·3930·223e·3c70·7265·3e3c·636f·6465·3e0a··90"><pre><code>. 
0003bd00:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003bd10:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003bd20:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003bd30:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bd40:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bd50:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bd60:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bd70:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003bd80:·3939·3122·2074·6162·696e·6465·783d·2230··991"·tabindex="0 
0003bd90:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003bda0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bdb0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bdc0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003bdd0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003bde0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003bdf0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
0003be00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003be10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003be20:·7365·2220·6964·3d22·6964·6d37·3939·3122··se"·id="idm7991" 
0003be30:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003be40:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003be50:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003be60:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003be70:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003be80:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003be90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003bea0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003beb0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003bec0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003bed0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003bee0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003bef0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003bf00:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003bf10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003bf20:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003bf30:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003bf40:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003bf50:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003bf60:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
0003bf70:·206b·6572·6e65·6c3b·2074·6865·6e0a·0a69···kernel;·then..i 
0003bf80:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
0003bf90:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
0003bfa0:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install 
0003bfb0:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
0003bfc0:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003bfd0:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003bfe0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003bff0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003c000:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003c010:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003c020:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003c030:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003c040:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003c050:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003c060:·6964·6d37·3939·3222·2074·6162·696e·6465··idm7992"·tabinde 
0003c070:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003c080:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003c090:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003c0a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003c0b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003c0c0:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib 
0003c0d0:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0003c0e0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003c0f0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003c100:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003c110:·646d·3739·3932·223e·3c74·6162·6c65·2063··dm7992"><table·c 
0003c120:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003c130:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003c140:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003c150:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003c160:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003c170:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003c180:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003c190:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003c1a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c1b0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003c1c0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003c1d0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003c1e0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003c1f0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003c200:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003c210:·2d20·6e61·6d65·3a20·4761·7468·6572·2074··-·name:·Gather·t 
0003c220:·6865·2070·6163·6b61·6765·2066·6163·7473··he·package·facts 
0003c230:·0a20·2070·6163·6b61·6765·5f66·6163·7473··.··package_facts 
0003c240:·3a0a·2020·2020·6d61·6e61·6765·723a·2061··:.····manager:·a 
0003c250:·7574·6f0a·2020·7461·6773·3a0a·2020·2d20··uto.··tags:.··-· 
0003c260:·4343·452d·3830·3834·342d·340a·2020·2d20··CCE-80844-4.··-· 
0003c270:·434a·4953·2d35·2e31·302e·312e·330a·2020··CJIS-5.10.1.3.·· 
0003c280:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL 
0003c290:·2d30·382d·3031·3033·3539·0a20·202d·204e··-08-010359.··-·N 
0003c2a0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003c2b0:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003c2c0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003c2d0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003c2e0:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003c2f0:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003c300:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003c310:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
0003c320:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n 
0003c330:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed. 
0003c340:·2020·2d20·7061·636b·6167·655f·6169·6465····-·package_aide 
0003c350:·5f69·6e73·7461·6c6c·6564·0a0a·2d20·6e61··_installed..-·na 
0003c360:·6d65·3a20·456e·7375·7265·2061·6964·6520··me:·Ensure·aide· 
0003c370:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p 
0003c380:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name 
0003c390:·3a20·6169·6465·0a20·2020·2073·7461·7465··:·aide.····state 
0003c3a0:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when 
0003c3b0:·3a20·2722·6b65·726e·656c·2220·696e·2061··:·'"kernel"·in·a 
0003c3c0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
0003c3d0:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.· 
0003c3e0:·202d·2043·4345·2d38·3038·3434·2d34·0a20···-·CCE-80844-4.· 
0003c3f0:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003c400:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R 
Max diff block lines reached; 4506216/4544194 bytes (99.16%) of diff not shown.
380 KB
html2text {}
    
Offset 123, 19 lines modifiedOffset 123, 21 lines modified
123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359125 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ·············_\x8c_\x8i_\x8s············5.3.1127 ·············_\x8c_\x8i_\x8s············5.3.1
128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule129 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 135 package·install·aide
131 [[packages]] 
132 name·=·"aide" 
133 version·=·"*" 
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
139 #·Remediation·is·applicable·only·in·certain·platforms141 #·Remediation·is·applicable·only·in·certain·platforms
140 if·rpm·--quiet·-q·kernel;·then142 if·rpm·--quiet·-q·kernel;·then
Offset 183, 14 lines modifiedOffset 185, 26 lines modified
183 ··-·PCI-DSSv4-11.5.2185 ··-·PCI-DSSv4-11.5.2
184 ··-·enable_strategy186 ··-·enable_strategy
185 ··-·low_complexity187 ··-·low_complexity
186 ··-·low_disruption188 ··-·low_disruption
187 ··-·medium_severity189 ··-·medium_severity
188 ··-·no_reboot_needed190 ··-·no_reboot_needed
189 ··-·package_aide_installed191 ··-·package_aide_installed
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 197 package·--add=aide
 198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 199 [[packages]]
 200 name·=·"aide"
 201 version·=·"*"
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
195 dnf·install·aide207 dnf·install·aide
Offset 202, 28 lines modifiedOffset 216, 14 lines modified
202 include·install_aide216 include·install_aide
  
203 class·install_aide·{217 class·install_aide·{
204 ··package·{·'aide':218 ··package·{·'aide':
205 ····ensure·=>·'installed',219 ····ensure·=>·'installed',
206 ··}220 ··}
207 }221 }
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
213 package·install·aide 
214 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
215 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
216 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
217 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
218 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
219 package·--add=aide 
220 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*222 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
221 Run·the·following·command·to·generate·a·new·database:223 Run·the·following·command·to·generate·a·new·database:
222 $·sudo·/usr/sbin/aide·--init224 $·sudo·/usr/sbin/aide·--init
223 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:225 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
224 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz226 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
225 To·initiate·a·manual·check,·run·the·following·command:227 To·initiate·a·manual·check,·run·the·following·command:
226 $·sudo·/usr/sbin/aide·--check228 $·sudo·/usr/sbin/aide·--check
Offset 779, 14 lines modifiedOffset 779, 39 lines modified
779 »       echo·"to·see·what·package·to·(re)install"·>&2779 »       echo·"to·see·what·package·to·(re)install"·>&2
  
780 »       false··#·end·with·an·error·code780 »       false··#·end·with·an·error·code
781 elif·test·"$rc"·!=·0;·then781 elif·test·"$rc"·!=·0;·then
782 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2782 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
783 »       false··#·end·with·an·error·code783 »       false··#·end·with·an·error·code
784 fi784 fi
 785 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 786 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 787 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 788 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 789 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 790 ---
 791 apiVersion:·machineconfiguration.openshift.io/v1
 792 kind:·MachineConfig
 793 spec:
 794 ··config:
 795 ····ignition:
 796 ······version:·3.1.0
 797 ····systemd:
 798 ······units:
 799 ········-·name:·configure-crypto-policy.service
 800 ··········enabled:·true
 801 ··········contents:·|
 802 ············[Unit]
 803 ············Before=kubelet.service
 804 ············[Service]
 805 ············Type=oneshot
 806 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 807 ············RemainAfterExit=yes
 808 ············[Install]
 809 ············WantedBy=multi-user.target
785 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8810 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
786 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low811 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
787 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low812 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
788 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false813 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
789 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict814 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
790 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable815 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
791 ··set_fact:816 ··set_fact:
Offset 835, 39 lines modifiedOffset 860, 14 lines modified
835 ··-·PCI-DSSv4-2.2.7860 ··-·PCI-DSSv4-2.2.7
836 ··-·configure_crypto_policy861 ··-·configure_crypto_policy
837 ··-·high_severity862 ··-·high_severity
838 ··-·low_complexity863 ··-·low_complexity
839 ··-·low_disruption864 ··-·low_disruption
840 ··-·no_reboot_needed865 ··-·no_reboot_needed
Max diff block lines reached; 384478/389333 bytes (98.75%) of diff not shown.
2.7 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_server_l1.html
    
Offset 15261, 285 lines modifiedOffset 15261, 285 lines modified
0003b9c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b9c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b9d0:·3739·3930·2220·7461·6269·6e64·6578·3d22··7990"·tabindex="0003b9d0:·3739·3930·2220·7461·6269·6e64·6578·3d22··7990"·tabindex="
0003b9e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b9e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b9f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b9f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003ba00:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003ba00:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003ba10:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003ba10:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003ba20:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003ba20:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003ba30:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·0003ba30:·6469·6174·696f·6e20·7363·7269·7074·20e2··diation·script·.
0003ba40:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0003ba50:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003ba60:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003ba70:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003ba80:·2220·6964·3d22·6964·6d37·3939·3022·3e3c··"·id="idm7990">< 
0003ba90:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
0003baa0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
0003bab0:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=· 
0003bac0:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre 
0003bad0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class= 
0003bae0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success 
0003baf0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c 
0003bb00:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta 
0003bb10:·7267·6574·3d22·2369·646d·3739·3931·2220··rget="#idm7991"· 
0003bb20:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol 
0003bb30:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria- 
0003bb40:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false" 
0003bb50:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate 
0003bb60:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href 
0003bb70:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio 
0003bb80:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·. 
0003bb90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0003ba40:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003bba0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0003ba50:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003bbb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0003ba60:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003bbc0:·643d·2269·646d·3739·3931·223e·3c74·6162··d="idm7991"><tab0003ba70:·643d·2269·646d·3739·3930·223e·3c74·6162··d="idm7990"><tab
0003bbd0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·0003ba80:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
0003bbe0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta0003ba90:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
0003bbf0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab0003baa0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
0003bc00:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t0003bab0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
0003bc10:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003bac0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
0003bc20:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003bad0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
0003bc30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D0003bae0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
0003bc40:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><0003baf0:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
0003bc50:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003bb00:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
0003bc60:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<0003bb10:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
0003bc70:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t0003bb20:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
0003bc80:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003bb30:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
0003bc90:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003bb40:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
0003bca0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr0003bb50:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
0003bcb0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c0003bb60:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003bb70:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins
 0003bb80:·7461·6c6c·2061·6964·650a·3c2f·636f·6465··tall·aide.</code
0003bcc0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
0003bcd0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
0003bce0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
0003bcf0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm 
0003bd00:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern 
0003bd10:·656c·3b20·7468·656e·0a0a·6966·2021·2072··el;·then..if·!·r 
0003bd20:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a 
0003bd30:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.···· 
0003bd40:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·" 
0003bd50:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.· 
0003bd60:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec 
0003bd70:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation· 
0003bd80:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl 
0003bd90:·652c·206e·6f74·6869·6e67·2077·6173·2064··e,·nothing·was·d 
0003bda0:·6f6e·6527·0a66·690a·3c2f·636f·6465·3e3c··one'.fi.</code>< 
0003bdb0:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003bb90:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
0003bdc0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003bba0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
0003bdd0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003bbb0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
0003bde0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003bbc0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
0003bdf0:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm790003bbd0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003be00:·3932·2220·7461·6269·6e64·6578·3d22·3022··92"·tabindex="0"0003bbe0:·3739·3931·2220·7461·6269·6e64·6578·3d22··7991"·tabindex="
0003be10:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003bbf0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003be20:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003bc00:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003be30:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003bc10:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003be40:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003bc20:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003be50:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003bc30:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 0003bc40:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
 0003bc50:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003bc60:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003bc70:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003bc80:·7073·6522·2069·643d·2269·646d·3739·3931··pse"·id="idm7991
 0003bc90:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003bca0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003be60:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
0003be70:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003be80:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003be90:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003bea0:·6170·7365·2220·6964·3d22·6964·6d37·3939··apse"·id="idm799 
0003beb0:·3222·3e3c·7461·626c·6520·636c·6173·733d··2"><table·class= 
0003bec0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
0003bed0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
0003bee0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden0003bcb0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003bef0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
0003bf00:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
0003bf10:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
0003bf20:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
0003bf30:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003bf40:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
0003bf50:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f0003bcc0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003bcd0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003bce0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003bcf0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003bd00:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003bd10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003bd20:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003bd30:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003bd40:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003bd50:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003bd60:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003bd70:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003bd80:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
 0003bd90:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 0003bda0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 0003bdb0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 0003bdc0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 0003bdd0:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then..
 0003bde0:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu
 0003bdf0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the
 0003be00:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal
 0003be10:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi..
 0003be20:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 0003be30:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 0003be40:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 0003be50:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 0003be60:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 0003be70:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003be80:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
Max diff block lines reached; 2538742/2576720 bytes (98.53%) of diff not shown.
247 KB
html2text {}
    
Offset 117, 19 lines modifiedOffset 117, 21 lines modified
117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359119 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
120 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79120 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
121 ·············_\x8c_\x8i_\x8s············5.3.1121 ·············_\x8c_\x8i_\x8s············5.3.1
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
123 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule123 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 129 package·install·aide
125 [[packages]] 
126 name·=·"aide" 
127 version·=·"*" 
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
133 #·Remediation·is·applicable·only·in·certain·platforms135 #·Remediation·is·applicable·only·in·certain·platforms
134 if·rpm·--quiet·-q·kernel;·then136 if·rpm·--quiet·-q·kernel;·then
Offset 177, 14 lines modifiedOffset 179, 26 lines modified
177 ··-·PCI-DSSv4-11.5.2179 ··-·PCI-DSSv4-11.5.2
178 ··-·enable_strategy180 ··-·enable_strategy
179 ··-·low_complexity181 ··-·low_complexity
180 ··-·low_disruption182 ··-·low_disruption
181 ··-·medium_severity183 ··-·medium_severity
182 ··-·no_reboot_needed184 ··-·no_reboot_needed
183 ··-·package_aide_installed185 ··-·package_aide_installed
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 191 package·--add=aide
 192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 193 [[packages]]
 194 name·=·"aide"
 195 version·=·"*"
184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
189 dnf·install·aide201 dnf·install·aide
Offset 196, 28 lines modifiedOffset 210, 14 lines modified
196 include·install_aide210 include·install_aide
  
197 class·install_aide·{211 class·install_aide·{
198 ··package·{·'aide':212 ··package·{·'aide':
199 ····ensure·=>·'installed',213 ····ensure·=>·'installed',
200 ··}214 ··}
201 }215 }
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
207 package·install·aide 
208 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
209 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
210 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
211 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
212 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
213 package·--add=aide 
214 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
215 Run·the·following·command·to·generate·a·new·database:217 Run·the·following·command·to·generate·a·new·database:
216 $·sudo·/usr/sbin/aide·--init218 $·sudo·/usr/sbin/aide·--init
217 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
218 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz220 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
219 To·initiate·a·manual·check,·run·the·following·command:221 To·initiate·a·manual·check,·run·the·following·command:
220 $·sudo·/usr/sbin/aide·--check222 $·sudo·/usr/sbin/aide·--check
Offset 773, 14 lines modifiedOffset 773, 39 lines modified
773 »       echo·"to·see·what·package·to·(re)install"·>&2773 »       echo·"to·see·what·package·to·(re)install"·>&2
  
774 »       false··#·end·with·an·error·code774 »       false··#·end·with·an·error·code
775 elif·test·"$rc"·!=·0;·then775 elif·test·"$rc"·!=·0;·then
776 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2776 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
777 »       false··#·end·with·an·error·code777 »       false··#·end·with·an·error·code
778 fi778 fi
 779 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 780 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 781 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 782 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 783 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 784 ---
 785 apiVersion:·machineconfiguration.openshift.io/v1
 786 kind:·MachineConfig
 787 spec:
 788 ··config:
 789 ····ignition:
 790 ······version:·3.1.0
 791 ····systemd:
 792 ······units:
 793 ········-·name:·configure-crypto-policy.service
 794 ··········enabled:·true
 795 ··········contents:·|
 796 ············[Unit]
 797 ············Before=kubelet.service
 798 ············[Service]
 799 ············Type=oneshot
 800 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 801 ············RemainAfterExit=yes
 802 ············[Install]
 803 ············WantedBy=multi-user.target
779 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
780 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low805 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
781 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low806 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
782 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false807 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
783 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict808 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
784 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable809 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
785 ··set_fact:810 ··set_fact:
Offset 829, 39 lines modifiedOffset 854, 14 lines modified
829 ··-·PCI-DSSv4-2.2.7854 ··-·PCI-DSSv4-2.2.7
830 ··-·configure_crypto_policy855 ··-·configure_crypto_policy
831 ··-·high_severity856 ··-·high_severity
832 ··-·low_complexity857 ··-·low_complexity
833 ··-·low_disruption858 ··-·low_disruption
834 ··-·no_reboot_needed859 ··-·no_reboot_needed
Max diff block lines reached; 247892/252747 bytes (98.08%) of diff not shown.
2.41 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_workstation_l1.html
    
Offset 15252, 285 lines modifiedOffset 15252, 285 lines modified
0003b930:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b930:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b940:·3d22·2369·646d·3739·3930·2220·7461·6269··="#idm7990"·tabi0003b940:·3d22·2369·646d·3739·3930·2220·7461·6269··="#idm7990"·tabi
0003b950:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b950:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b960:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b960:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b970:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b970:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b980:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b980:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b990:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b990:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b9a0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003b9a0:·223e·5265·6d65·6469·6174·696f·6e20·7363··">Remediation·sc
0003b9b0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003b9c0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b9d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b9e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b9f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d37··llapse"·id="idm7 
0003ba00:·3939·3022·3e3c·7072·653e·3c63·6f64·653e··990"><pre><code> 
0003ba10:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003ba20:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003ba30:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003ba40:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003ba50:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003ba60:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003ba70:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003ba80:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003ba90:·3739·3931·2220·7461·6269·6e64·6578·3d22··7991"·tabindex=" 
0003baa0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003bab0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003bac0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003bad0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003bae0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003baf0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003bb00:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0003b9b0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
0003bb10:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003b9c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
0003bb20:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003b9d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
0003bb30:·7073·6522·2069·643d·2269·646d·3739·3931··pse"·id="idm79910003b9e0:·7073·6522·2069·643d·2269·646d·3739·3930··pse"·id="idm7990
0003bb40:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="0003b9f0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
0003bb50:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri0003ba00:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
0003bb60:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border0003ba10:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
0003bb70:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens0003ba20:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
0003bb80:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp0003ba30:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
0003bb90:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>0003ba40:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
0003bba0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003ba50:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
0003bbb0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:0003ba60:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
0003bbc0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003ba70:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
0003bbd0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re0003ba80:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
0003bbe0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa0003ba90:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
0003bbf0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003baa0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
0003bc00:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</0003bab0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
0003bc10:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t0003bac0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
0003bc20:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><0003bad0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003bc30:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme0003bae0:·7072·653e·3c63·6f64·653e·0a70·6163·6b61··pre><code>.packa
 0003baf0:·6765·2069·6e73·7461·6c6c·2061·6964·650a··ge·install·aide.
0003bc40:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003bc50:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003bc60:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003bc70:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003bc80:·7120·6b65·726e·656c·3b20·7468·656e·0a0a··q·kernel;·then.. 
0003bc90:·6966·2021·2072·706d·202d·7120·2d2d·7175··if·!·rpm·-q·--qu 
0003bca0:·6965·7420·2261·6964·6522·203b·2074·6865··iet·"aide"·;·the 
0003bcb0:·6e0a·2020·2020·7975·6d20·696e·7374·616c··n.····yum·instal 
0003bcc0:·6c20·2d79·2022·6169·6465·220a·6669·0a0a··l·-y·"aide".fi.. 
0003bcd0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am 
0003bce0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi 
0003bcf0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app 
0003bd00:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing 
0003bd10:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</ 
0003bd20:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div0003bb00:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003bd30:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b0003bb10:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003bd40:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data0003bb20:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003bd50:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps0003bb30:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003bd60:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003bb40:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003bd70:·2369·646d·3739·3932·2220·7461·6269·6e64··#idm7992"·tabind0003bb50:·3d22·2369·646d·3739·3931·2220·7461·6269··="#idm7991"·tabi
0003bd80:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003bb60:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003bd90:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003bb70:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003bda0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003bb80:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003bdb0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003bb90:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003bdc0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003bba0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003bdd0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi0003bbb0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003bbc0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003bbd0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003bbe0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003bbf0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003bc00:·646d·3739·3931·223e·3c74·6162·6c65·2063··dm7991"><table·c
 0003bc10:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
0003bde0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...< 
0003bdf0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
0003be00:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
0003be10:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
0003be20:·6964·6d37·3939·3222·3e3c·7461·626c·6520··idm7992"><table· 
0003be30:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab 
0003be40:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table 
0003be50:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003bc20:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
0003be60:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr>< 
0003be70:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</ 
0003be80:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003be90:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003bea0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>0003bc30:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003bc40:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003bc50:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003bc60:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003bc70:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003bc80:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003bc90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003bca0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003bcb0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003bcc0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003bcd0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003beb0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr0003bce0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
0003bec0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th0003bcf0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
 0003bd00:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003bd10:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003bd20:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003bd30:·666f·726d·730a·6966·2072·706d·202d·2d71··forms.if·rpm·--q
 0003bd40:·7569·6574·202d·7120·6b65·726e·656c·3b20··uiet·-q·kernel;·
 0003bd50:·7468·656e·0a0a·6966·2021·2072·706d·202d··then..if·!·rpm·-
 0003bd60:·7120·2d2d·7175·6965·7420·2261·6964·6522··q·--quiet·"aide"
 0003bd70:·203b·2074·6865·6e0a·2020·2020·7975·6d20···;·then.····yum·
 0003bd80:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003bd90:·220a·6669·0a0a·656c·7365·0a20·2020·2026··".fi..else.····&
 0003bda0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 0003bdb0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 0003bdc0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 0003bdd0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 0003bde0:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
 0003bdf0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003be00:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003be10:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003be20:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003be30:·7267·6574·3d22·2369·646d·3739·3932·2220··rget="#idm7992"·
Max diff block lines reached; 2259694/2297672 bytes (98.35%) of diff not shown.
223 KB
html2text {}
    
Offset 116, 19 lines modifiedOffset 116, 21 lines modified
116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
117 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199117 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
118 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359118 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
119 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79119 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
120 ·············_\x8c_\x8i_\x8s············5.3.1120 ·············_\x8c_\x8i_\x8s············5.3.1
121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule122 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 128 package·install·aide
124 [[packages]] 
125 name·=·"aide" 
126 version·=·"*" 
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
132 #·Remediation·is·applicable·only·in·certain·platforms134 #·Remediation·is·applicable·only·in·certain·platforms
133 if·rpm·--quiet·-q·kernel;·then135 if·rpm·--quiet·-q·kernel;·then
Offset 176, 14 lines modifiedOffset 178, 26 lines modified
176 ··-·PCI-DSSv4-11.5.2178 ··-·PCI-DSSv4-11.5.2
177 ··-·enable_strategy179 ··-·enable_strategy
178 ··-·low_complexity180 ··-·low_complexity
179 ··-·low_disruption181 ··-·low_disruption
180 ··-·medium_severity182 ··-·medium_severity
181 ··-·no_reboot_needed183 ··-·no_reboot_needed
182 ··-·package_aide_installed184 ··-·package_aide_installed
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 190 package·--add=aide
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 192 [[packages]]
 193 name·=·"aide"
 194 version·=·"*"
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
188 dnf·install·aide200 dnf·install·aide
Offset 195, 28 lines modifiedOffset 209, 14 lines modified
195 include·install_aide209 include·install_aide
  
196 class·install_aide·{210 class·install_aide·{
197 ··package·{·'aide':211 ··package·{·'aide':
198 ····ensure·=>·'installed',212 ····ensure·=>·'installed',
199 ··}213 ··}
200 }214 }
201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
206 package·install·aide 
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
212 package·--add=aide 
213 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
214 Run·the·following·command·to·generate·a·new·database:216 Run·the·following·command·to·generate·a·new·database:
215 $·sudo·/usr/sbin/aide·--init217 $·sudo·/usr/sbin/aide·--init
216 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:218 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
217 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz219 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
218 To·initiate·a·manual·check,·run·the·following·command:220 To·initiate·a·manual·check,·run·the·following·command:
219 $·sudo·/usr/sbin/aide·--check221 $·sudo·/usr/sbin/aide·--check
Offset 772, 14 lines modifiedOffset 772, 39 lines modified
772 »       echo·"to·see·what·package·to·(re)install"·>&2772 »       echo·"to·see·what·package·to·(re)install"·>&2
  
773 »       false··#·end·with·an·error·code773 »       false··#·end·with·an·error·code
774 elif·test·"$rc"·!=·0;·then774 elif·test·"$rc"·!=·0;·then
775 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2775 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
776 »       false··#·end·with·an·error·code776 »       false··#·end·with·an·error·code
777 fi777 fi
 778 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 779 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 780 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 781 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 782 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 783 ---
 784 apiVersion:·machineconfiguration.openshift.io/v1
 785 kind:·MachineConfig
 786 spec:
 787 ··config:
 788 ····ignition:
 789 ······version:·3.1.0
 790 ····systemd:
 791 ······units:
 792 ········-·name:·configure-crypto-policy.service
 793 ··········enabled:·true
 794 ··········contents:·|
 795 ············[Unit]
 796 ············Before=kubelet.service
 797 ············[Service]
 798 ············Type=oneshot
 799 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 800 ············RemainAfterExit=yes
 801 ············[Install]
 802 ············WantedBy=multi-user.target
778 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8803 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
779 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low804 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
780 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low805 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
781 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false806 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
782 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict807 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
783 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable808 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
784 ··set_fact:809 ··set_fact:
Offset 828, 39 lines modifiedOffset 853, 14 lines modified
828 ··-·PCI-DSSv4-2.2.7853 ··-·PCI-DSSv4-2.2.7
829 ··-·configure_crypto_policy854 ··-·configure_crypto_policy
830 ··-·high_severity855 ··-·high_severity
831 ··-·low_complexity856 ··-·low_complexity
832 ··-·low_disruption857 ··-·low_disruption
833 ··-·no_reboot_needed858 ··-·no_reboot_needed
Max diff block lines reached; 223646/228501 bytes (97.88%) of diff not shown.
4.54 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cis_workstation_l2.html
    
Offset 15291, 284 lines modifiedOffset 15291, 284 lines modified
0003bba0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm70003bba0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7
0003bbb0:·3939·3022·2074·6162·696e·6465·783d·2230··990"·tabindex="00003bbb0:·3939·3022·2074·6162·696e·6465·783d·2230··990"·tabindex="0
0003bbc0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003bbc0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003bbd0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003bbd0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003bbe0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003bbe0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003bbf0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003bbf0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003bc00:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003bc00:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 0003bc10:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
0003bc10:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B 
0003bc20:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
0003bc30:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003bc40:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003bc50:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003bc60:·2069·643d·2269·646d·3739·3930·223e·3c70···id="idm7990"><p 
0003bc70:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
0003bc80:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a 
0003bc90:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·" 
0003bca0:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
0003bcb0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003bcc0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003bcd0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003bce0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003bcf0:·6765·743d·2223·6964·6d37·3939·3122·2074··get="#idm7991"·t 
0003bd00:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003bd10:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003bd20:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003bd30:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003bd40:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003bd50:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003bd60:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
0003bd70:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl0003bc20:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
0003bd80:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla0003bc30:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
0003bd90:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id0003bc40:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
0003bda0:·3d22·6964·6d37·3939·3122·3e3c·7461·626c··="idm7991"><tabl0003bc50:·3d22·6964·6d37·3939·3022·3e3c·7461·626c··="idm7990"><tabl
0003bdb0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t0003bc60:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
0003bdc0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab0003bc70:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
0003bdd0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl0003bc80:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
0003bde0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr0003bc90:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
0003bdf0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003be00:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003be10:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003be20:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003be30:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003be40:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003be50:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003be60:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003be70:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003be80:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003be90:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003bea0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
0003beb0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
0003bec0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
0003bed0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm· 
0003bee0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003bef0:·6c3b·2074·6865·6e0a·0a69·6620·2120·7270··l;·then..if·!·rp 
0003bf00:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
0003bf10:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y 
0003bf20:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a 
0003bf30:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
0003bf40:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
0003bf50:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
0003bf60:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
0003bf70:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
0003bf80:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
0003bf90:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003bfa0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003bfb0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003bfc0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003bfd0:·2d74·6172·6765·743d·2223·6964·6d37·3939··-target="#idm799 
0003bfe0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"· 
0003bff0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003c000:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003c010:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003c020:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003c030:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003c040:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
0003c050:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003c060:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003c070:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003c080:·7073·6522·2069·643d·2269·646d·3739·3932··pse"·id="idm7992 
0003c090:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003c0a0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003c0b0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003c0c0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003c0d0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003c0e0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003c0f0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003c100:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003c110:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003c120:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003c130:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003c140:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr 
0003c150:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003c160:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003c170:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003c180:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name 
0003c190:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac 
0003c1a0:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac 
0003c1b0:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.···· 
0003c1c0:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.·· 
0003c1d0:·7461·6773·3a0a·2020·2d20·4343·452d·3830··tags:.··-·CCE-80 
0003c1e0:·3834·342d·340a·2020·2d20·434a·4953·2d35··844-4.··-·CJIS-5 
0003c1f0:·2e31·302e·312e·330a·2020·2d20·4449·5341··.10.1.3.··-·DISA 
0003c200:·2d53·5449·472d·5248·454c·2d30·382d·3031··-STIG-RHEL-08-01 
0003c210:·3033·3539·0a20·202d·204e·4953·542d·3830··0359.··-·NIST-80 
0003c220:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··- 
0003c230:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11. 
0003c240:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4- 
0003c250:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl 
0003c260:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l 
0003c270:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.·· 
0003c280:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption 
0003c290:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve 
0003c2a0:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo 
0003c2b0:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa 
0003c2c0:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta 
0003c2d0:·6c6c·6564·0a0a·2d20·6e61·6d65·3a20·456e··lled..-·name:·En 
0003c2e0:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins 
0003c2f0:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package 
0003c300:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide 
0003c310:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres 
0003c320:·656e·740a·2020·7768·656e·3a20·2722·6b65··ent.··when:·'"ke 
0003c330:·726e·656c·2220·696e·2061·6e73·6962·6c65··rnel"·in·ansible 
0003c340:·5f66·6163·7473·2e70·6163·6b61·6765·7327··_facts.packages' 
0003c350:·0a20·2074·6167·733a·0a20·202d·2043·4345··.··tags:.··-·CCE 
0003c360:·2d38·3038·3434·2d34·0a20·202d·2043·4a49··-80844-4.··-·CJI 
0003c370:·532d·352e·3130·2e31·2e33·0a20·202d·2044··S-5.10.1.3.··-·D 
Max diff block lines reached; 4342913/4380753 bytes (99.14%) of diff not shown.
366 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 21 lines modified
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
125 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79125 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
126 ·············_\x8c_\x8i_\x8s············5.3.1126 ·············_\x8c_\x8i_\x8s············5.3.1
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 134 package·install·aide
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms140 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel;·then141 if·rpm·--quiet·-q·kernel;·then
Offset 182, 14 lines modifiedOffset 184, 26 lines modified
182 ··-·PCI-DSSv4-11.5.2184 ··-·PCI-DSSv4-11.5.2
183 ··-·enable_strategy185 ··-·enable_strategy
184 ··-·low_complexity186 ··-·low_complexity
185 ··-·low_disruption187 ··-·low_disruption
186 ··-·medium_severity188 ··-·medium_severity
187 ··-·no_reboot_needed189 ··-·no_reboot_needed
188 ··-·package_aide_installed190 ··-·package_aide_installed
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 196 package·--add=aide
 197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 198 [[packages]]
 199 name·=·"aide"
 200 version·=·"*"
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
194 dnf·install·aide206 dnf·install·aide
Offset 201, 28 lines modifiedOffset 215, 14 lines modified
201 include·install_aide215 include·install_aide
  
202 class·install_aide·{216 class·install_aide·{
203 ··package·{·'aide':217 ··package·{·'aide':
204 ····ensure·=>·'installed',218 ····ensure·=>·'installed',
205 ··}219 ··}
206 }220 }
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
212 package·install·aide 
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
218 package·--add=aide 
219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*221 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
220 Run·the·following·command·to·generate·a·new·database:222 Run·the·following·command·to·generate·a·new·database:
221 $·sudo·/usr/sbin/aide·--init223 $·sudo·/usr/sbin/aide·--init
222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:224 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz225 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
224 To·initiate·a·manual·check,·run·the·following·command:226 To·initiate·a·manual·check,·run·the·following·command:
225 $·sudo·/usr/sbin/aide·--check227 $·sudo·/usr/sbin/aide·--check
Offset 778, 14 lines modifiedOffset 778, 39 lines modified
778 »       echo·"to·see·what·package·to·(re)install"·>&2778 »       echo·"to·see·what·package·to·(re)install"·>&2
  
779 »       false··#·end·with·an·error·code779 »       false··#·end·with·an·error·code
780 elif·test·"$rc"·!=·0;·then780 elif·test·"$rc"·!=·0;·then
781 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2781 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
782 »       false··#·end·with·an·error·code782 »       false··#·end·with·an·error·code
783 fi783 fi
 784 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 785 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 786 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 787 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 788 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 789 ---
 790 apiVersion:·machineconfiguration.openshift.io/v1
 791 kind:·MachineConfig
 792 spec:
 793 ··config:
 794 ····ignition:
 795 ······version:·3.1.0
 796 ····systemd:
 797 ······units:
 798 ········-·name:·configure-crypto-policy.service
 799 ··········enabled:·true
 800 ··········contents:·|
 801 ············[Unit]
 802 ············Before=kubelet.service
 803 ············[Service]
 804 ············Type=oneshot
 805 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 806 ············RemainAfterExit=yes
 807 ············[Install]
 808 ············WantedBy=multi-user.target
784 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8809 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
785 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low810 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
786 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low811 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
787 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false812 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
788 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict813 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
789 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable814 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
790 ··set_fact:815 ··set_fact:
Offset 834, 39 lines modifiedOffset 859, 14 lines modified
834 ··-·PCI-DSSv4-2.2.7859 ··-·PCI-DSSv4-2.2.7
835 ··-·configure_crypto_policy860 ··-·configure_crypto_policy
836 ··-·high_severity861 ··-·high_severity
837 ··-·low_complexity862 ··-·low_complexity
838 ··-·low_disruption863 ··-·low_disruption
839 ··-·no_reboot_needed864 ··-·no_reboot_needed
Max diff block lines reached; 369850/374705 bytes (98.70%) of diff not shown.
4.21 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-cui.html
    
Offset 15283, 285 lines modifiedOffset 15283, 285 lines modified
0003bb20:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003bb20:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003bb30:·6d37·3939·3022·2074·6162·696e·6465·783d··m7990"·tabindex=0003bb30:·6d37·3939·3022·2074·6162·696e·6465·783d··m7990"·tabindex=
0003bb40:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003bb40:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003bb50:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003bb50:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003bb60:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003bb60:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003bb70:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003bb70:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003bb80:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003bb80:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003bb90:·6564·6961·7469·6f6e·2073·6372·6970·7420··ediation·script·
0003bb90:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild 
0003bba0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003bbb0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003bbc0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003bbd0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003bbe0:·6522·2069·643d·2269·646d·3739·3930·223e··e"·id="idm7990"> 
0003bbf0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003bc00:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003bc10:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·= 
0003bc20:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003bc30:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003bc40:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003bc50:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003bc60:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003bc70:·6172·6765·743d·2223·6964·6d37·3939·3122··arget="#idm7991" 
0003bc80:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003bc90:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003bca0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003bcb0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003bcc0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003bcd0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003bce0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script· 
0003bcf0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·0003bba0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
0003bd00:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col0003bbb0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
0003bd10:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·0003bbc0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
0003bd20:·6964·3d22·6964·6d37·3939·3122·3e3c·7461··id="idm7991"><ta0003bbd0:·6964·3d22·6964·6d37·3939·3022·3e3c·7461··id="idm7990"><ta
0003bd30:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table0003bbe0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
0003bd40:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t0003bbf0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
0003bd50:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta0003bc00:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
0003bd60:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><0003bc10:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
0003bd70:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit0003bc20:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
0003bd80:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</0003bc30:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
0003bd90:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003bc40:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003bda0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>0003bc50:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
0003bdb0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr0003bc60:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
0003bdc0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:0003bc70:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
0003bdd0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</0003bc80:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
0003bde0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003bdf0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
0003be00:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
0003be10:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
0003be20:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati 
0003be30:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable 
0003be40:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain 
0003be50:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp 
0003be60:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker 
0003be70:·6e65·6c3b·2074·6865·6e0a·0a69·6620·2120··nel;·then..if·!· 
0003be80:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·" 
0003be90:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.··· 
0003bea0:·2079·756d·2069·6e73·7461·6c6c·202d·7920···yum·install·-y· 
0003beb0:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else. 
0003bec0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e 
0003bed0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation 
0003bee0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab 
0003bef0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was· 
0003bf00:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code> 
0003bf10:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003bf20:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003bf30:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bf40:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bf50:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003bf60:·3939·3222·2074·6162·696e·6465·783d·2230··992"·tabindex="0 
0003bf70:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003bf80:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bf90:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bfa0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003bfb0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003bfc0:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s 
0003bfd0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003bfe0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003bff0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003c000:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
0003c010:·3932·223e·3c74·6162·6c65·2063·6c61·7373··92"><table·class 
0003c020:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
0003c030:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
0003c040:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
0003c050:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
0003c060:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
0003c070:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003c080:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
0003c090:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
0003c0a0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
0003c0b0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
0003c0c0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr>< 
0003c0d0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003c0e0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003c0f0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003c100:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na 
0003c110:·6d65·3a20·4761·7468·6572·2074·6865·2070··me:·Gather·the·p 
0003c120:·6163·6b61·6765·2066·6163·7473·0a20·2070··ackage·facts.··p 
0003c130:·6163·6b61·6765·5f66·6163·7473·3a0a·2020··ackage_facts:.·· 
0003c140:·2020·6d61·6e61·6765·723a·2061·7574·6f0a····manager:·auto. 
0003c150:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE- 
0003c160:·3830·3834·342d·340a·2020·2d20·434a·4953··80844-4.··-·CJIS 
0003c170:·2d35·2e31·302e·312e·330a·2020·2d20·4449··-5.10.1.3.··-·DI 
0003c180:·5341·2d53·5449·472d·5248·454c·2d30·382d··SA-STIG-RHEL-08- 
0003c190:·3031·3033·3539·0a20·202d·204e·4953·542d··010359.··-·NIST- 
0003c1a0:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).· 
0003c1b0:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1 
0003c1c0:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv 
0003c1d0:·342d·3131·2e35·2e32·0a20·202d·2065·6e61··4-11.5.2.··-·ena 
0003c1e0:·626c·655f·7374·7261·7465·6779·0a20·202d··ble_strategy.··- 
0003c1f0:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity. 
0003c200:·2020·2d20·6c6f·775f·6469·7372·7570·7469····-·low_disrupti 
0003c210:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se 
0003c220:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re 
0003c230:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-· 
0003c240:·7061·636b·6167·655f·6169·6465·5f69·6e73··package_aide_ins 
0003c250:·7461·6c6c·6564·0a0a·2d20·6e61·6d65·3a20··talled..-·name:· 
0003c260:·456e·7375·7265·2061·6964·6520·6973·2069··Ensure·aide·is·i 
0003c270:·6e73·7461·6c6c·6564·0a20·2070·6163·6b61··nstalled.··packa 
0003c280:·6765·3a0a·2020·2020·6e61·6d65·3a20·6169··ge:.····name:·ai 
0003c290:·6465·0a20·2020·2073·7461·7465·3a20·7072··de.····state:·pr 
0003c2a0:·6573·656e·740a·2020·7768·656e·3a20·2722··esent.··when:·'" 
0003c2b0:·6b65·726e·656c·2220·696e·2061·6e73·6962··kernel"·in·ansib 
0003c2c0:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package 
0003c2d0:·7327·0a20·2074·6167·733a·0a20·202d·2043··s'.··tags:.··-·C 
0003c2e0:·4345·2d38·3038·3434·2d34·0a20·202d·2043··CE-80844-4.··-·C 
0003c2f0:·4a49·532d·352e·3130·2e31·2e33·0a20·202d··JIS-5.10.1.3.··- 
Max diff block lines reached; 3935223/3973201 bytes (99.04%) of diff not shown.
435 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 21 lines modified
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
125 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79125 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
126 ·············_\x8c_\x8i_\x8s············5.3.1126 ·············_\x8c_\x8i_\x8s············5.3.1
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 134 package·install·aide
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms140 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel;·then141 if·rpm·--quiet·-q·kernel;·then
Offset 182, 14 lines modifiedOffset 184, 26 lines modified
182 ··-·PCI-DSSv4-11.5.2184 ··-·PCI-DSSv4-11.5.2
183 ··-·enable_strategy185 ··-·enable_strategy
184 ··-·low_complexity186 ··-·low_complexity
185 ··-·low_disruption187 ··-·low_disruption
186 ··-·medium_severity188 ··-·medium_severity
187 ··-·no_reboot_needed189 ··-·no_reboot_needed
188 ··-·package_aide_installed190 ··-·package_aide_installed
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 196 package·--add=aide
 197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 198 [[packages]]
 199 name·=·"aide"
 200 version·=·"*"
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8201 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low202 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low203 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false204 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable205 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
194 dnf·install·aide206 dnf·install·aide
Offset 201, 28 lines modifiedOffset 215, 14 lines modified
201 include·install_aide215 include·install_aide
  
202 class·install_aide·{216 class·install_aide·{
203 ··package·{·'aide':217 ··package·{·'aide':
204 ····ensure·=>·'installed',218 ····ensure·=>·'installed',
205 ··}219 ··}
206 }220 }
207 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
208 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
209 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
210 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
211 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
212 package·install·aide 
213 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
214 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
215 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
216 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
217 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
218 package·--add=aide 
219 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules221 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
220 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.222 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
221 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.223 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
222 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.224 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
223 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*225 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 253, 31 lines modifiedOffset 253, 31 lines modified
253 ·············_\x8i_\x8s_\x8m······1446253 ·············_\x8i_\x8s_\x8m······1446
254 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1254 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
255 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12255 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
256 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1256 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
257 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176257 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
258 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020258 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020
259 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule259 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
261 [customizations] 
262 fips·=·true 
263 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8260 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
264 #·Remediation·is·applicable·only·in·certain·platforms261 #·Remediation·is·applicable·only·in·certain·platforms
265 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then262 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
266 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then263 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
267 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF264 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
268 kargs·=·["fips=1"]265 kargs·=·["fips=1"]
269 EOF266 EOF
270 fi267 fi
  
271 else268 else
272 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'269 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
273 fi270 fi
 271 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 272 [customizations]
 273 fips·=·true
274 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules274 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules
275 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:275 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
276 ····*·GnuTLS·library276 ····*·GnuTLS·library
277 ····*·OpenSSL·library277 ····*·OpenSSL·library
278 ····*·NSS·library278 ····*·NSS·library
279 ····*·OpenJDK279 ····*·OpenJDK
280 ····*·Libkrb5280 ····*·Libkrb5
Offset 290, 19 lines modifiedOffset 290, 21 lines modified
290 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.290 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
291 Severity: ···medium291 Severity: ···medium
292 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed292 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
293 Identifiers:·CCE-82723-8293 Identifiers:·CCE-82723-8
294 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123294 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
295 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1295 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
296 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174296 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 298 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 299 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 438826/445706 bytes (98.46%) of diff not shown.
2.1 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-e8.html
    
Offset 17794, 185 lines modifiedOffset 17794, 185 lines modified
00045810:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i00045810:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
00045820:·646d·3837·3731·2220·7461·6269·6e64·6578··dm8771"·tabindex00045820:·646d·3837·3731·2220·7461·6269·6e64·6578··dm8771"·tabindex
00045830:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto00045830:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
00045840:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded00045840:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
00045850:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="00045850:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00045860:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00045860:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00045870:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00045870:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
00045880:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl00045880:·6d65·6469·6174·696f·6e20·4b75·6265·726e··mediation·Kubern
00045890:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a 
000458a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
000458b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
000458c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
000458d0:·6d38·3737·3122·3e3c·7461·626c·6520·636c··m8771"><table·cl 
000458e0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
000458f0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00045900:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00045910:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00045920:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th00045890:·6574·6573·2073·6e69·7070·6574·20e2·87b2··etes·snippet·...
 000458a0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 000458b0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 000458c0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000458d0:·2269·646d·3837·3731·223e·3c74·6162·6c65··"idm8771"><table
 000458e0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 000458f0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00045900:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00045910:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00045920:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00045930:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00045940:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00045950:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00045930:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t00045960:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00045970:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00045980:·683e·3c74·643e·7472·7565·3c2f·7464·3e3c··h><td>true</td><
00045940:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00045950:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
00045960:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00045970:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
00045980:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
00045990:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate00045990:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
000459a0:·6779·3a3c·2f74·683e·3c74·643e·7265·7374··gy:</th><td>rest000459a0:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re
000459b0:·7269·6374·3c2f·7464·3e3c·2f74·723e·3c2f··rict</td></tr></000459b0:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>
000459c0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code000459c0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 000459d0:·6465·3e2d·2d2d·0a61·7069·5665·7273·696f··de>---.apiVersio
 000459e0:·6e3a·206d·6163·6869·6e65·636f·6e66·6967··n:·machineconfig
 000459f0:·7572·6174·696f·6e2e·6f70·656e·7368·6966··uration.openshif
 00045a00:·742e·696f·2f76·310a·6b69·6e64·3a20·4d61··t.io/v1.kind:·Ma
 00045a10:·6368·696e·6543·6f6e·6669·670a·7370·6563··chineConfig.spec
 00045a20:·3a0a·2020·636f·6e66·6967·3a0a·2020·2020··:.··config:.····
 00045a30:·6967·6e69·7469·6f6e·3a0a·2020·2020·2020··ignition:.······
 00045a40:·7665·7273·696f·6e3a·2033·2e31·2e30·0a20··version:·3.1.0.·
 00045a50:·2020·2073·7973·7465·6d64·3a0a·2020·2020·····systemd:.····
 00045a60:·2020·756e·6974·733a·0a20·2020·2020·2020····units:.·······
 00045a70:·202d·206e·616d·653a·2063·6f6e·6669·6775···-·name:·configu
 00045a80:·7265·2d63·7279·7074·6f2d·706f·6c69·6379··re-crypto-policy
 00045a90:·2e73·6572·7669·6365·0a20·2020·2020·2020··.service.·······
 00045aa0:·2020·2065·6e61·626c·6564·3a20·7472·7565·····enabled:·true
 00045ab0:·0a20·2020·2020·2020·2020·2063·6f6e·7465··.··········conte
 00045ac0:·6e74·733a·207c·0a20·2020·2020·2020·2020··nts:·|.·········
 00045ad0:·2020·205b·556e·6974·5d0a·2020·2020·2020·····[Unit].······
 00045ae0:·2020·2020·2020·4265·666f·7265·3d6b·7562········Before=kub
 00045af0:·656c·6574·2e73·6572·7669·6365·0a20·2020··elet.service.···
 00045b00:·2020·2020·2020·2020·205b·5365·7276·6963···········[Servic
 00045b10:·655d·0a20·2020·2020·2020·2020·2020·2054··e].············T
 00045b20:·7970·653d·6f6e·6573·686f·740a·2020·2020··ype=oneshot.····
 00045b30:·2020·2020·2020·2020·4578·6563·5374·6172··········ExecStar
 00045b40:·743d·7570·6461·7465·2d63·7279·7074·6f2d··t=update-crypto-
 00045b50:·706f·6c69·6369·6573·202d·2d73·6574·207b··policies·--set·{
 00045b60:·7b2e·7661·725f·7379·7374·656d·5f63·7279··{.var_system_cry
 00045b70:·7074·6f5f·706f·6c69·6379·7d7d·0a20·2020··pto_policy}}.···
 00045b80:·2020·2020·2020·2020·2052·656d·6169·6e41···········RemainA
 00045b90:·6674·6572·4578·6974·3d79·6573·0a20·2020··fterExit=yes.···
 00045ba0:·2020·2020·2020·2020·205b·496e·7374·616c···········[Instal
 00045bb0:·6c5d·0a20·2020·2020·2020·2020·2020·2057··l].············W
 00045bc0:·616e·7465·6442·793d·6d75·6c74·692d·7573··antedBy=multi-us
 00045bd0:·6572·2e74·6172·6765·740a·3c2f·636f·6465··er.target.</code
 00045be0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 00045bf0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 00045c00:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 00045c10:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
 00045c20:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
 00045c30:·3837·3732·2220·7461·6269·6e64·6578·3d22··8772"·tabindex="
 00045c40:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
 00045c50:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
 00045c60:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
 00045c70:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
 00045c80:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
 00045c90:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·
 00045ca0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><
 00045cb0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 00045cc0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 00045cd0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
 00045ce0:·3737·3222·3e3c·7461·626c·6520·636c·6173··772"><table·clas
 00045cf0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00045d00:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 00045d10:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 00045d20:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 00045d30:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 00045d40:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00045d50:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 00045d60:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 00045d70:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00045d80:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 00045d90:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 00045da0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 00045db0:·3a3c·2f74·683e·3c74·643e·7265·7374·7269··:</th><td>restri
 00045dc0:·6374·3c2f·7464·3e3c·2f74·723e·3c2f·7461··ct</td></tr></ta
 00045dd0:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>-
000459d0:·3e2d·206e·616d·653a·2058·4343·4446·2056··>-·name:·XCCDF·V00045de0:·206e·616d·653a·2058·4343·4446·2056·616c···name:·XCCDF·Val
000459e0:·616c·7565·2076·6172·5f73·7973·7465·6d5f··alue·var_system_00045df0:·7565·2076·6172·5f73·7973·7465·6d5f·6372··ue·var_system_cr
000459f0:·6372·7970·746f·5f70·6f6c·6963·7920·2320··crypto_policy·#·00045e00:·7970·746f·5f70·6f6c·6963·7920·2320·7072··ypto_policy·#·pr
00045a00:·7072·6f6d·6f74·6520·746f·2076·6172·6961··promote·to·varia00045e10:·6f6d·6f74·6520·746f·2076·6172·6961·626c··omote·to·variabl
00045a10:·626c·650a·2020·7365·745f·6661·6374·3a0a··ble.··set_fact:.00045e20:·650a·2020·7365·745f·6661·6374·3a0a·2020··e.··set_fact:.··
00045a20:·2020·2020·7661·725f·7379·7374·656d·5f63······var_system_c00045e30:·2020·7661·725f·7379·7374·656d·5f63·7279····var_system_cry
00045a30:·7279·7074·6f5f·706f·6c69·6379·3a20·2121··rypto_policy:·!!00045e40:·7074·6f5f·706f·6c69·6379·3a20·2121·7374··pto_policy:·!!st
00045a40:·7374·7220·3c61·6262·7220·7469·746c·653d··str·<abbr·title=00045e50:·7220·3c61·6262·7220·7469·746c·653d·2266··r·<abbr·title="f
00045a50:·2266·726f·6d20·5072·6f66·696c·652f·7265··"from·Profile/re00045e60:·726f·6d20·5072·6f66·696c·652f·7265·6669··rom·Profile/refi
00045a60:·6669·6e65·2d76·616c·7565·3a20·7863·6364··fine-value:·xccd00045e70:·6e65·2d76·616c·7565·3a20·7863·6364·665f··ne-value:·xccdf_
00045a70:·665f·6f72·672e·7373·6770·726f·6a65·6374··f_org.ssgproject00045e80:·6f72·672e·7373·6770·726f·6a65·6374·2e63··org.ssgproject.c
00045a80:·2e63·6f6e·7465·6e74·5f76·616c·7565·5f76··.content_value_v00045e90:·6f6e·7465·6e74·5f76·616c·7565·5f76·6172··ontent_value_var
00045a90:·6172·5f73·7973·7465·6d5f·6372·7970·746f··ar_system_crypto00045ea0:·5f73·7973·7465·6d5f·6372·7970·746f·5f70··_system_crypto_p
00045aa0:·5f70·6f6c·6963·7922·3e44·4546·4155·4c54··_policy">DEFAULT00045eb0:·6f6c·6963·7922·3e44·4546·4155·4c54·3a4e··olicy">DEFAULT:N
00045ab0:·3a4e·4f2d·5348·4131·3c2f·6162·6272·3e0a··:NO-SHA1</abbr>.00045ec0:·4f2d·5348·4131·3c2f·6162·6272·3e0a·2020··O-SHA1</abbr>.··
00045ac0:·2020·7461·6773·3a0a·2020·2020·2d20·616c····tags:.····-·al00045ed0:·7461·6773·3a0a·2020·2020·2d20·616c·7761··tags:.····-·alwa
00045ad0:·7761·7973·0a0a·2d20·6e61·6d65·3a20·436f··ways..-·name:·Co00045ee0:·7973·0a0a·2d20·6e61·6d65·3a20·436f·6e66··ys..-·name:·Conf
00045ae0:·6e66·6967·7572·6520·5379·7374·656d·2043··nfigure·System·C00045ef0:·6967·7572·6520·5379·7374·656d·2043·7279··igure·System·Cry
00045af0:·7279·7074·6f67·7261·7068·7920·506f·6c69··ryptography·Poli00045f00:·7074·6f67·7261·7068·7920·506f·6c69·6379··ptography·Policy
00045b00:·6379·0a20·206c·696e·6569·6e66·696c·653a··cy.··lineinfile:00045f10:·0a20·206c·696e·6569·6e66·696c·653a·0a20··.··lineinfile:.·
Max diff block lines reached; 2002490/2026668 bytes (98.81%) of diff not shown.
173 KB
html2text {}
    
Offset 730, 14 lines modifiedOffset 730, 39 lines modified
730 »       echo·"to·see·what·package·to·(re)install"·>&2730 »       echo·"to·see·what·package·to·(re)install"·>&2
  
731 »       false··#·end·with·an·error·code731 »       false··#·end·with·an·error·code
732 elif·test·"$rc"·!=·0;·then732 elif·test·"$rc"·!=·0;·then
733 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2733 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
734 »       false··#·end·with·an·error·code734 »       false··#·end·with·an·error·code
735 fi735 fi
 736 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 737 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 738 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 739 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 740 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 741 ---
 742 apiVersion:·machineconfiguration.openshift.io/v1
 743 kind:·MachineConfig
 744 spec:
 745 ··config:
 746 ····ignition:
 747 ······version:·3.1.0
 748 ····systemd:
 749 ······units:
 750 ········-·name:·configure-crypto-policy.service
 751 ··········enabled:·true
 752 ··········contents:·|
 753 ············[Unit]
 754 ············Before=kubelet.service
 755 ············[Service]
 756 ············Type=oneshot
 757 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 758 ············RemainAfterExit=yes
 759 ············[Install]
 760 ············WantedBy=multi-user.target
736 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8761 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
737 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low762 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
738 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low763 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
739 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false764 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
740 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict765 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
741 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable766 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
742 ··set_fact:767 ··set_fact:
Offset 786, 39 lines modifiedOffset 811, 14 lines modified
786 ··-·PCI-DSSv4-2.2.7811 ··-·PCI-DSSv4-2.2.7
787 ··-·configure_crypto_policy812 ··-·configure_crypto_policy
788 ··-·high_severity813 ··-·high_severity
789 ··-·low_complexity814 ··-·low_complexity
790 ··-·low_disruption815 ··-·low_disruption
791 ··-·no_reboot_needed816 ··-·no_reboot_needed
792 ··-·restrict_strategy817 ··-·restrict_strategy
793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
794 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
795 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
796 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
797 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
798 --- 
799 apiVersion:·machineconfiguration.openshift.io/v1 
800 kind:·MachineConfig 
801 spec: 
802 ··config: 
803 ····ignition: 
804 ······version:·3.1.0 
805 ····systemd: 
806 ······units: 
807 ········-·name:·configure-crypto-policy.service 
808 ··········enabled:·true 
809 ··········contents:·| 
810 ············[Unit] 
811 ············Before=kubelet.service 
812 ············[Service] 
813 ············Type=oneshot 
814 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
815 ············RemainAfterExit=yes 
816 ············[Install] 
817 ············WantedBy=multi-user.target 
818 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*818 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
819 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.819 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
820 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.820 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
821 Severity: ···medium821 Severity: ···medium
822 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy822 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
823 Identifiers:·CCE-80939-2823 Identifiers:·CCE-80939-2
824 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453824 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
Offset 1174, 19 lines modifiedOffset 1174, 21 lines modified
1174 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1174 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1175 The·rear·package·can·be·installed·with·the·following·command:1175 The·rear·package·can·be·installed·with·the·following·command:
1176 $·sudo·yum·install·rear1176 $·sudo·yum·install·rear
1177 Rationale:···rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.1177 Rationale:···rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.
1178 Severity: ···medium1178 Severity: ···medium
1179 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_rear_installed1179 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_rear_installed
1180 Identifiers:·CCE-82883-01180 Identifiers:·CCE-82883-0
1181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1186 package·install·rear
1182 [[packages]] 
1183 name·=·"rear" 
1184 version·=·"*" 
1185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1190 #·Remediation·is·applicable·only·in·certain·platforms1192 #·Remediation·is·applicable·only·in·certain·platforms
1191 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1193 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1216, 14 lines modifiedOffset 1218, 26 lines modified
1216 ··-·CCE-82883-01218 ··-·CCE-82883-0
1217 ··-·enable_strategy1219 ··-·enable_strategy
1218 ··-·low_complexity1220 ··-·low_complexity
1219 ··-·low_disruption1221 ··-·low_disruption
1220 ··-·medium_severity1222 ··-·medium_severity
1221 ··-·no_reboot_needed1223 ··-·no_reboot_needed
1222 ··-·package_rear_installed1224 ··-·package_rear_installed
 1225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1230 package·--add=rear
 1231 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1232 [[packages]]
 1233 name·=·"rear"
 1234 version·=·"*"
1223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81235 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1224 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1236 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1225 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1237 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 170436/176676 bytes (96.47%) of diff not shown.
2.22 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-hipaa.html
    
Offset 17091, 184 lines modifiedOffset 17091, 184 lines modified
00042c20:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe00042c20:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
00042c30:·743d·2223·6964·6d38·3737·3122·2074·6162··t="#idm8771"·tab00042c30:·743d·2223·6964·6d38·3737·3122·2074·6162··t="#idm8771"·tab
00042c40:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="00042c40:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
00042c50:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp00042c50:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
00042c60:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti00042c60:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
00042c70:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to00042c70:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
00042c80:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#00042c80:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
00042c90:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A00042c90:·2122·3e52·656d·6564·6961·7469·6f6e·204b··!">Remediation·K
00042ca0:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
00042cb0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00042cc0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00042cd0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00042ce0:·643d·2269·646d·3837·3731·223e·3c74·6162··d="idm8771"><tab 
00042cf0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
00042d00:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
00042d10:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
00042d20:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
00042d30:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity00042ca0:·7562·6572·6e65·7465·7320·736e·6970·7065··ubernetes·snippe
 00042cb0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 00042cc0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 00042cd0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 00042ce0:·2220·6964·3d22·6964·6d38·3737·3122·3e3c··"·id="idm8771"><
 00042cf0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 00042d00:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 00042d10:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 00042d20:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 00042d30:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 00042d40:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 00042d50:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 00042d60:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
00042d40:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t00042d70:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00042d80:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 00042d90:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true<
00042d50:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
00042d60:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
00042d70:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
00042d80:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
00042d90:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
00042da0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S00042da0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
00042db0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td00042db0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
00042dc0:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></00042dc0:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
00042dd0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>00042dd0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
00042de0:·3c63·6f64·653e·2d20·6e61·6d65·3a20·5843··<code>-·name:·XC 
00042df0:·4344·4620·5661·6c75·6520·7661·725f·7379··CDF·Value·var_sy 
00042e00:·7374·656d·5f63·7279·7074·6f5f·706f·6c69··stem_crypto_poli 
00042e10:·6379·2023·2070·726f·6d6f·7465·2074·6f20··cy·#·promote·to· 
00042e20:·7661·7269·6162·6c65·0a20·2073·6574·5f66··variable.··set_f 
00042e30:·6163·743a·0a20·2020·2076·6172·5f73·7973··act:.····var_sys00042de0:·653e·3c63·6f64·653e·2d2d·2d0a·6170·6956··e><code>---.apiV
 00042df0:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec
 00042e00:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope
 00042e10:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin
 00042e20:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig
 00042e30:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config:
 00042e40:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.·
 00042e50:·2020·2020·2076·6572·7369·6f6e·3a20·332e·······version:·3.
 00042e60:·312e·300a·2020·2020·7379·7374·656d·643a··1.0.····systemd:
 00042e70:·0a20·2020·2020·2075·6e69·7473·3a0a·2020··.······units:.··
 00042e80:·2020·2020·2020·2d20·6e61·6d65·3a20·636f········-·name:·co
 00042e90:·6e66·6967·7572·652d·6372·7970·746f·2d70··nfigure-crypto-p
 00042ea0:·6f6c·6963·792e·7365·7276·6963·650a·2020··olicy.service.··
 00042eb0:·2020·2020·2020·2020·656e·6162·6c65·643a··········enabled:
 00042ec0:·2074·7275·650a·2020·2020·2020·2020·2020···true.··········
 00042ed0:·636f·6e74·656e·7473·3a20·7c0a·2020·2020··contents:·|.····
 00042ee0:·2020·2020·2020·2020·5b55·6e69·745d·0a20··········[Unit].·
 00042ef0:·2020·2020·2020·2020·2020·2042·6566·6f72·············Befor
 00042f00:·653d·6b75·6265·6c65·742e·7365·7276·6963··e=kubelet.servic
 00042f10:·650a·2020·2020·2020·2020·2020·2020·5b53··e.············[S
 00042f20:·6572·7669·6365·5d0a·2020·2020·2020·2020··ervice].········
 00042f30:·2020·2020·5479·7065·3d6f·6e65·7368·6f74······Type=oneshot
 00042f40:·0a20·2020·2020·2020·2020·2020·2045·7865··.············Exe
 00042f50:·6353·7461·7274·3d75·7064·6174·652d·6372··cStart=update-cr
 00042f60:·7970·746f·2d70·6f6c·6963·6965·7320·2d2d··ypto-policies·--
 00042f70:·7365·7420·7b7b·2e76·6172·5f73·7973·7465··set·{{.var_syste
00042e40:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic00042f80:·6d5f·6372·7970·746f·5f70·6f6c·6963·797d··m_crypto_policy}
00042e50:·793a·2021·2173·7472·203c·6162·6272·2074··y:·!!str·<abbr·t 
00042e60:·6974·6c65·3d22·6672·6f6d·2050·726f·6669··itle="from·Profi 
00042e70:·6c65·2f72·6566·696e·652d·7661·6c75·653a··le/refine-value: 
00042e80:·2078·6363·6466·5f6f·7267·2e73·7367·7072···xccdf_org.ssgpr 
00042e90:·6f6a·6563·742e·636f·6e74·656e·745f·7661··oject.content_va 
00042ea0:·6c75·655f·7661·725f·7379·7374·656d·5f63··lue_var_system_c 
00042eb0:·7279·7074·6f5f·706f·6c69·6379·223e·4649··rypto_policy">FI 
00042ec0:·5053·3c2f·6162·6272·3e0a·2020·7461·6773··PS</abbr>.··tags 
00042ed0:·3a0a·2020·2020·2d20·616c·7761·7973·0a0a··:.····-·always.. 
00042ee0:·2d20·6e61·6d65·3a20·436f·6e66·6967·7572··-·name:·Configur 
00042ef0:·6520·5379·7374·656d·2043·7279·7074·6f67··e·System·Cryptog 
00042f00:·7261·7068·7920·506f·6c69·6379·0a20·206c··raphy·Policy.··l 
00042f10:·696e·6569·6e66·696c·653a·0a20·2020·2070··ineinfile:.····p 
00042f20:·6174·683a·202f·6574·632f·6372·7970·746f··ath:·/etc/crypto 
00042f30:·2d70·6f6c·6963·6965·732f·636f·6e66·6967··-policies/config 
00042f40:·0a20·2020·2072·6567·6578·703a·205e·283f··.····regexp:·^(? 
00042f50:·2123·2928·5c53·2b29·240a·2020·2020·6c69··!#)(\S+)$.····li 
00042f60:·6e65·3a20·277b·7b20·7661·725f·7379·7374··ne:·'{{·var_syst00042f90:·7d0a·2020·2020·2020·2020·2020·2020·5265··}.············Re
 00042fa0:·6d61·696e·4166·7465·7245·7869·743d·7965··mainAfterExit=ye
 00042fb0:·730a·2020·2020·2020·2020·2020·2020·5b49··s.············[I
 00042fc0:·6e73·7461·6c6c·5d0a·2020·2020·2020·2020··nstall].········
 00042fd0:·2020·2020·5761·6e74·6564·4279·3d6d·756c······WantedBy=mul
 00042fe0:·7469·2d75·7365·722e·7461·7267·6574·0a3c··ti-user.target.<
 00042ff0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 00043000:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 00043010:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 00043020:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 00043030:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 00043040:·2223·6964·6d38·3737·3222·2074·6162·696e··"#idm8772"·tabin
 00043050:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00043060:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00043070:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00043080:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00043090:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 000430a0:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
 000430b0:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
 000430c0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 000430d0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 000430e0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 000430f0:·2269·646d·3837·3732·223e·3c74·6162·6c65··"idm8772"><table
 00043100:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00043110:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 00043120:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 00043130:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 00043140:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 00043150:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00043160:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00043170:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00043180:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00043190:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 000431a0:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 000431b0:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 000431c0:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
Max diff block lines reached; 2139169/2163209 bytes (98.89%) of diff not shown.
160 KB
html2text {}
    
Offset 558, 14 lines modifiedOffset 558, 39 lines modified
558 »       echo·"to·see·what·package·to·(re)install"·>&2558 »       echo·"to·see·what·package·to·(re)install"·>&2
  
559 »       false··#·end·with·an·error·code559 »       false··#·end·with·an·error·code
560 elif·test·"$rc"·!=·0;·then560 elif·test·"$rc"·!=·0;·then
561 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2561 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
562 »       false··#·end·with·an·error·code562 »       false··#·end·with·an·error·code
563 fi563 fi
 564 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 565 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 566 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 567 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 568 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 569 ---
 570 apiVersion:·machineconfiguration.openshift.io/v1
 571 kind:·MachineConfig
 572 spec:
 573 ··config:
 574 ····ignition:
 575 ······version:·3.1.0
 576 ····systemd:
 577 ······units:
 578 ········-·name:·configure-crypto-policy.service
 579 ··········enabled:·true
 580 ··········contents:·|
 581 ············[Unit]
 582 ············Before=kubelet.service
 583 ············[Service]
 584 ············Type=oneshot
 585 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 586 ············RemainAfterExit=yes
 587 ············[Install]
 588 ············WantedBy=multi-user.target
564 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8589 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
565 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low590 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
566 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low591 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
567 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false592 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
568 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict593 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
569 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable594 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
570 ··set_fact:595 ··set_fact:
Offset 614, 39 lines modifiedOffset 639, 14 lines modified
614 ··-·PCI-DSSv4-2.2.7639 ··-·PCI-DSSv4-2.2.7
615 ··-·configure_crypto_policy640 ··-·configure_crypto_policy
616 ··-·high_severity641 ··-·high_severity
617 ··-·low_complexity642 ··-·low_complexity
618 ··-·low_disruption643 ··-·low_disruption
619 ··-·no_reboot_needed644 ··-·no_reboot_needed
620 ··-·restrict_strategy645 ··-·restrict_strategy
621 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
622 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
623 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
624 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
625 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
626 --- 
627 apiVersion:·machineconfiguration.openshift.io/v1 
628 kind:·MachineConfig 
629 spec: 
630 ··config: 
631 ····ignition: 
632 ······version:·3.1.0 
633 ····systemd: 
634 ······units: 
635 ········-·name:·configure-crypto-policy.service 
636 ··········enabled:·true 
637 ··········contents:·| 
638 ············[Unit] 
639 ············Before=kubelet.service 
640 ············[Service] 
641 ············Type=oneshot 
642 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
643 ············RemainAfterExit=yes 
644 ············[Install] 
645 ············WantedBy=multi-user.target 
646 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*646 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
647 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.647 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
648 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.648 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
649 Severity: ···medium649 Severity: ···medium
650 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy650 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
651 Identifiers:·CCE-80939-2651 Identifiers:·CCE-80939-2
652 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453652 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
Offset 1657, 18 lines modifiedOffset 1657, 21 lines modified
1657 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-0022351657 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-002235
1658 ·············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1658 ·············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1659 References:··_\x8n_\x8i_\x8s_\x8t····CM-61659 References:··_\x8n_\x8i_\x8s_\x8t····CM-6
1660 ·············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.11660 ·············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.1
1661 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271661 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1662 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··RHEL-08-0401801662 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··RHEL-08-040180
1663 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-230532r1017294_rule1663 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-230532r1017294_rule
1664 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81664 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1665 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1666 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1667 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1668 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1669 service·disable·debug-shell
1665 [customizations.services] 
1666 masked·=·["debug-shell"] 
1667 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81670 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1668 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1671 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1669 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1672 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1670 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1673 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1671 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1674 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1672 #·Remediation·is·applicable·only·in·certain·platforms1675 #·Remediation·is·applicable·only·in·certain·platforms
1673 if·rpm·--quiet·-q·kernel;·then1676 if·rpm·--quiet·-q·kernel;·then
Offset 1690, 14 lines modifiedOffset 1693, 33 lines modified
1690 #·so·let's·reset·the·state·so·OVAL·checks·pass.1693 #·so·let's·reset·the·state·so·OVAL·checks·pass.
1691 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.1694 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
1692 "$SYSTEMCTL_EXEC"·reset-failed·'debug-shell.service'·||·true1695 "$SYSTEMCTL_EXEC"·reset-failed·'debug-shell.service'·||·true
  
1693 else1696 else
1694 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1697 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1695 fi1698 fi
 1699 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1700 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1701 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 1702 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 1703 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
 1704 apiVersion:·machineconfiguration.openshift.io/v1
 1705 kind:·MachineConfig
 1706 spec:
 1707 ··config:
 1708 ····ignition:
 1709 ······version:·3.1.0
 1710 ····systemd:
 1711 ······units:
 1712 ······-·name:·debug-shell.service
 1713 ········enabled:·false
 1714 ········mask:·true
Max diff block lines reached; 158253/163664 bytes (96.69%) of diff not shown.
2.75 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-ism_o.html
    
Offset 17634, 284 lines modifiedOffset 17634, 284 lines modified
00044e10:·7267·6574·3d22·2369·646d·3739·3930·2220··rget="#idm7990"·00044e10:·7267·6574·3d22·2369·646d·3739·3930·2220··rget="#idm7990"·
00044e20:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol00044e20:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00044e30:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00044e30:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
00044e40:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00044e40:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
00044e50:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00044e50:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
00044e60:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00044e60:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
00044e70:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00044e70:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
00044e80:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr 
00044e90:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...< 
00044ea0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas 
00044eb0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps 
00044ec0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id=" 
00044ed0:·6964·6d37·3939·3022·3e3c·7072·653e·3c63··idm7990"><pre><c 
00044ee0:·6f64·653e·0a5b·5b70·6163·6b61·6765·735d··ode>.[[packages] 
00044ef0:·5d0a·6e61·6d65·203d·2022·6169·6465·220a··].name·=·"aide". 
00044f00:·7665·7273·696f·6e20·3d20·222a·220a·3c2f··version·=·"*".</ 
00044f10:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div 
00044f20:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b 
00044f30:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data 
00044f40:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps 
00044f50:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target=" 
00044f60:·2369·646d·3739·3931·2220·7461·6269·6e64··#idm7991"·tabind 
00044f70:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00044f80:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00044f90:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00044fa0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00044fb0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00044fc0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
00044fd0:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>00044e80:·6e20·7363·7269·7074·20e2·87b2·3c2f·613e··n·script·...</a>
00044fe0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="00044e90:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
00044ff0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c00044ea0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
00045000:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm00044eb0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
00045010:·3739·3931·223e·3c74·6162·6c65·2063·6c61··7991"><table·cla00044ec0:·3739·3930·223e·3c74·6162·6c65·2063·6c61··7990"><table·cla
00045020:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-00044ed0:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
00045030:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo00044ee0:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
00045040:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con00044ef0:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
00045050:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>00044f00:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
00045060:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>00044f10:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
00045070:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr00044f20:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
00045080:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt00044f30:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
00045090:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low00044f40:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
000450a0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t00044f50:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
000450b0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t00044f60:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
000450c0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr00044f70:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
000450d0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg00044f80:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
000450e0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl00044f90:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
000450f0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab00044fa0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
00045100:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·00044fb0:·6c65·3e3c·7072·653e·3c63·6f64·653e·0a70··le><pre><code>.p
 00044fc0:·6163·6b61·6765·2069·6e73·7461·6c6c·2061··ackage·install·a
00045110:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a 
00045120:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
00045130:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
00045140:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui 
00045150:·6574·202d·7120·6b65·726e·656c·3b20·7468··et·-q·kernel;·th 
00045160:·656e·0a0a·6966·2021·2072·706d·202d·7120··en..if·!·rpm·-q· 
00045170:·2d2d·7175·6965·7420·2261·6964·6522·203b··--quiet·"aide"·; 
00045180:·2074·6865·6e0a·2020·2020·7975·6d20·696e···then.····yum·in 
00045190:·7374·616c·6c20·2d79·2022·6169·6465·220a··stall·-y·"aide". 
000451a0:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
000451b0:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
000451c0:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
000451d0:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
000451e0:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
000451f0:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><00044fd0:·6964·650a·3c2f·636f·6465·3e3c·2f70·7265··ide.</code></pre
00045200:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b00044fe0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
00045210:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·00044ff0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
00045220:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col00045000:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
00045230:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ00045010:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
00045240:·6574·3d22·2369·646d·3739·3932·2220·7461··et="#idm7992"·ta00045020:·7267·6574·3d22·2369·646d·3739·3931·2220··rget="#idm7991"·
00045250:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00045030:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
00045260:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00045040:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
00045270:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00045050:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
00045280:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00045060:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
00045290:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00045070:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
000452a0:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00045080:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
000452b0:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
000452c0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
000452d0:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
000452e0:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
000452f0:·6964·3d22·6964·6d37·3939·3222·3e3c·7461··id="idm7992"><ta 
00045300:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
00045310:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
00045320:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
00045330:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
00045340:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
00045350:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
00045360:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00045370:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>00045090:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
 000450a0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 000450b0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 000450c0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 000450d0:·643d·2269·646d·3739·3931·223e·3c74·6162··d="idm7991"><tab
 000450e0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 000450f0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00045100:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00045110:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00045120:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00045130:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00045140:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00045150:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00045160:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00045170:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00045180:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 00045190:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 000451a0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
00045380:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr000451b0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
00045390:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
000453a0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
000453b0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
000453c0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
000453d0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
000453e0:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
000453f0:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat 
00045400:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package·000451c0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 000451d0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio
 000451e0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable·
 000451f0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain·
 00045200:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm
 00045210:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern
 00045220:·656c·3b20·7468·656e·0a0a·6966·2021·2072··el;·then..if·!·r
 00045230:·706d·202d·7120·2d2d·7175·6965·7420·2261··pm·-q·--quiet·"a
 00045240:·6964·6522·203b·2074·6865·6e0a·2020·2020··ide"·;·then.····
 00045250:·7975·6d20·696e·7374·616c·6c20·2d79·2022··yum·install·-y·"
 00045260:·6169·6465·220a·6669·0a0a·656c·7365·0a20··aide".fi..else.·
 00045270:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 00045280:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
 00045290:·6973·206e·6f74·2061·7070·6c69·6361·626c··is·not·applicabl
Max diff block lines reached; 2608280/2646120 bytes (98.57%) of diff not shown.
232 KB
html2text {}
    
Offset 713, 19 lines modifiedOffset 713, 21 lines modified
713 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5713 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
714 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199714 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
715 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359715 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
716 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79716 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
717 ·············_\x8c_\x8i_\x8s············5.3.1717 ·············_\x8c_\x8i_\x8s············5.3.1
718 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2718 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
719 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule719 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8720 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 721 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 722 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 723 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 724 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 725 package·install·aide
721 [[packages]] 
722 name·=·"aide" 
723 version·=·"*" 
724 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8726 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
725 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low727 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
726 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low728 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
727 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false729 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
728 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable730 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
729 #·Remediation·is·applicable·only·in·certain·platforms731 #·Remediation·is·applicable·only·in·certain·platforms
730 if·rpm·--quiet·-q·kernel;·then732 if·rpm·--quiet·-q·kernel;·then
Offset 773, 14 lines modifiedOffset 775, 26 lines modified
773 ··-·PCI-DSSv4-11.5.2775 ··-·PCI-DSSv4-11.5.2
774 ··-·enable_strategy776 ··-·enable_strategy
775 ··-·low_complexity777 ··-·low_complexity
776 ··-·low_disruption778 ··-·low_disruption
777 ··-·medium_severity779 ··-·medium_severity
778 ··-·no_reboot_needed780 ··-·no_reboot_needed
779 ··-·package_aide_installed781 ··-·package_aide_installed
 782 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 783 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 784 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 785 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 786 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 787 package·--add=aide
 788 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 789 [[packages]]
 790 name·=·"aide"
 791 version·=·"*"
780 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8792 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
781 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low793 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
782 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low794 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
783 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false795 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
784 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable796 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
785 dnf·install·aide797 dnf·install·aide
Offset 792, 28 lines modifiedOffset 806, 14 lines modified
792 include·install_aide806 include·install_aide
  
793 class·install_aide·{807 class·install_aide·{
794 ··package·{·'aide':808 ··package·{·'aide':
795 ····ensure·=>·'installed',809 ····ensure·=>·'installed',
796 ··}810 ··}
797 }811 }
798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
799 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
800 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
801 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
802 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
803 package·install·aide 
804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
805 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
806 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
807 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
808 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
809 package·--add=aide 
810 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule812 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·1·rule
811 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.813 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
812 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.814 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
813 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.815 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
814 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*816 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8de\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 828, 31 lines modifiedOffset 828, 31 lines modified
828 ·············_\x8i_\x8s_\x8m······1446828 ·············_\x8i_\x8s_\x8m······1446
829 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1829 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
830 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12830 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
831 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1831 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
832 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176832 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
833 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020833 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020
834 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule834 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
835 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
836 [customizations] 
837 fips·=·true 
838 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8835 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
839 #·Remediation·is·applicable·only·in·certain·platforms836 #·Remediation·is·applicable·only·in·certain·platforms
840 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then837 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
841 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then838 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
842 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF839 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
843 kargs·=·["fips=1"]840 kargs·=·["fips=1"]
844 EOF841 EOF
845 fi842 fi
  
846 else843 else
847 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'844 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
848 fi845 fi
 846 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 847 [customizations]
 848 fips·=·true
849 Group  ·System·Cryptographic·Policies·  Group·contains·3·rules849 Group  ·System·Cryptographic·Policies·  Group·contains·3·rules
850 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:850 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
851 ····*·GnuTLS·library851 ····*·GnuTLS·library
852 ····*·OpenSSL·library852 ····*·OpenSSL·library
853 ····*·NSS·library853 ····*·NSS·library
854 ····*·OpenJDK854 ····*·OpenJDK
855 ····*·Libkrb5855 ····*·Libkrb5
Offset 895, 14 lines modifiedOffset 895, 39 lines modified
895 »       echo·"to·see·what·package·to·(re)install"·>&2895 »       echo·"to·see·what·package·to·(re)install"·>&2
  
896 »       false··#·end·with·an·error·code896 »       false··#·end·with·an·error·code
897 elif·test·"$rc"·!=·0;·then897 elif·test·"$rc"·!=·0;·then
898 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2898 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
899 »       false··#·end·with·an·error·code899 »       false··#·end·with·an·error·code
900 fi900 fi
 901 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 902 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 903 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 230307/237233 bytes (97.08%) of diff not shown.
4.22 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-ospp.html
    
Offset 15256, 285 lines modifiedOffset 15256, 285 lines modified
0003b970:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b970:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b980:·2223·6964·6d37·3939·3022·2074·6162·696e··"#idm7990"·tabin0003b980:·2223·6964·6d37·3939·3022·2074·6162·696e··"#idm7990"·tabin
0003b990:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b990:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b9a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b9a0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b9b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b9b0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b9c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b9c0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b9d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b9d0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b9e0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003b9e0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
0003b9f0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003ba00:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003ba10:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003ba20:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003ba30:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
0003ba40:·3930·223e·3c70·7265·3e3c·636f·6465·3e0a··90"><pre><code>. 
0003ba50:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003ba60:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003ba70:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003ba80:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003ba90:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003baa0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003bab0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003bac0:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
0003bad0:·3939·3122·2074·6162·696e·6465·783d·2230··991"·tabindex="0 
0003bae0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003baf0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003bb00:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003bb10:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003bb20:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003bb30:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003bb40:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><0003b9f0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
0003bb50:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003ba00:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003bb60:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003ba10:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003bb70:·7365·2220·6964·3d22·6964·6d37·3939·3122··se"·id="idm7991"0003ba20:·7365·2220·6964·3d22·6964·6d37·3939·3022··se"·id="idm7990"
0003bb80:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003ba30:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003bb90:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003ba40:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003bba0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003ba50:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003bbb0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003ba60:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003bbc0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl0003ba70:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
0003bbd0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l0003ba80:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
0003bbe0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003ba90:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
0003bbf0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<0003baa0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
0003bc00:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bab0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bc10:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb0003bac0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
0003bc20:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal0003bad0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
0003bc30:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>0003bae0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
0003bc40:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t0003baf0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
0003bc50:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td0003bb00:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
0003bc60:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p0003bb10:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 0003bb20:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 0003bb30:·6520·696e·7374·616c·6c20·6169·6465·0a3c··e·install·aide.<
0003bc70:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003bc80:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003bc90:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003bca0:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003bcb0:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
0003bcc0:·206b·6572·6e65·6c3b·2074·6865·6e0a·0a69···kernel;·then..i 
0003bcd0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
0003bce0:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
0003bcf0:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install 
0003bd00:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
0003bd10:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003bd20:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003bd30:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003bd40:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003bd50:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003bd60:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003bb40:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
0003bd70:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003bb50:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
0003bd80:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003bb60:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
0003bd90:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003bb70:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
0003bda0:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003bb80:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003bdb0:·6964·6d37·3939·3222·2074·6162·696e·6465··idm7992"·tabinde0003bb90:·2223·6964·6d37·3939·3122·2074·6162·696e··"#idm7991"·tabin
0003bdc0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003bba0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003bdd0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003bbb0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003bde0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003bbc0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003bdf0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003bbd0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003be00:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003bbe0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003be10:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib0003bbf0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 0003bc00:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003bc10:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003bc20:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003bc30:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003bc40:·6d37·3939·3122·3e3c·7461·626c·6520·636c··m7991"><table·cl
 0003bc50:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003be20:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0003be30:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003be40:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003be50:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003be60:·646d·3739·3932·223e·3c74·6162·6c65·2063··dm7992"><table·c 
0003be70:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003be80:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003be90:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c0003bc60:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003bea0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003beb0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003bec0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003bed0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003bee0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l0003bc70:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003bc80:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003bc90:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003bca0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003bcb0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003bcc0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003bcd0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003bce0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003bcf0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003bd00:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003bd10:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003bef0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>0003bd20:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003bf00:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>0003bd30:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
 0003bd40:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003bd50:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003bd60:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003bd70:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 0003bd80:·6965·7420·2d71·206b·6572·6e65·6c3b·2074··iet·-q·kernel;·t
 0003bd90:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 0003bda0:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"·
 0003bdb0:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 0003bdc0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 0003bdd0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 0003bde0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 0003bdf0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 0003be00:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 0003be10:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 0003be20:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 0003be30:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003be40:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003be50:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003be60:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
Max diff block lines reached; 3936465/3974443 bytes (99.04%) of diff not shown.
435 KB
html2text {}
    
Offset 114, 19 lines modifiedOffset 114, 21 lines modified
114 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5114 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
115 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199115 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
116 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359116 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
117 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79117 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
118 ·············_\x8c_\x8i_\x8s············5.3.1118 ·············_\x8c_\x8i_\x8s············5.3.1
119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
120 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule120 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 126 package·install·aide
122 [[packages]] 
123 name·=·"aide" 
124 version·=·"*" 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
130 #·Remediation·is·applicable·only·in·certain·platforms132 #·Remediation·is·applicable·only·in·certain·platforms
131 if·rpm·--quiet·-q·kernel;·then133 if·rpm·--quiet·-q·kernel;·then
Offset 174, 14 lines modifiedOffset 176, 26 lines modified
174 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
175 ··-·enable_strategy177 ··-·enable_strategy
176 ··-·low_complexity178 ··-·low_complexity
177 ··-·low_disruption179 ··-·low_disruption
178 ··-·medium_severity180 ··-·medium_severity
179 ··-·no_reboot_needed181 ··-·no_reboot_needed
180 ··-·package_aide_installed182 ··-·package_aide_installed
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 188 package·--add=aide
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 190 [[packages]]
 191 name·=·"aide"
 192 version·=·"*"
181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
186 dnf·install·aide198 dnf·install·aide
Offset 193, 28 lines modifiedOffset 207, 14 lines modified
193 include·install_aide207 include·install_aide
  
194 class·install_aide·{208 class·install_aide·{
195 ··package·{·'aide':209 ··package·{·'aide':
196 ····ensure·=>·'installed',210 ····ensure·=>·'installed',
197 ··}211 ··}
198 }212 }
199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
204 package·install·aide 
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
210 package·--add=aide 
211 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules213 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
212 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.214 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
213 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.215 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·8.
  
214 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.216 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
215 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 245, 31 lines modifiedOffset 245, 31 lines modified
245 ·············_\x8i_\x8s_\x8m······1446245 ·············_\x8i_\x8s_\x8m······1446
246 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1246 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
247 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12247 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
248 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1248 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
249 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176249 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
250 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020250 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020
251 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule251 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
252 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
253 [customizations] 
254 fips·=·true 
255 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8252 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
256 #·Remediation·is·applicable·only·in·certain·platforms253 #·Remediation·is·applicable·only·in·certain·platforms
257 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then254 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
258 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then255 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
259 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF256 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
260 kargs·=·["fips=1"]257 kargs·=·["fips=1"]
261 EOF258 EOF
262 fi259 fi
  
263 else260 else
264 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'261 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
265 fi262 fi
 263 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 264 [customizations]
 265 fips·=·true
266 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules266 Group  ·System·Cryptographic·Policies·  Group·contains·8·rules
267 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:267 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
268 ····*·GnuTLS·library268 ····*·GnuTLS·library
269 ····*·OpenSSL·library269 ····*·OpenSSL·library
270 ····*·NSS·library270 ····*·NSS·library
271 ····*·OpenJDK271 ····*·OpenJDK
272 ····*·Libkrb5272 ····*·Libkrb5
Offset 282, 19 lines modifiedOffset 282, 21 lines modified
282 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.282 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
283 Severity: ···medium283 Severity: ···medium
284 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed284 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
285 Identifiers:·CCE-82723-8285 Identifiers:·CCE-82723-8
286 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123286 ·············_\x8d_\x8i_\x8s_\x8a···CCI-002890,·CCI-002450,·CCI-003123
287 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1287 References:··_\x8o_\x8s_\x8p_\x8p···FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
288 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174288 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
289 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8289 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 290 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 291 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 438826/445706 bytes (98.46%) of diff not shown.
2.92 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-pci-dss.html
    
Offset 16852, 285 lines modifiedOffset 16852, 285 lines modified
00041d30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00041d30:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00041d40:·2223·6964·6d37·3939·3022·2074·6162·696e··"#idm7990"·tabin00041d40:·2223·6964·6d37·3939·3022·2074·6162·696e··"#idm7990"·tabin
00041d50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00041d50:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00041d60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00041d60:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00041d70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00041d70:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00041d80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00041d80:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00041d90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00041d90:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00041da0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB00041da0:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
00041db0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
00041dc0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00041dd0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00041de0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00041df0:·6c61·7073·6522·2069·643d·2269·646d·3739··lapse"·id="idm79 
00041e00:·3930·223e·3c70·7265·3e3c·636f·6465·3e0a··90"><pre><code>. 
00041e10:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
00041e20:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
00041e30:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
00041e40:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00041e50:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00041e60:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00041e70:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00041e80:·7461·2d74·6172·6765·743d·2223·6964·6d37··ta-target="#idm7 
00041e90:·3939·3122·2074·6162·696e·6465·783d·2230··991"·tabindex="0 
00041ea0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
00041eb0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
00041ec0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
00041ed0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
00041ee0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
00041ef0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
00041f00:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><00041db0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
00041f10:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel00041dc0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
00041f20:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap00041dd0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
00041f30:·7365·2220·6964·3d22·6964·6d37·3939·3122··se"·id="idm7991"00041de0:·7365·2220·6964·3d22·6964·6d37·3939·3022··se"·id="idm7990"
00041f40:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t00041df0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
00041f50:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip00041e00:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
00041f60:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere00041e10:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
00041f70:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense00041e20:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
00041f80:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl00041e30:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
00041f90:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l00041e40:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
00041fa0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>00041e50:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
00041fb0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<00041e60:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
00041fc0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>00041e70:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
00041fd0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb00041e80:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
00041fe0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal00041e90:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
00041ff0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>00041ea0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
00042000:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t00041eb0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
00042010:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td00041ec0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
00042020:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p00041ed0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00041ee0:·7265·3e3c·636f·6465·3e0a·7061·636b·6167··re><code>.packag
 00041ef0:·6520·696e·7374·616c·6c20·6169·6465·0a3c··e·install·aide.<
00042030:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
00042040:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
00042050:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
00042060:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
00042070:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
00042080:·206b·6572·6e65·6c3b·2074·6865·6e0a·0a69···kernel;·then..i 
00042090:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
000420a0:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
000420b0:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install 
000420c0:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
000420d0:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
000420e0:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
000420f0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
00042100:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
00042110:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
00042120:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>00041f00:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
00042130:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt00041f10:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
00042140:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-00041f20:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
00042150:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse00041f30:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
00042160:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#00041f40:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00042170:·6964·6d37·3939·3222·2074·6162·696e·6465··idm7992"·tabinde00041f50:·2223·6964·6d37·3939·3122·2074·6162·696e··"#idm7991"·tabin
00042180:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt00041f60:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00042190:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande00041f70:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
000421a0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=00041f80:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
000421b0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev00041f90:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
000421c0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R00041fa0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00041fb0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 00041fc0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 00041fd0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00041fe0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00041ff0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00042000:·6d37·3939·3122·3e3c·7461·626c·6520·636c··m7991"><table·cl
 00042010:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00042020:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 00042030:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 00042040:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00042050:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 00042060:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00042070:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00042080:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00042090:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 000420a0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 000420b0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 000420c0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 000420d0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 000420e0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 000420f0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
000421d0:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib00042100:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
000421e0:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
000421f0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00042200:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00042210:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00042220:·646d·3739·3932·223e·3c74·6162·6c65·2063··dm7992"><table·c 
00042230:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
00042240:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
00042250:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
00042260:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
00042270:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
00042280:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
00042290:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
000422a0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
000422b0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
000422c0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>00042110:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 00042120:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 00042130:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 00042140:·6965·7420·2d71·206b·6572·6e65·6c3b·2074··iet·-q·kernel;·t
 00042150:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 00042160:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"·
 00042170:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 00042180:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 00042190:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 000421a0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 000421b0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 000421c0:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 000421d0:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 000421e0:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 000421f0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
Max diff block lines reached; 2777414/2815392 bytes (98.65%) of diff not shown.
236 KB
html2text {}
    
Offset 524, 19 lines modifiedOffset 524, 21 lines modified
524 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5524 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
525 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199525 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
526 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359526 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
527 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79527 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
528 ·············_\x8c_\x8i_\x8s············5.3.1528 ·············_\x8c_\x8i_\x8s············5.3.1
529 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2529 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
530 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule530 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
531 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8531 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 532 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 533 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 534 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 535 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 536 package·install·aide
532 [[packages]] 
533 name·=·"aide" 
534 version·=·"*" 
535 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8537 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
536 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low538 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
537 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low539 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
538 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false540 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
539 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable541 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
540 #·Remediation·is·applicable·only·in·certain·platforms542 #·Remediation·is·applicable·only·in·certain·platforms
541 if·rpm·--quiet·-q·kernel;·then543 if·rpm·--quiet·-q·kernel;·then
Offset 584, 14 lines modifiedOffset 586, 26 lines modified
584 ··-·PCI-DSSv4-11.5.2586 ··-·PCI-DSSv4-11.5.2
585 ··-·enable_strategy587 ··-·enable_strategy
586 ··-·low_complexity588 ··-·low_complexity
587 ··-·low_disruption589 ··-·low_disruption
588 ··-·medium_severity590 ··-·medium_severity
589 ··-·no_reboot_needed591 ··-·no_reboot_needed
590 ··-·package_aide_installed592 ··-·package_aide_installed
 593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 594 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 595 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 596 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 597 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 598 package·--add=aide
 599 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 600 [[packages]]
 601 name·=·"aide"
 602 version·=·"*"
591 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8603 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
592 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low604 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
593 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low605 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
594 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false606 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
595 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable607 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
596 dnf·install·aide608 dnf·install·aide
Offset 603, 28 lines modifiedOffset 617, 14 lines modified
603 include·install_aide617 include·install_aide
  
604 class·install_aide·{618 class·install_aide·{
605 ··package·{·'aide':619 ··package·{·'aide':
606 ····ensure·=>·'installed',620 ····ensure·=>·'installed',
607 ··}621 ··}
608 }622 }
609 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
610 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
611 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
612 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
613 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
614 package·install·aide 
615 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
616 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
617 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
618 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
619 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
620 package·--add=aide 
621 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*623 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
622 Run·the·following·command·to·generate·a·new·database:624 Run·the·following·command·to·generate·a·new·database:
623 $·sudo·/usr/sbin/aide·--init625 $·sudo·/usr/sbin/aide·--init
624 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:626 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
625 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz627 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
626 To·initiate·a·manual·check,·run·the·following·command:628 To·initiate·a·manual·check,·run·the·following·command:
627 $·sudo·/usr/sbin/aide·--check629 $·sudo·/usr/sbin/aide·--check
Offset 987, 14 lines modifiedOffset 987, 39 lines modified
987 »       echo·"to·see·what·package·to·(re)install"·>&2987 »       echo·"to·see·what·package·to·(re)install"·>&2
  
988 »       false··#·end·with·an·error·code988 »       false··#·end·with·an·error·code
989 elif·test·"$rc"·!=·0;·then989 elif·test·"$rc"·!=·0;·then
990 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2990 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
991 »       false··#·end·with·an·error·code991 »       false··#·end·with·an·error·code
992 fi992 fi
 993 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 994 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 995 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 996 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 997 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 998 ---
 999 apiVersion:·machineconfiguration.openshift.io/v1
 1000 kind:·MachineConfig
 1001 spec:
 1002 ··config:
 1003 ····ignition:
 1004 ······version:·3.1.0
 1005 ····systemd:
 1006 ······units:
 1007 ········-·name:·configure-crypto-policy.service
 1008 ··········enabled:·true
 1009 ··········contents:·|
 1010 ············[Unit]
 1011 ············Before=kubelet.service
 1012 ············[Service]
 1013 ············Type=oneshot
 1014 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 1015 ············RemainAfterExit=yes
 1016 ············[Install]
 1017 ············WantedBy=multi-user.target
993 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81018 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
994 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1019 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
995 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1020 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
996 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1021 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
997 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict1022 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
998 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable1023 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
999 ··set_fact:1024 ··set_fact:
Offset 1043, 39 lines modifiedOffset 1068, 14 lines modified
1043 ··-·PCI-DSSv4-2.2.71068 ··-·PCI-DSSv4-2.2.7
1044 ··-·configure_crypto_policy1069 ··-·configure_crypto_policy
1045 ··-·high_severity1070 ··-·high_severity
1046 ··-·low_complexity1071 ··-·low_complexity
1047 ··-·low_disruption1072 ··-·low_disruption
1048 ··-·no_reboot_needed1073 ··-·no_reboot_needed
Max diff block lines reached; 236547/241404 bytes (97.99%) of diff not shown.
4.2 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-stig.html
    
Offset 15289, 284 lines modifiedOffset 15289, 284 lines modified
0003bb80:·2d74·6172·6765·743d·2223·6964·6d37·3939··-target="#idm7990003bb80:·2d74·6172·6765·743d·2223·6964·6d37·3939··-target="#idm799
0003bb90:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·0003bb90:·3022·2074·6162·696e·6465·783d·2230·2220··0"·tabindex="0"·
0003bba0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003bba0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003bbb0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003bbb0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003bbc0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003bbc0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003bbd0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003bbd0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003bbe0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003bbe0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003bbf0:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
0003bc00:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
0003bc10:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003bc20:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003bc30:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003bc40:·643d·2269·646d·3739·3930·223e·3c70·7265··d="idm7990"><pre 
0003bc50:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
0003bc60:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
0003bc70:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
0003bc80:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003bc90:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003bca0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003bcb0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003bcc0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003bcd0:·743d·2223·6964·6d37·3939·3122·2074·6162··t="#idm7991"·tab 
0003bce0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003bcf0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003bd00:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003bd10:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003bd20:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003bd30:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
0003bd40:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<0003bbf0:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...<
0003bd50:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas0003bc00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
0003bd60:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps0003bc10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
0003bd70:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="0003bc20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
0003bd80:·6964·6d37·3939·3122·3e3c·7461·626c·6520··idm7991"><table·0003bc30:·6964·6d37·3939·3022·3e3c·7461·626c·6520··idm7990"><table·
0003bd90:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab0003bc40:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
0003bda0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table0003bc50:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
0003bdb0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-0003bc60:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
0003bdc0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><0003bc70:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
0003bdd0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</0003bc80:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
0003bde0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><0003bc90:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
0003bdf0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
0003be00:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
0003be10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003be20:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
0003be30:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
0003be40:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
0003be50:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
0003be60:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
0003be70:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
0003be80:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
0003be90:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
0003bea0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
0003beb0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·-- 
0003bec0:·7175·6965·7420·2d71·206b·6572·6e65·6c3b··quiet·-q·kernel; 
0003bed0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
0003bee0:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
0003bef0:·2220·3b20·7468·656e·0a20·2020·2079·756d··"·;·then.····yum 
0003bf00:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
0003bf10:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
0003bf20:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
0003bf30:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
0003bf40:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
0003bf50:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
0003bf60:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
0003bf70:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003bf80:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003bf90:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003bfa0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003bfb0:·6172·6765·743d·2223·6964·6d37·3939·3222··arget="#idm7992" 
0003bfc0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003bfd0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003bfe0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003bff0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003c000:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003c010:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003c020:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
0003c030:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003c040:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003c050:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003c060:·6522·2069·643d·2269·646d·3739·3932·223e··e"·id="idm7992"> 
0003c070:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
0003c080:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
0003c090:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
0003c0a0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
0003c0b0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
0003c0c0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
0003c0d0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003c0e0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003c0f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003c100:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003c110:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003c120:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003c130:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003c140:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003c150:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003c160:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:· 
0003c170:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa 
0003c180:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa 
0003c190:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma 
0003c1a0:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta 
0003c1b0:·6773·3a0a·2020·2d20·4343·452d·3830·3834··gs:.··-·CCE-8084 
0003c1c0:·342d·340a·2020·2d20·434a·4953·2d35·2e31··4-4.··-·CJIS-5.1 
0003c1d0:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S 
0003c1e0:·5449·472d·5248·454c·2d30·382d·3031·3033··TIG-RHEL-08-0103 
0003c1f0:·3539·0a20·202d·204e·4953·542d·3830·302d··59.··-·NIST-800- 
0003c200:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
0003c210:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
0003c220:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
0003c230:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
0003c240:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
0003c250:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
0003c260:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
0003c270:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
0003c280:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
0003c290:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
0003c2a0:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
0003c2b0:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu 
0003c2c0:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
0003c2d0:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
0003c2e0:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
0003c2f0:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
0003c300:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern 
0003c310:·656c·2220·696e·2061·6e73·6962·6c65·5f66··el"·in·ansible_f 
0003c320:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
0003c330:·2074·6167·733a·0a20·202d·2043·4345·2d38···tags:.··-·CCE-8 
0003c340:·3038·3434·2d34·0a20·202d·2043·4a49·532d··0844-4.··-·CJIS- 
0003c350:·352e·3130·2e31·2e33·0a20·202d·2044·4953··5.10.1.3.··-·DIS 
0003c360:·412d·5354·4947·2d52·4845·4c2d·3038·2d30··A-STIG-RHEL-08-0 
Max diff block lines reached; 3956164/3994004 bytes (99.05%) of diff not shown.
396 KB
html2text {}
    
Offset 120, 19 lines modifiedOffset 120, 21 lines modified
120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5120 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
121 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199121 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
122 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359122 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
123 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79123 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
124 ·············_\x8c_\x8i_\x8s············5.3.1124 ·············_\x8c_\x8i_\x8s············5.3.1
125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
126 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule126 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 132 package·install·aide
128 [[packages]] 
129 name·=·"aide" 
130 version·=·"*" 
131 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
132 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
133 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
134 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
135 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
136 #·Remediation·is·applicable·only·in·certain·platforms138 #·Remediation·is·applicable·only·in·certain·platforms
137 if·rpm·--quiet·-q·kernel;·then139 if·rpm·--quiet·-q·kernel;·then
Offset 180, 14 lines modifiedOffset 182, 26 lines modified
180 ··-·PCI-DSSv4-11.5.2182 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy183 ··-·enable_strategy
182 ··-·low_complexity184 ··-·low_complexity
183 ··-·low_disruption185 ··-·low_disruption
184 ··-·medium_severity186 ··-·medium_severity
185 ··-·no_reboot_needed187 ··-·no_reboot_needed
186 ··-·package_aide_installed188 ··-·package_aide_installed
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 194 package·--add=aide
 195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 196 [[packages]]
 197 name·=·"aide"
 198 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
192 dnf·install·aide204 dnf·install·aide
Offset 199, 28 lines modifiedOffset 213, 14 lines modified
199 include·install_aide213 include·install_aide
  
200 class·install_aide·{214 class·install_aide·{
201 ··package·{·'aide':215 ··package·{·'aide':
202 ····ensure·=>·'installed',216 ····ensure·=>·'installed',
203 ··}217 ··}
204 }218 }
205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
206 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
207 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
208 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
209 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
210 package·install·aide 
211 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
212 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
213 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
214 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
215 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
216 package·--add=aide 
217 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*219 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
218 Run·the·following·command·to·generate·a·new·database:220 Run·the·following·command·to·generate·a·new·database:
219 $·sudo·/usr/sbin/aide·--init221 $·sudo·/usr/sbin/aide·--init
220 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:222 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
221 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz223 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
222 To·initiate·a·manual·check,·run·the·following·command:224 To·initiate·a·manual·check,·run·the·following·command:
223 $·sudo·/usr/sbin/aide·--check225 $·sudo·/usr/sbin/aide·--check
Offset 1803, 31 lines modifiedOffset 1803, 31 lines modified
1803 ·············_\x8i_\x8s_\x8m······14461803 ·············_\x8i_\x8s_\x8m······1446
1804 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11804 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1805 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121805 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1806 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11806 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1807 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761807 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1808 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-0100201808 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020
1809 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule1809 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
1810 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1811 [customizations] 
1812 fips·=·true 
1813 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81810 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1814 #·Remediation·is·applicable·only·in·certain·platforms1811 #·Remediation·is·applicable·only·in·certain·platforms
1815 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then1812 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
1816 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1813 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1817 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1814 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1818 kargs·=·["fips=1"]1815 kargs·=·["fips=1"]
1819 EOF1816 EOF
1820 fi1817 fi
  
1821 else1818 else
1822 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1819 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1823 fi1820 fi
 1821 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1822 [customizations]
 1823 fips·=·true
1824 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1824 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1825 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·8·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1825 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·8·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1826 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1826 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1827 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1827 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1828 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1828 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
1829 Severity: ···high1829 Severity: ···high
1830 Rule·ID:·····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled1830 Rule·ID:·····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled
Offset 1998, 14 lines modifiedOffset 1998, 39 lines modified
1998 »       echo·"to·see·what·package·to·(re)install"·>&21998 »       echo·"to·see·what·package·to·(re)install"·>&2
  
1999 »       false··#·end·with·an·error·code1999 »       false··#·end·with·an·error·code
2000 elif·test·"$rc"·!=·0;·then2000 elif·test·"$rc"·!=·0;·then
2001 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&22001 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
2002 »       false··#·end·with·an·error·code2002 »       false··#·end·with·an·error·code
2003 fi2003 fi
 2004 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2005 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2006 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 397086/405441 bytes (97.94%) of diff not shown.
4.13 MB
./usr/share/doc/ssg-nondebian/ssg-rhel8-guide-stig_gui.html
    
Offset 15308, 284 lines modifiedOffset 15308, 284 lines modified
0003bcb0:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm790003bcb0:·612d·7461·7267·6574·3d22·2369·646d·3739··a-target="#idm79
0003bcc0:·3930·2220·7461·6269·6e64·6578·3d22·3022··90"·tabindex="0"0003bcc0:·3930·2220·7461·6269·6e64·6578·3d22·3022··90"·tabindex="0"
0003bcd0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003bcd0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
0003bce0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003bce0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
0003bcf0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003bcf0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
0003bd00:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003bd00:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
0003bd10:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003bd10:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
0003bd20:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
0003bd30:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
0003bd40:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
0003bd50:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
0003bd60:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
0003bd70:·6964·3d22·6964·6d37·3939·3022·3e3c·7072··id="idm7990"><pr 
0003bd80:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa 
0003bd90:·6765·735d·5d0a·6e61·6d65·203d·2022·6169··ges]].name·=·"ai 
0003bda0:·6465·220a·7665·7273·696f·6e20·3d20·222a··de".version·=·"* 
0003bdb0:·220a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··".</code></pre>< 
0003bdc0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
0003bdd0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
0003bde0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
0003bdf0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
0003be00:·6574·3d22·2369·646d·3739·3931·2220·7461··et="#idm7991"·ta 
0003be10:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
0003be20:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
0003be30:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
0003be40:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
0003be50:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
0003be60:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation· 
0003be70:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...0003bd20:·6174·696f·6e20·7363·7269·7074·20e2·87b2··ation·script·...
0003be80:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003bd30:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
0003be90:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003bd40:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
0003bea0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003bd50:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
0003beb0:·2269·646d·3739·3931·223e·3c74·6162·6c65··"idm7991"><table0003bd60:·2269·646d·3739·3930·223e·3c74·6162·6c65··"idm7990"><table
0003bec0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta0003bd70:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
0003bed0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl0003bd80:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
0003bee0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table0003bd90:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
0003bef0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>0003bda0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
0003bf00:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<0003bdb0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
0003bf10:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>0003bdc0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
0003bf20:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis0003bdd0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
0003bf30:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td0003bde0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003bf40:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t0003bdf0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
0003bf50:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t0003be00:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
0003bf60:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>0003be10:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
0003bf70:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str0003be20:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
0003bf80:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e0003be30:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
0003bf90:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><0003be40:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
0003bfa0:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod0003be50:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
0003bfb0:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation· 
0003bfc0:·6973·2061·7070·6c69·6361·626c·6520·6f6e··is·applicable·on 
0003bfd0:·6c79·2069·6e20·6365·7274·6169·6e20·706c··ly·in·certain·pl 
0003bfe0:·6174·666f·726d·730a·6966·2072·706d·202d··atforms.if·rpm·- 
0003bff0:·2d71·7569·6574·202d·7120·6b65·726e·656c··-quiet·-q·kernel 
0003c000:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm 
0003c010:·202d·7120·2d2d·7175·6965·7420·2261·6964···-q·--quiet·"aid 
0003c020:·6522·203b·2074·6865·6e0a·2020·2020·7975··e"·;·then.····yu 
0003c030:·6d20·696e·7374·616c·6c20·2d79·2022·6169··m·install·-y·"ai 
0003c040:·6465·220a·6669·0a0a·656c·7365·0a20·2020··de".fi..else.··· 
0003c050:·2026·6774·3b26·616d·703b·3220·6563·686f···&gt;&amp;2·echo 
0003c060:·2027·5265·6d65·6469·6174·696f·6e20·6973···'Remediation·is 
0003c070:·206e·6f74·2061·7070·6c69·6361·626c·652c···not·applicable, 
0003c080:·206e·6f74·6869·6e67·2077·6173·2064·6f6e···nothing·was·don 
0003c090:·6527·0a66·690a·3c2f·636f·6465·3e3c·2f70··e'.fi.</code></p 
0003c0a0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003c0b0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003c0c0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003c0d0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003c0e0:·7461·7267·6574·3d22·2369·646d·3739·3932··target="#idm7992 
0003c0f0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003c100:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003c110:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003c120:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003c130:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003c140:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003c150:·696f·6e20·416e·7369·626c·6520·736e·6970··ion·Ansible·snip 
0003c160:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003c170:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c180:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c190:·7365·2220·6964·3d22·6964·6d37·3939·3222··se"·id="idm7992" 
0003c1a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
0003c1b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
0003c1c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
0003c1d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
0003c1e0:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003c1f0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003c200:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003c210:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003c220:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003c230:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003c240:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003c250:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003c260:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003c270:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003c280:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003c290:·7265·3e3c·636f·6465·3e2d·206e·616d·653a··re><code>-·name: 
0003c2a0:·2047·6174·6865·7220·7468·6520·7061·636b···Gather·the·pack 
0003c2b0:·6167·6520·6661·6374·730a·2020·7061·636b··age·facts.··pack 
0003c2c0:·6167·655f·6661·6374·733a·0a20·2020·206d··age_facts:.····m 
0003c2d0:·616e·6167·6572·3a20·6175·746f·0a20·2074··anager:·auto.··t 
0003c2e0:·6167·733a·0a20·202d·2043·4345·2d38·3038··ags:.··-·CCE-808 
0003c2f0:·3434·2d34·0a20·202d·2043·4a49·532d·352e··44-4.··-·CJIS-5. 
0003c300:·3130·2e31·2e33·0a20·202d·2044·4953·412d··10.1.3.··-·DISA- 
0003c310:·5354·4947·2d52·4845·4c2d·3038·2d30·3130··STIG-RHEL-08-010 
0003c320:·3335·390a·2020·2d20·4e49·5354·2d38·3030··359.··-·NIST-800 
0003c330:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-· 
0003c340:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.5 
0003c350:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1 
0003c360:·312e·352e·320a·2020·2d20·656e·6162·6c65··1.5.2.··-·enable 
0003c370:·5f73·7472·6174·6567·790a·2020·2d20·6c6f··_strategy.··-·lo 
0003c380:·775f·636f·6d70·6c65·7869·7479·0a20·202d··w_complexity.··- 
0003c390:·206c·6f77·5f64·6973·7275·7074·696f·6e0a···low_disruption. 
0003c3a0:·2020·2d20·6d65·6469·756d·5f73·6576·6572····-·medium_sever 
0003c3b0:·6974·790a·2020·2d20·6e6f·5f72·6562·6f6f··ity.··-·no_reboo 
0003c3c0:·745f·6e65·6564·6564·0a20·202d·2070·6163··t_needed.··-·pac 
0003c3d0:·6b61·6765·5f61·6964·655f·696e·7374·616c··kage_aide_instal 
0003c3e0:·6c65·640a·0a2d·206e·616d·653a·2045·6e73··led..-·name:·Ens 
0003c3f0:·7572·6520·6169·6465·2069·7320·696e·7374··ure·aide·is·inst 
0003c400:·616c·6c65·640a·2020·7061·636b·6167·653a··alled.··package: 
0003c410:·0a20·2020·206e·616d·653a·2061·6964·650a··.····name:·aide. 
0003c420:·2020·2020·7374·6174·653a·2070·7265·7365······state:·prese 
0003c430:·6e74·0a20·2077·6865·6e3a·2027·226b·6572··nt.··when:·'"ker 
0003c440:·6e65·6c22·2069·6e20·616e·7369·626c·655f··nel"·in·ansible_ 
0003c450:·6661·6374·732e·7061·636b·6167·6573·270a··facts.packages'. 
0003c460:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE- 
0003c470:·3830·3834·342d·340a·2020·2d20·434a·4953··80844-4.··-·CJIS 
0003c480:·2d35·2e31·302e·312e·330a·2020·2d20·4449··-5.10.1.3.··-·DI 
0003c490:·5341·2d53·5449·472d·5248·454c·2d30·382d··SA-STIG-RHEL-08- 
Max diff block lines reached; 3896835/3934675 bytes (99.04%) of diff not shown.
391 KB
html2text {}
    
Offset 125, 19 lines modifiedOffset 125, 21 lines modified
125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
127 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359127 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-08-010359
128 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79128 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
129 ·············_\x8c_\x8i_\x8s············5.3.1129 ·············_\x8c_\x8i_\x8s············5.3.1
130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
131 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule131 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-251710r958944_rule
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 137 package·install·aide
133 [[packages]] 
134 name·=·"aide" 
135 version·=·"*" 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 #·Remediation·is·applicable·only·in·certain·platforms143 #·Remediation·is·applicable·only·in·certain·platforms
142 if·rpm·--quiet·-q·kernel;·then144 if·rpm·--quiet·-q·kernel;·then
Offset 185, 14 lines modifiedOffset 187, 26 lines modified
185 ··-·PCI-DSSv4-11.5.2187 ··-·PCI-DSSv4-11.5.2
186 ··-·enable_strategy188 ··-·enable_strategy
187 ··-·low_complexity189 ··-·low_complexity
188 ··-·low_disruption190 ··-·low_disruption
189 ··-·medium_severity191 ··-·medium_severity
190 ··-·no_reboot_needed192 ··-·no_reboot_needed
191 ··-·package_aide_installed193 ··-·package_aide_installed
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 199 package·--add=aide
 200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 201 [[packages]]
 202 name·=·"aide"
 203 version·=·"*"
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
197 dnf·install·aide209 dnf·install·aide
Offset 204, 28 lines modifiedOffset 218, 14 lines modified
204 include·install_aide218 include·install_aide
  
205 class·install_aide·{219 class·install_aide·{
206 ··package·{·'aide':220 ··package·{·'aide':
207 ····ensure·=>·'installed',221 ····ensure·=>·'installed',
208 ··}222 ··}
209 }223 }
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
215 package·install·aide 
216 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
217 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
218 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
219 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
220 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
221 package·--add=aide 
222 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*224 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
223 Run·the·following·command·to·generate·a·new·database:225 Run·the·following·command·to·generate·a·new·database:
224 $·sudo·/usr/sbin/aide·--init226 $·sudo·/usr/sbin/aide·--init
225 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:227 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
226 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz228 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
227 To·initiate·a·manual·check,·run·the·following·command:229 To·initiate·a·manual·check,·run·the·following·command:
228 $·sudo·/usr/sbin/aide·--check230 $·sudo·/usr/sbin/aide·--check
Offset 1808, 31 lines modifiedOffset 1808, 31 lines modified
1808 ·············_\x8i_\x8s_\x8m······14461808 ·············_\x8i_\x8s_\x8m······1446
1809 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11809 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1810 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121810 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1811 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11811 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1812 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761812 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1813 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-0100201813 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-08-010020
1814 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule1814 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-230223r1017042_rule
1815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1816 [customizations] 
1817 fips·=·true 
1818 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1819 #·Remediation·is·applicable·only·in·certain·platforms1816 #·Remediation·is·applicable·only·in·certain·platforms
1820 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then1817 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
1821 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1818 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1822 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1819 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1823 kargs·=·["fips=1"]1820 kargs·=·["fips=1"]
1824 EOF1821 EOF
1825 fi1822 fi
  
1826 else1823 else
1827 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1824 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1828 fi1825 fi
 1826 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1827 [customizations]
 1828 fips·=·true
1829 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1829 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·S\x8Se\x8et\x8t·k\x8ke\x8er\x8rn\x8ne\x8el\x8l·p\x8pa\x8ar\x8ra\x8am\x8me\x8et\x8te\x8er\x8r·'\x8'c\x8cr\x8ry\x8yp\x8pt\x8to\x8o.\x8.f\x8fi\x8ip\x8ps\x8s_\x8_e\x8en\x8na\x8ab\x8bl\x8le\x8ed\x8d'\x8'·t\x8to\x8o·1\x81·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1830 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·8·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.1830 System·running·in·FIPS·mode·is·indicated·by·kernel·parameter·'crypto.fips_enabled'.·This·parameter·should·be·set·to·1·in·FIPS·mode.·Red·Hat·Enterprise·Linux·8·has·an·installation-time·kernel·flag·that·can·enable·FIPS·mode.·The·installer·must·be·booted·with·fips=1·for·the·system·to·have·FIPS·mode·enabled.·Enabling·FIPS·mode·on·a·preexisting·system·is·not·supported.·If·this·rule·fails·on·an·installed·system,·then·this·is·a·permanent·finding·and·cannot·be·fixed.·To·enable·strict·FIPS·compliance,·the·fips=1·kernel·option·needs·to·be·added·to·the·kernel·boot·parameters·during·system·installation·so·key·generation·is·done·with·FIPS-approved·algorithms·and·continuous·monitoring·tests·in·place.
1831 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.1831 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
1832 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.1832 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
1833 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.1833 Rationale:···Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.·The·operating·system·must·implement·cryptographic·modules·adhering·to·the·higher·standards·approved·by·the·federal·government·since·this·provides·assurance·they·have·been·tested·and·validated.
1834 Severity: ···high1834 Severity: ···high
1835 Rule·ID:·····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled1835 Rule·ID:·····xccdf_org.ssgproject.content_rule_sysctl_crypto_fips_enabled
Offset 2003, 14 lines modifiedOffset 2003, 39 lines modified
2003 »       echo·"to·see·what·package·to·(re)install"·>&22003 »       echo·"to·see·what·package·to·(re)install"·>&2
  
2004 »       false··#·end·with·an·error·code2004 »       false··#·end·with·an·error·code
2005 elif·test·"$rc"·!=·0;·then2005 elif·test·"$rc"·!=·0;·then
2006 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&22006 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
2007 »       false··#·end·with·an·error·code2007 »       false··#·end·with·an·error·code
2008 fi2008 fi
 2009 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2010 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2011 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 391789/400144 bytes (97.91%) of diff not shown.
3.11 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_enhanced.html
    
Offset 15108, 284 lines modifiedOffset 15108, 284 lines modified
0003b030:·6574·3d22·2369·646d·3834·3538·2220·7461··et="#idm8458"·ta0003b030:·6574·3d22·2369·646d·3834·3538·2220·7461··et="#idm8458"·ta
0003b040:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b040:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b050:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b050:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b060:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b060:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b070:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b070:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b080:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b080:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b090:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b090:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b0a0:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003b0b0:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003b0c0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b0d0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b0e0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b0f0:·6d38·3435·3822·3e3c·7072·653e·3c63·6f64··m8458"><pre><cod 
0003b100:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003b110:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003b120:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003b130:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b140:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b150:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b160:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b170:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b180:·646d·3834·3539·2220·7461·6269·6e64·6578··dm8459"·tabindex 
0003b190:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b1a0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b1b0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b1c0:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b1d0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b1e0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b1f0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b0003b0a0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
0003b200:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003b0b0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b210:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003b0c0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b220:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm840003b0d0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
0003b230:·3539·223e·3c74·6162·6c65·2063·6c61·7373··59"><table·class0003b0e0:·3538·223e·3c74·6162·6c65·2063·6c61·7373··58"><table·class
0003b240:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003b0f0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b250:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003b100:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b260:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003b110:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b270:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003b120:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b280:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003b130:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b290:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b140:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b2a0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b150:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b2b0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003b160:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b2c0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b170:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b2d0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003b180:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b2e0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b190:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003b2f0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
0003b300:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
0003b310:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
0003b320:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
0003b330:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b340:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b350:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b360:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
0003b370:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
0003b380:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b390:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b3a0:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
0003b3b0:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b3c0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b3d0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b3e0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b3f0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b400:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b410:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b420:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b430:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b440:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b450:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b460:·3d22·2369·646d·3834·3630·2220·7461·6269··="#idm8460"·tabi 
0003b470:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b480:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b490:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b4a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b4b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b4c0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An 
0003b4d0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b4e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b4f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b500:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b510:·3d22·6964·6d38·3436·3022·3e3c·7461·626c··="idm8460"><tabl 
0003b520:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b530:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b540:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b550:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b560:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b570:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b580:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b590:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b5a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b5b0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b5c0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b5d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b5e0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b5f0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b600:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b610:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
0003b620:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
0003b630:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
0003b640:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
0003b650:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
0003b660:·202d·2043·4345·2d39·3038·3433·2d34·0a20···-·CCE-90843-4.· 
0003b670:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003b680:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R 
0003b690:·4845·4c2d·3039·2d36·3531·3031·300a·2020··HEL-09-651010.·· 
0003b6a0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
0003b6b0:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
0003b6c0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
0003b6d0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
0003b6e0:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
0003b6f0:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
0003b700:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d 
0003b710:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me 
0003b720:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.·· 
0003b730:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need 
0003b740:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a 
0003b750:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..- 
0003b760:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai 
0003b770:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed. 
0003b780:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n 
0003b790:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st 
0003b7a0:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w 
0003b7b0:·6865·6e3a·2027·226b·6572·6e65·6c22·2069··hen:·'"kernel"·i 
0003b7c0:·6e20·616e·7369·626c·655f·6661·6374·732e··n·ansible_facts. 
0003b7d0:·7061·636b·6167·6573·270a·2020·7461·6773··packages'.··tags 
0003b7e0:·3a0a·2020·2d20·4343·452d·3930·3834·332d··:.··-·CCE-90843- 
0003b7f0:·340a·2020·2d20·434a·4953·2d35·2e31·302e··4.··-·CJIS-5.10. 
0003b800:·312e·330a·2020·2d20·4449·5341·2d53·5449··1.3.··-·DISA-STI 
0003b810:·472d·5248·454c·2d30·392d·3635·3130·3130··G-RHEL-09-651010 
Max diff block lines reached; 2989343/3027183 bytes (98.75%) of diff not shown.
226 KB
html2text {}
    
Offset 103, 19 lines modifiedOffset 103, 21 lines modified
103 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5103 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
104 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199104 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
105 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79105 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
106 ·············_\x8c_\x8i_\x8s············6.1.1106 ·············_\x8c_\x8i_\x8s············6.1.1
107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2107 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
108 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010108 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
109 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule109 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8110 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 111 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 112 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 113 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 114 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 115 package·install·aide
111 [[packages]] 
112 name·=·"aide" 
113 version·=·"*" 
114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
119 #·Remediation·is·applicable·only·in·certain·platforms121 #·Remediation·is·applicable·only·in·certain·platforms
120 if·rpm·--quiet·-q·kernel;·then122 if·rpm·--quiet·-q·kernel;·then
Offset 163, 14 lines modifiedOffset 165, 26 lines modified
163 ··-·PCI-DSSv4-11.5.2165 ··-·PCI-DSSv4-11.5.2
164 ··-·enable_strategy166 ··-·enable_strategy
165 ··-·low_complexity167 ··-·low_complexity
166 ··-·low_disruption168 ··-·low_disruption
167 ··-·medium_severity169 ··-·medium_severity
168 ··-·no_reboot_needed170 ··-·no_reboot_needed
169 ··-·package_aide_installed171 ··-·package_aide_installed
 172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 177 package·--add=aide
 178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 179 [[packages]]
 180 name·=·"aide"
 181 version·=·"*"
170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
175 dnf·install·aide187 dnf·install·aide
Offset 182, 28 lines modifiedOffset 196, 14 lines modified
182 include·install_aide196 include·install_aide
  
183 class·install_aide·{197 class·install_aide·{
184 ··package·{·'aide':198 ··package·{·'aide':
185 ····ensure·=>·'installed',199 ····ensure·=>·'installed',
186 ··}200 ··}
187 }201 }
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
193 package·install·aide 
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
199 package·--add=aide 
200 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
201 Run·the·following·command·to·generate·a·new·database:203 Run·the·following·command·to·generate·a·new·database:
202 $·sudo·/usr/sbin/aide·--init204 $·sudo·/usr/sbin/aide·--init
203 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:205 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
204 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz206 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
205 To·initiate·a·manual·check,·run·the·following·command:207 To·initiate·a·manual·check,·run·the·following·command:
206 $·sudo·/usr/sbin/aide·--check208 $·sudo·/usr/sbin/aide·--check
Offset 363, 51 lines modifiedOffset 363, 51 lines modified
363 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)363 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
364 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4364 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
365 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227365 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
366 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28366 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
367 ·············_\x8c_\x8i_\x8s············1.1.2.3.1367 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
368 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010368 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010
369 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule369 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
370 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
371 [[customizations.filesystem]] 
372 mountpoint·=·"/home" 
373 size·=·1073741824 
374 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8370 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
375 logvol·/home·1024371 logvol·/home·1024
376 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8372 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
377 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low373 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
378 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high374 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
379 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false375 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
380 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable376 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
381 part·/home377 part·/home
 378 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 379 [[customizations.filesystem]]
 380 mountpoint·=·"/home"
 381 size·=·1073741824
382 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*382 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
383 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.383 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
384 Rationale:···Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.384 Rationale:···Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
385 Severity: ···unknown385 Severity: ···unknown
386 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv386 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv
387 Identifiers:·CCE-90846-7387 Identifiers:·CCE-90846-7
388 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28388 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
390 [[customizations.filesystem]] 
391 mountpoint·=·"/srv" 
392 size·=·1073741824 
393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
394 logvol·/srv·1024390 logvol·/srv·1024
395 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
396 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low392 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
397 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high393 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
398 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false394 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 225962/231882 bytes (97.45%) of diff not shown.
3.22 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_high.html
    
Offset 15113, 284 lines modifiedOffset 15113, 284 lines modified
0003b080:·6172·6765·743d·2223·6964·6d38·3435·3822··arget="#idm8458"0003b080:·6172·6765·743d·2223·6964·6d38·3435·3822··arget="#idm8458"
0003b090:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b090:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b0a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b0a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b0b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b0b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b0c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b0c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b0d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b0d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b0e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b0e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003b0f0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003b100:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003b110:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b120:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b130:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b140:·2269·646d·3834·3538·223e·3c70·7265·3e3c··"idm8458"><pre>< 
0003b150:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003b160:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003b170:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003b180:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b190:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b1a0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b1b0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b1c0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b1d0:·2223·6964·6d38·3435·3922·2074·6162·696e··"#idm8459"·tabin 
0003b1e0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b1f0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b200:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b210:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b220:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b230:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b240:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a0003b0f0:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a
0003b250:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b100:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b260:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b110:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b270:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b120:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b280:·6d38·3435·3922·3e3c·7461·626c·6520·636c··m8459"><table·cl0003b130:·6d38·3435·3822·3e3c·7461·626c·6520·636c··m8458"><table·cl
0003b290:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b140:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b2a0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b150:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b2b0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b160:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b2c0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b170:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b2d0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b180:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b2e0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b190:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b2f0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b300:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003b310:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b320:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003b330:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003b340:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
0003b350:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
0003b360:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003b370:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
0003b380:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b390:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b3a0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b3b0:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu 
0003b3c0:·6965·7420·2d71·206b·6572·6e65·6c3b·2074··iet·-q·kernel;·t 
0003b3d0:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q 
0003b3e0:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"· 
0003b3f0:·3b20·7468·656e·0a20·2020·2064·6e66·2069··;·then.····dnf·i 
0003b400:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003b410:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g 
0003b420:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003b430:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003b440:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003b450:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003b460:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre> 
0003b470:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003b480:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003b490:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003b4a0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003b4b0:·6765·743d·2223·6964·6d38·3436·3022·2074··get="#idm8460"·t 
0003b4c0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
0003b4d0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
0003b4e0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
0003b4f0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
0003b500:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
0003b510:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
0003b520:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003b530:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b540:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b550:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b560:·2069·643d·2269·646d·3834·3630·223e·3c74···id="idm8460"><t 
0003b570:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b580:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b590:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b5a0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b5b0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b5c0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b5d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b5e0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b5f0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b600:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b610:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false< 
0003b620:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b630:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th>< 
0003b640:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></ 
0003b650:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre> 
0003b660:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4761··<code>-·name:·Ga 
0003b670:·7468·6572·2074·6865·2070·6163·6b61·6765··ther·the·package 
0003b680:·2066·6163·7473·0a20·2070·6163·6b61·6765···facts.··package 
0003b690:·5f66·6163·7473·3a0a·2020·2020·6d61·6e61··_facts:.····mana 
0003b6a0:·6765·723a·2061·7574·6f0a·2020·7461·6773··ger:·auto.··tags 
0003b6b0:·3a0a·2020·2d20·4343·452d·3930·3834·332d··:.··-·CCE-90843- 
0003b6c0:·340a·2020·2d20·434a·4953·2d35·2e31·302e··4.··-·CJIS-5.10. 
0003b6d0:·312e·330a·2020·2d20·4449·5341·2d53·5449··1.3.··-·DISA-STI 
0003b6e0:·472d·5248·454c·2d30·392d·3635·3130·3130··G-RHEL-09-651010 
0003b6f0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
0003b700:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI 
0003b710:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.·· 
0003b720:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5 
0003b730:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st 
0003b740:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c 
0003b750:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo 
0003b760:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··- 
0003b770:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity 
0003b780:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n 
0003b790:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag 
0003b7a0:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed 
0003b7b0:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure 
0003b7c0:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install 
0003b7d0:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.·· 
0003b7e0:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.··· 
0003b7f0:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present. 
0003b800:·2020·7768·656e·3a20·2722·6b65·726e·656c····when:·'"kernel 
0003b810:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac 
0003b820:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t 
0003b830:·6167·733a·0a20·202d·2043·4345·2d39·3038··ags:.··-·CCE-908 
0003b840:·3433·2d34·0a20·202d·2043·4a49·532d·352e··43-4.··-·CJIS-5. 
0003b850:·3130·2e31·2e33·0a20·202d·2044·4953·412d··10.1.3.··-·DISA- 
0003b860:·5354·4947·2d52·4845·4c2d·3039·2d36·3531··STIG-RHEL-09-651 
Max diff block lines reached; 3101304/3139144 bytes (98.79%) of diff not shown.
235 KB
html2text {}
    
Offset 104, 19 lines modifiedOffset 104, 21 lines modified
104 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5104 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
105 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199105 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
106 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79106 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
107 ·············_\x8c_\x8i_\x8s············6.1.1107 ·············_\x8c_\x8i_\x8s············6.1.1
108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2108 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
109 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010109 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
110 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule110 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 116 package·install·aide
112 [[packages]] 
113 name·=·"aide" 
114 version·=·"*" 
115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
120 #·Remediation·is·applicable·only·in·certain·platforms122 #·Remediation·is·applicable·only·in·certain·platforms
121 if·rpm·--quiet·-q·kernel;·then123 if·rpm·--quiet·-q·kernel;·then
Offset 164, 14 lines modifiedOffset 166, 26 lines modified
164 ··-·PCI-DSSv4-11.5.2166 ··-·PCI-DSSv4-11.5.2
165 ··-·enable_strategy167 ··-·enable_strategy
166 ··-·low_complexity168 ··-·low_complexity
167 ··-·low_disruption169 ··-·low_disruption
168 ··-·medium_severity170 ··-·medium_severity
169 ··-·no_reboot_needed171 ··-·no_reboot_needed
170 ··-·package_aide_installed172 ··-·package_aide_installed
 173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 178 package·--add=aide
 179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 180 [[packages]]
 181 name·=·"aide"
 182 version·=·"*"
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
176 dnf·install·aide188 dnf·install·aide
Offset 183, 28 lines modifiedOffset 197, 14 lines modified
183 include·install_aide197 include·install_aide
  
184 class·install_aide·{198 class·install_aide·{
185 ··package·{·'aide':199 ··package·{·'aide':
186 ····ensure·=>·'installed',200 ····ensure·=>·'installed',
187 ··}201 ··}
188 }202 }
189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
194 package·install·aide 
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
200 package·--add=aide 
201 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
202 Run·the·following·command·to·generate·a·new·database:204 Run·the·following·command·to·generate·a·new·database:
203 $·sudo·/usr/sbin/aide·--init205 $·sudo·/usr/sbin/aide·--init
204 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:206 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
205 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz207 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
206 To·initiate·a·manual·check,·run·the·following·command:208 To·initiate·a·manual·check,·run·the·following·command:
207 $·sudo·/usr/sbin/aide·--check209 $·sudo·/usr/sbin/aide·--check
Offset 899, 51 lines modifiedOffset 899, 51 lines modified
899 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)899 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
900 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4900 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
901 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227901 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
902 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28902 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
903 ·············_\x8c_\x8i_\x8s············1.1.2.3.1903 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
904 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010904 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010
905 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule905 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
907 [[customizations.filesystem]] 
908 mountpoint·=·"/home" 
909 size·=·1073741824 
910 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8906 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
911 logvol·/home·1024907 logvol·/home·1024
912 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8908 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
913 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low909 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
914 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high910 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
915 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false911 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
916 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable912 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
917 part·/home913 part·/home
 914 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 915 [[customizations.filesystem]]
 916 mountpoint·=·"/home"
 917 size·=·1073741824
918 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*918 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
919 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.919 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at·installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such·as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the·mountpoint·can·instead·be·configured·later.
920 Rationale:···Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.920 Rationale:···Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is·mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and·also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data·storage.
921 Severity: ···unknown921 Severity: ···unknown
922 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv922 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv
923 Identifiers:·CCE-90846-7923 Identifiers:·CCE-90846-7
924 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28924 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
926 [[customizations.filesystem]] 
927 mountpoint·=·"/srv" 
928 size·=·1073741824 
929 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8925 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
930 logvol·/srv·1024926 logvol·/srv·1024
931 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8927 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
932 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low928 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
933 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high929 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
934 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false930 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
Max diff block lines reached; 234374/240294 bytes (97.54%) of diff not shown.
1.9 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_intermediary.html
    
Offset 15103, 285 lines modifiedOffset 15103, 285 lines modified
0003afe0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003afe0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003aff0:·2223·6964·6d38·3435·3822·2074·6162·696e··"#idm8458"·tabin0003aff0:·2223·6964·6d38·3435·3822·2074·6162·696e··"#idm8458"·tabin
0003b000:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b000:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b010:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b010:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b020:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b020:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b030:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b030:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b040:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b040:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b050:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003b050:·3e52·656d·6564·6961·7469·6f6e·2073·6372··>Remediation·scr
0003b060:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003b070:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b080:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b090:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b0a0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84 
0003b0b0:·3538·223e·3c70·7265·3e3c·636f·6465·3e0a··58"><pre><code>. 
0003b0c0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003b0d0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003b0e0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
0003b0f0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
0003b100:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
0003b110:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
0003b120:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
0003b130:·7461·2d74·6172·6765·743d·2223·6964·6d38··ta-target="#idm8 
0003b140:·3435·3922·2074·6162·696e·6465·783d·2230··459"·tabindex="0 
0003b150:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
0003b160:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
0003b170:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
0003b180:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
0003b190:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
0003b1a0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
0003b1b0:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><0003b060:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
0003b1c0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel0003b070:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
0003b1d0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap0003b080:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
0003b1e0:·7365·2220·6964·3d22·6964·6d38·3435·3922··se"·id="idm8459"0003b090:·7365·2220·6964·3d22·6964·6d38·3435·3822··se"·id="idm8458"
0003b1f0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t0003b0a0:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
0003b200:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip0003b0b0:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
0003b210:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere0003b0c0:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
0003b220:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense0003b0d0:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
0003b230:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
0003b240:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
0003b250:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b260:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
0003b270:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
0003b280:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
0003b290:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
0003b2a0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr> 
0003b2b0:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
0003b2c0:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
0003b2d0:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
0003b2e0:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
0003b2f0:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
0003b300:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
0003b310:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
0003b320:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
0003b330:·206b·6572·6e65·6c3b·2074·6865·6e0a·0a69···kernel;·then..i 
0003b340:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
0003b350:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
0003b360:·0a20·2020·2064·6e66·2069·6e73·7461·6c6c··.····dnf·install 
0003b370:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
0003b380:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
0003b390:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
0003b3a0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
0003b3b0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
0003b3c0:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
0003b3d0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b3e0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b3f0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b400:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b410:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b420:·6964·6d38·3436·3022·2074·6162·696e·6465··idm8460"·tabinde 
0003b430:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b440:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b450:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b460:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b470:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b480:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib 
0003b490:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
0003b4a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b4b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b4c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b4d0:·646d·3834·3630·223e·3c74·6162·6c65·2063··dm8460"><table·c 
0003b4e0:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
0003b4f0:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
0003b500:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c 
0003b510:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t 
0003b520:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t 
0003b530:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b540:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru 
0003b550:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l 
0003b560:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
0003b570:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th> 
0003b580:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></ 
0003b590:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat 
0003b5a0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena 
0003b5b0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t 
0003b5c0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code> 
0003b5d0:·2d20·6e61·6d65·3a20·4761·7468·6572·2074··-·name:·Gather·t 
0003b5e0:·6865·2070·6163·6b61·6765·2066·6163·7473··he·package·facts 
0003b5f0:·0a20·2070·6163·6b61·6765·5f66·6163·7473··.··package_facts 
0003b600:·3a0a·2020·2020·6d61·6e61·6765·723a·2061··:.····manager:·a 
0003b610:·7574·6f0a·2020·7461·6773·3a0a·2020·2d20··uto.··tags:.··-· 
0003b620:·4343·452d·3930·3834·332d·340a·2020·2d20··CCE-90843-4.··-· 
0003b630:·434a·4953·2d35·2e31·302e·312e·330a·2020··CJIS-5.10.1.3.·· 
0003b640:·2d20·4449·5341·2d53·5449·472d·5248·454c··-·DISA-STIG-RHEL 
0003b650:·2d30·392d·3635·3130·3130·0a20·202d·204e··-09-651010.··-·N 
0003b660:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
0003b670:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R 
0003b680:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI- 
0003b690:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··- 
0003b6a0:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy 
0003b6b0:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex 
0003b6c0:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr 
0003b6d0:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu 
0003b6e0:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n 
0003b6f0:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed. 
0003b700:·2020·2d20·7061·636b·6167·655f·6169·6465····-·package_aide 
0003b710:·5f69·6e73·7461·6c6c·6564·0a0a·2d20·6e61··_installed..-·na 
0003b720:·6d65·3a20·456e·7375·7265·2061·6964·6520··me:·Ensure·aide· 
0003b730:·6973·2069·6e73·7461·6c6c·6564·0a20·2070··is·installed.··p 
0003b740:·6163·6b61·6765·3a0a·2020·2020·6e61·6d65··ackage:.····name 
0003b750:·3a20·6169·6465·0a20·2020·2073·7461·7465··:·aide.····state 
0003b760:·3a20·7072·6573·656e·740a·2020·7768·656e··:·present.··when 
0003b770:·3a20·2722·6b65·726e·656c·2220·696e·2061··:·'"kernel"·in·a 
0003b780:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac 
0003b790:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.· 
0003b7a0:·202d·2043·4345·2d39·3038·3433·2d34·0a20···-·CCE-90843-4.· 
0003b7b0:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003b7c0:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R 
Max diff block lines reached; 1801067/1839045 bytes (97.93%) of diff not shown.
149 KB
html2text {}
    
Offset 119, 19 lines modifiedOffset 119, 21 lines modified
119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199120 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
121 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79121 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
122 ·············_\x8c_\x8i_\x8s············6.1.1122 ·············_\x8c_\x8i_\x8s············6.1.1
123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
125 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule125 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 131 package·install·aide
127 [[packages]] 
128 name·=·"aide" 
129 version·=·"*" 
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
135 #·Remediation·is·applicable·only·in·certain·platforms137 #·Remediation·is·applicable·only·in·certain·platforms
136 if·rpm·--quiet·-q·kernel;·then138 if·rpm·--quiet·-q·kernel;·then
Offset 179, 14 lines modifiedOffset 181, 26 lines modified
179 ··-·PCI-DSSv4-11.5.2181 ··-·PCI-DSSv4-11.5.2
180 ··-·enable_strategy182 ··-·enable_strategy
181 ··-·low_complexity183 ··-·low_complexity
182 ··-·low_disruption184 ··-·low_disruption
183 ··-·medium_severity185 ··-·medium_severity
184 ··-·no_reboot_needed186 ··-·no_reboot_needed
185 ··-·package_aide_installed187 ··-·package_aide_installed
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 193 package·--add=aide
 194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 195 [[packages]]
 196 name·=·"aide"
 197 version·=·"*"
186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8198 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low199 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low200 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false201 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable202 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
191 dnf·install·aide203 dnf·install·aide
Offset 198, 28 lines modifiedOffset 212, 14 lines modified
198 include·install_aide212 include·install_aide
  
199 class·install_aide·{213 class·install_aide·{
200 ··package·{·'aide':214 ··package·{·'aide':
201 ····ensure·=>·'installed',215 ····ensure·=>·'installed',
202 ··}216 ··}
203 }217 }
204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
209 package·install·aide 
210 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
211 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
212 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
213 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
214 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
215 package·--add=aide 
216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*218 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
217 Run·the·following·command·to·generate·a·new·database:219 Run·the·following·command·to·generate·a·new·database:
218 $·sudo·/usr/sbin/aide·--init220 $·sudo·/usr/sbin/aide·--init
219 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the221 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the
220 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these222 database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these
221 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their223 files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their
222 integrity.·The·newly-generated·database·can·be·installed·as·follows:224 integrity.·The·newly-generated·database·can·be·installed·as·follows:
Offset 402, 57 lines modifiedOffset 402, 57 lines modified
402 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)402 References:··_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·SC-5(2)
403 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4403 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-4
404 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227404 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
405 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28405 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R28
406 ·············_\x8c_\x8i_\x8s············1.1.2.3.1406 ·············_\x8c_\x8i_\x8s············1.1.2.3.1
407 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010407 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-231010
408 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule408 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-257843r991589_rule
409 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
410 [[customizations.filesystem]] 
411 mountpoint·=·"/home" 
412 size·=·1073741824 
413 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8409 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
  
414 logvol·/home·1024410 logvol·/home·1024
415 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8411 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
416 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low412 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
417 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high413 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·high
418 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false414 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
419 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable415 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
420 part·/home416 part·/home
 417 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 418 [[customizations.filesystem]]
 419 mountpoint·=·"/home"
 420 size·=·1073741824
421 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*421 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8ns\x8su\x8ur\x8re\x8e·/\x8/s\x8sr\x8rv\x8v·L\x8Lo\x8oc\x8ca\x8at\x8te\x8ed\x8d·O\x8On\x8n·S\x8Se\x8ep\x8pa\x8ar\x8ra\x8at\x8te\x8e·P\x8Pa\x8ar\x8rt\x8ti\x8it\x8ti\x8io\x8on\x8n·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
422 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at422 If·a·file·server·(FTP,·TFTP...)·is·hosted·locally,·create·a·separate·partition·for·/srv·at
423 installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such423 installation·time·(or·migrate·it·later·using·LVM).·If·/srv·will·be·mounted·from·another·system·such
424 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the424 as·an·NFS·server,·then·creating·a·separate·partition·is·not·necessary·at·installation·time,·and·the
425 mountpoint·can·instead·be·configured·later.425 mountpoint·can·instead·be·configured·later.
426 ·············Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is426 ·············Srv·deserves·files·for·local·network·file·server·such·as·FTP.·Ensuring·that·/srv·is
427 Rationale:···mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and427 Rationale:···mounted·on·its·own·partition·enables·the·setting·of·more·restrictive·mount·options,·and
428 ·············also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data428 ·············also·helps·ensure·that·users·cannot·trivially·fill·partitions·used·for·log·or·audit·data
429 ·············storage.429 ·············storage.
430 Severity: ···unknown430 Severity: ···unknown
431 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv431 Rule·ID:·····xccdf_org.ssgproject.content_rule_partition_for_srv
432 Identifiers:·CCE-90846-7432 Identifiers:·CCE-90846-7
433 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28433 References:··_\x8a_\x8n_\x8s_\x8s_\x8i·R28
434 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
435 [[customizations.filesystem]] 
436 mountpoint·=·"/srv" 
437 size·=·1073741824 
438 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8434 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
Max diff block lines reached; 146545/152101 bytes (96.35%) of diff not shown.
506 KB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-anssi_bp28_minimal.html
    
Offset 14773, 297 lines modifiedOffset 14773, 297 lines modified
00039b40:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm1200039b40:·612d·7461·7267·6574·3d22·2369·646d·3132··a-target="#idm12
00039b50:·3833·3922·2074·6162·696e·6465·783d·2230··839"·tabindex="000039b50:·3833·3922·2074·6162·696e·6465·783d·2230··839"·tabindex="0
00039b60:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00039b60:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00039b70:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00039b70:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00039b80:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00039b80:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00039b90:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00039b90:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00039ba0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00039ba0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00039bb0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B 
00039bc0:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet00039bb0:·6961·7469·6f6e·2073·6372·6970·7420·e287··iation·script·..
 00039bc0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00039bd0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00039be0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00039bf0:·3d22·6964·6d31·3238·3339·223e·3c74·6162··="idm12839"><tab
 00039c00:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 00039c10:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 00039c20:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 00039c30:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 00039c40:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 00039c50:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 00039c60:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 00039c70:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 00039c80:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 00039c90:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 00039ca0:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 00039cb0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 00039cc0:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 00039cd0:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 00039ce0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 00039cf0:·6f64·653e·0a70·6163·6b61·6765·2069·6e73··ode>.package·ins
 00039d00:·7461·6c6c·2064·6e66·2d61·7574·6f6d·6174··tall·dnf-automat
 00039d10:·6963·0a3c·2f63·6f64·653e·3c2f·7072·653e··ic.</code></pre>
 00039d20:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 00039d30:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 00039d40:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 00039d50:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 00039d60:·6765·743d·2223·6964·6d31·3238·3430·2220··get="#idm12840"·
 00039d70:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 00039d80:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 00039d90:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 00039da0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 00039db0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 00039dc0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 00039dd0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.
00039bd0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div00039de0:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
00039be0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co00039df0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
00039bf0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00039e00:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
00039c00:·2069·643d·2269·646d·3132·3833·3922·3e3c···id="idm12839"><00039e10:·643d·2269·646d·3132·3834·3022·3e3c·7461··d="idm12840"><ta
 00039e20:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 00039e30:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 00039e40:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 00039e50:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 00039e60:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 00039e70:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 00039e80:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00039e90:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 00039ea0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 00039eb0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 00039ec0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 00039ed0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 00039ee0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
00039c10:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac 
00039c20:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
00039c30:·646e·662d·6175·746f·6d61·7469·6322·0a76··dnf-automatic".v 
00039c40:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
00039c50:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00039c60:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00039c70:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00039c80:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00039c90:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00039ca0:·6964·6d31·3238·3430·2220·7461·6269·6e64··idm12840"·tabind 
00039cb0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but 
00039cc0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand 
00039cd0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title 
00039ce0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re 
00039cf0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!"> 
00039d00:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel 
00039d10:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a> 
00039d20:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
00039d30:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
00039d40:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
00039d50:·3132·3834·3022·3e3c·7461·626c·6520·636c··12840"><table·cl 
00039d60:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
00039d70:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
00039d80:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
00039d90:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
00039da0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
00039db0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
00039dc0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
00039dd0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
00039de0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00039df0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
00039e00:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t00039ef0:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
00039e10:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate 
00039e20:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab 
00039e30:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
00039e40:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code># 
00039e50:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
00039e60:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
00039e70:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
00039e80:·6f72·6d73·0a69·6620·2120·2820·7b20·7270··orms.if·!·(·{·rp 
00039e90:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker00039f00:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 00039f10:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 00039f20:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 00039f30:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 00039f40:·2070·6c61·7466·6f72·6d73·0a69·6620·2120···platforms.if·!·
 00039f50:·2820·7b20·7270·6d20·2d2d·7175·6965·7420··(·{·rpm·--quiet·
 00039f60:·2d71·206b·6572·6e65·6c20·3b7d·2026·616d··-q·kernel·;}·&am
 00039f70:·703b·2661·6d70·3b20·7b20·7270·6d20·2d2d··p;&amp;·{·rpm·--
 00039f80:·7175·6965·7420·2d71·2072·706d·2d6f·7374··quiet·-q·rpm-ost
00039ea0:·6e65·6c20·3b7d·2026·616d·703b·2661·6d70··nel·;}·&amp;&amp00039f90:·7265·6520·3b7d·2026·616d·703b·2661·6d70··ree·;}·&amp;&amp
00039eb0:·3b20·7b20·7270·6d20·2d2d·7175·6965·7420··;·{·rpm·--quiet·00039fa0:·3b20·7b20·7270·6d20·2d2d·7175·6965·7420··;·{·rpm·--quiet·
00039ec0:·2d71·2072·706d·2d6f·7374·7265·6520·3b7d··-q·rpm-ostree·;} 
00039ed0:·2026·616d·703b·2661·6d70·3b20·7b20·7270···&amp;&amp;·{·rp 
00039ee0:·6d20·2d2d·7175·6965·7420·2d71·2062·6f6f··m·--quiet·-q·boo 
00039ef0:·7463·203b·7d20·2661·6d70·3b26·616d·703b··tc·;}·&amp;&amp; 
00039f00:·207b·2021·2072·706d·202d·2d71·7569·6574···{·!·rpm·--quiet00039fb0:·2d71·2062·6f6f·7463·203b·7d20·2661·6d70··-q·bootc·;}·&amp
 00039fc0:·3b26·616d·703b·207b·2021·2072·706d·202d··;&amp;·{·!·rpm·-
 00039fd0:·2d71·7569·6574·202d·7120·6f70·656e·7368··-quiet·-q·opensh
 00039fe0:·6966·742d·6b75·6265·6c65·7420·3b7d·2029··ift-kubelet·;}·)
 00039ff0:·3b20·7468·656e·0a0a·6966·2021·2072·706d··;·then..if·!·rpm
 0003a000:·202d·7120·2d2d·7175·6965·7420·2264·6e66···-q·--quiet·"dnf
 0003a010:·2d61·7574·6f6d·6174·6963·2220·3b20·7468··-automatic"·;·th
 0003a020:·656e·0a20·2020·2064·6e66·2069·6e73·7461··en.····dnf·insta
 0003a030:·6c6c·202d·7920·2264·6e66·2d61·7574·6f6d··ll·-y·"dnf-autom
 0003a040:·6174·6963·220a·6669·0a0a·656c·7365·0a20··atic".fi..else.·
 0003a050:·2020·2026·6774·3b26·616d·703b·3220·6563·····&gt;&amp;2·ec
 0003a060:·686f·2027·5265·6d65·6469·6174·696f·6e20··ho·'Remediation·
Max diff block lines reached; 438514/478148 bytes (91.71%) of diff not shown.
39.2 KB
html2text {}
    
Offset 84, 19 lines modifiedOffset 84, 21 lines modified
84 ·············suitable·for·automatic,·regular·execution.84 ·············suitable·for·automatic,·regular·execution.
85 Severity: ···medium85 Severity: ···medium
86 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed86 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
87 Identifiers:·CCE-83454-987 Identifiers:·CCE-83454-9
88 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.288 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
89 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008089 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
90 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R6190 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
91 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x891 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 92 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 93 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 94 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 95 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 96 package·install·dnf-automatic
92 [[packages]] 
93 name·=·"dnf-automatic" 
94 version·=·"*" 
95 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x897 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
96 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low98 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
97 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low99 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
98 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false100 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
99 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable101 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
100 #·Remediation·is·applicable·only·in·certain·platforms102 #·Remediation·is·applicable·only·in·certain·platforms
101 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc103 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc
Offset 138, 14 lines modifiedOffset 140, 26 lines modified
138 ··-·CCE-83454-9140 ··-·CCE-83454-9
139 ··-·enable_strategy141 ··-·enable_strategy
140 ··-·low_complexity142 ··-·low_complexity
141 ··-·low_disruption143 ··-·low_disruption
142 ··-·medium_severity144 ··-·medium_severity
143 ··-·no_reboot_needed145 ··-·no_reboot_needed
144 ··-·package_dnf-automatic_installed146 ··-·package_dnf-automatic_installed
 147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 152 package·--add=dnf-automatic
 153 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 154 [[packages]]
 155 name·=·"dnf-automatic"
 156 version·=·"*"
145 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8157 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
146 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low158 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
147 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low159 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
148 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false160 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
149 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable161 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
150 dnf·install·dnf-automatic162 dnf·install·dnf-automatic
Offset 157, 28 lines modifiedOffset 171, 14 lines modified
157 include·install_dnf-automatic171 include·install_dnf-automatic
  
158 class·install_dnf-automatic·{172 class·install_dnf-automatic·{
159 ··package·{·'dnf-automatic':173 ··package·{·'dnf-automatic':
160 ····ensure·=>·'installed',174 ····ensure·=>·'installed',
161 ··}175 ··}
162 }176 }
163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
164 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
165 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
166 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
167 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
168 package·install·dnf-automatic 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
174 package·--add=dnf-automatic 
175 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*177 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·d\x8dn\x8nf\x8f-\x8-a\x8au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8c·t\x8to\x8o·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·A\x8Av\x8va\x8ai\x8il\x8la\x8ab\x8bl\x8le\x8e·U\x8Up\x8pd\x8da\x8at\x8te\x8es\x8s·A\x8Au\x8ut\x8to\x8om\x8ma\x8at\x8ti\x8ic\x8ca\x8al\x8ll\x8ly\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
176 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed178 To·ensure·that·the·packages·comprising·the·available·updates·will·be·automatically·installed
177 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/179 by·dnf-automatic,·set·apply_updates·to·yes·under·[commands]·section·in·/etc/dnf/
178 automatic.conf.180 automatic.conf.
179 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation181 ·············Installing·software·updates·is·a·fundamental·mitigation·against·the·exploitation
180 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and182 ·············of·publicly-known·vulnerabilities.·If·the·most·recent·security·patches·and
181 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in183 Rationale:···updates·are·not·installed,·unauthorized·users·may·take·advantage·of·weaknesses·in
Offset 10353, 14 lines modifiedOffset 10353, 21 lines modified
10353 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,10353 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,
10354 ····························A.9.1.210354 ····························A.9.1.2
10355 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)10355 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
10356 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-310356 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
10357 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R6210357 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R62
10358 ·············_\x8c_\x8i_\x8s············2.1.310358 ·············_\x8c_\x8i_\x8s············2.1.3
10359 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.4,·2.210359 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.4,·2.2
 10360 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
 10361 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10362 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10363 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10364 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10365 package·remove·dhcp-server
10360 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810366 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10361 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10367 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10362 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10368 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10363 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10369 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10364 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10370 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
10365 #·CAUTION:·This·remediation·script·will·remove·dhcp-server10371 #·CAUTION:·This·remediation·script·will·remove·dhcp-server
Offset 10390, 14 lines modifiedOffset 10397, 21 lines modified
10390 ··-·PCI-DSSv4-2.2.410397 ··-·PCI-DSSv4-2.2.4
10391 ··-·disable_strategy10398 ··-·disable_strategy
10392 ··-·low_complexity10399 ··-·low_complexity
10393 ··-·low_disruption10400 ··-·low_disruption
10394 ··-·medium_severity10401 ··-·medium_severity
10395 ··-·no_reboot_needed10402 ··-·no_reboot_needed
10396 ··-·package_dhcp_removed10403 ··-·package_dhcp_removed
 10404 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 10405 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 10406 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 10407 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 10408 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 10409 package·--remove=dhcp-server
10397 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810410 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10398 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10411 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10399 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10412 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10400 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10413 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10401 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable10414 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
10402 dnf·remove·dhcp-server10415 dnf·remove·dhcp-server
Offset 10409, 28 lines modifiedOffset 10423, 14 lines modified
10409 include·remove_dhcp-server10423 include·remove_dhcp-server
  
Max diff block lines reached; 34972/40137 bytes (87.13%) of diff not shown.
1.76 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ccn_advanced.html
    
Offset 15238, 192 lines modifiedOffset 15238, 192 lines modified
0003b850:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b850:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b860:·3d22·2369·646d·3932·3635·2220·7461·6269··="#idm9265"·tabi0003b860:·3d22·2369·646d·3932·3635·2220·7461·6269··="#idm9265"·tabi
0003b870:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b870:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b880:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b880:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b890:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b890:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b8a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b8a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b8b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b8b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b8c0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b8c0:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
0003b8d0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b8e0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b8f0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b900:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b910:·3d22·6964·6d39·3236·3522·3e3c·7461·626c··="idm9265"><tabl 
0003b920:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b930:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b940:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b950:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b960:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003b8d0:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
 0003b8e0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b8f0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b900:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b910:·2069·643d·2269·646d·3932·3635·223e·3c74···id="idm9265"><t
 0003b920:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b930:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b940:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b950:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b960:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b970:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b980:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b990:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b970:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b9a0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b9b0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b9c0:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
0003b980:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b990:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b9a0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b9b0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b9c0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b9d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003b9d0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b9e0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b9e0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003b9f0:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t0003b9f0:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><
0003ba00:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003ba00:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003ba10:·3e3c·636f·6465·3e2d·2d2d·0a61·7069·5665··><code>---.apiVe
 0003ba20:·7273·696f·6e3a·206d·6163·6869·6e65·636f··rsion:·machineco
 0003ba30:·6e66·6967·7572·6174·696f·6e2e·6f70·656e··nfiguration.open
 0003ba40:·7368·6966·742e·696f·2f76·310a·6b69·6e64··shift.io/v1.kind
 0003ba50:·3a20·4d61·6368·696e·6543·6f6e·6669·670a··:·MachineConfig.
 0003ba60:·7370·6563·3a0a·2020·636f·6e66·6967·3a0a··spec:.··config:.
 0003ba70:·2020·2020·6967·6e69·7469·6f6e·3a0a·2020······ignition:.··
 0003ba80:·2020·2020·7665·7273·696f·6e3a·2033·2e31······version:·3.1
 0003ba90:·2e30·0a20·2020·2073·7973·7465·6d64·3a0a··.0.····systemd:.
 0003baa0:·2020·2020·2020·756e·6974·733a·0a20·2020········units:.···
 0003bab0:·2020·2020·202d·206e·616d·653a·2063·6f6e·······-·name:·con
 0003bac0:·6669·6775·7265·2d63·7279·7074·6f2d·706f··figure-crypto-po
 0003bad0:·6c69·6379·2e73·6572·7669·6365·0a20·2020··licy.service.···
 0003bae0:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:·
 0003baf0:·7472·7565·0a20·2020·2020·2020·2020·2063··true.··········c
 0003bb00:·6f6e·7465·6e74·733a·207c·0a20·2020·2020··ontents:·|.·····
 0003bb10:·2020·2020·2020·205b·556e·6974·5d0a·2020·········[Unit].··
 0003bb20:·2020·2020·2020·2020·2020·4265·666f·7265············Before
 0003bb30:·3d6b·7562·656c·6574·2e73·6572·7669·6365··=kubelet.service
 0003bb40:·0a20·2020·2020·2020·2020·2020·205b·5365··.············[Se
 0003bb50:·7276·6963·655d·0a20·2020·2020·2020·2020··rvice].·········
 0003bb60:·2020·2054·7970·653d·6f6e·6573·686f·740a·····Type=oneshot.
 0003bb70:·2020·2020·2020·2020·2020·2020·4578·6563··············Exec
 0003bb80:·5374·6172·743d·7570·6461·7465·2d63·7279··Start=update-cry
 0003bb90:·7074·6f2d·706f·6c69·6369·6573·202d·2d73··pto-policies·--s
 0003bba0:·6574·207b·7b2e·7661·725f·7379·7374·656d··et·{{.var_system
 0003bbb0:·5f63·7279·7074·6f5f·706f·6c69·6379·7d7d··_crypto_policy}}
 0003bbc0:·0a20·2020·2020·2020·2020·2020·2052·656d··.············Rem
 0003bbd0:·6169·6e41·6674·6572·4578·6974·3d79·6573··ainAfterExit=yes
 0003bbe0:·0a20·2020·2020·2020·2020·2020·205b·496e··.············[In
 0003bbf0:·7374·616c·6c5d·0a20·2020·2020·2020·2020··stall].·········
 0003bc00:·2020·2057·616e·7465·6442·793d·6d75·6c74·····WantedBy=mult
 0003bc10:·692d·7573·6572·2e74·6172·6765·740a·3c2f··i-user.target.</
 0003bc20:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003bc30:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003bc40:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003bc50:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003bc60:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003bc70:·2369·646d·3932·3636·2220·7461·6269·6e64··#idm9266"·tabind
 0003bc80:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003bc90:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003bca0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003bcb0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003bcc0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003bcd0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
 0003bce0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
 0003bcf0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003bd00:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003bd10:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003bd20:·6964·6d39·3236·3622·3e3c·7461·626c·6520··idm9266"><table·
 0003bd30:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003bd40:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003bd50:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003bd60:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003bd70:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003bd80:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003bd90:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003bda0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003bdb0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003bdc0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003bdd0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003bde0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003bdf0:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re
 0003be00:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>
 0003be10:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003ba10:·636f·6465·3e2d·206e·616d·653a·2058·4343··code>-·name:·XCC0003be20:·6465·3e2d·206e·616d·653a·2058·4343·4446··de>-·name:·XCCDF
0003ba20:·4446·2056·616c·7565·2076·6172·5f73·7973··DF·Value·var_sys0003be30:·2056·616c·7565·2076·6172·5f73·7973·7465···Value·var_syste
0003ba30:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic0003be40:·6d5f·6372·7970·746f·5f70·6f6c·6963·7920··m_crypto_policy·
0003ba40:·7920·2320·7072·6f6d·6f74·6520·746f·2076··y·#·promote·to·v0003be50:·2320·7072·6f6d·6f74·6520·746f·2076·6172··#·promote·to·var
0003ba50:·6172·6961·626c·650a·2020·7365·745f·6661··ariable.··set_fa0003be60:·6961·626c·650a·2020·7365·745f·6661·6374··iable.··set_fact
0003ba60:·6374·3a0a·2020·2020·7661·725f·7379·7374··ct:.····var_syst0003be70:·3a0a·2020·2020·7661·725f·7379·7374·656d··:.····var_system
 0003be80:·5f63·7279·7074·6f5f·706f·6c69·6379·3a20··_crypto_policy:·
 0003be90:·2121·7374·7220·3c61·6262·7220·7469·746c··!!str·<abbr·titl
 0003bea0:·653d·2266·726f·6d20·5072·6f66·696c·652f··e="from·Profile/
 0003beb0:·7265·6669·6e65·2d76·616c·7565·3a20·7863··refine-value:·xc
 0003bec0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
 0003bed0:·6374·2e63·6f6e·7465·6e74·5f76·616c·7565··ct.content_value
 0003bee0:·5f76·6172·5f73·7973·7465·6d5f·6372·7970··_var_system_cryp
 0003bef0:·746f·5f70·6f6c·6963·7922·3e44·4546·4155··to_policy">DEFAU
 0003bf00:·4c54·3c2f·6162·6272·3e0a·2020·7461·6773··LT</abbr>.··tags
 0003bf10:·3a0a·2020·2020·2d20·616c·7761·7973·0a0a··:.····-·always..
 0003bf20:·2d20·6e61·6d65·3a20·436f·6e66·6967·7572··-·name:·Configur
 0003bf30:·6520·5379·7374·656d·2043·7279·7074·6f67··e·System·Cryptog
 0003bf40:·7261·7068·7920·506f·6c69·6379·0a20·206c··raphy·Policy.··l
 0003bf50:·696e·6569·6e66·696c·653a·0a20·2020·2070··ineinfile:.····p
Max diff block lines reached; 1678699/1703843 bytes (98.52%) of diff not shown.
139 KB
html2text {}
    
Offset 124, 14 lines modifiedOffset 124, 39 lines modified
124 »       echo·"to·see·what·package·to·(re)install"·>&2124 »       echo·"to·see·what·package·to·(re)install"·>&2
  
125 »       false··#·end·with·an·error·code125 »       false··#·end·with·an·error·code
126 elif·test·"$rc"·!=·0;·then126 elif·test·"$rc"·!=·0;·then
127 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2127 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
128 »       false··#·end·with·an·error·code128 »       false··#·end·with·an·error·code
129 fi129 fi
 130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 135 ---
 136 apiVersion:·machineconfiguration.openshift.io/v1
 137 kind:·MachineConfig
 138 spec:
 139 ··config:
 140 ····ignition:
 141 ······version:·3.1.0
 142 ····systemd:
 143 ······units:
 144 ········-·name:·configure-crypto-policy.service
 145 ··········enabled:·true
 146 ··········contents:·|
 147 ············[Unit]
 148 ············Before=kubelet.service
 149 ············[Service]
 150 ············Type=oneshot
 151 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 152 ············RemainAfterExit=yes
 153 ············[Install]
 154 ············WantedBy=multi-user.target
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
135 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable160 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
136 ··set_fact:161 ··set_fact:
Offset 184, 39 lines modifiedOffset 209, 14 lines modified
184 ··-·PCI-DSSv4-2.2.7209 ··-·PCI-DSSv4-2.2.7
185 ··-·configure_crypto_policy210 ··-·configure_crypto_policy
186 ··-·high_severity211 ··-·high_severity
187 ··-·low_complexity212 ··-·low_complexity
188 ··-·low_disruption213 ··-·low_disruption
189 ··-·no_reboot_needed214 ··-·no_reboot_needed
190 ··-·restrict_strategy215 ··-·restrict_strategy
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
196 --- 
197 apiVersion:·machineconfiguration.openshift.io/v1 
198 kind:·MachineConfig 
199 spec: 
200 ··config: 
201 ····ignition: 
202 ······version:·3.1.0 
203 ····systemd: 
204 ······units: 
205 ········-·name:·configure-crypto-policy.service 
206 ··········enabled:·true 
207 ··········contents:·| 
208 ············[Unit] 
209 ············Before=kubelet.service 
210 ············[Service] 
211 ············Type=oneshot 
212 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
213 ············RemainAfterExit=yes 
214 ············[Install] 
215 ············WantedBy=multi-user.target 
216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
217 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.217 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
218 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.218 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
219 Severity: ···medium219 Severity: ···medium
220 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy220 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
221 Identifiers:·CCE-83445-7221 Identifiers:·CCE-83445-7
222 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453222 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
Offset 1808, 19 lines modifiedOffset 1808, 21 lines modified
1808 $·sudo·dnf·install·cryptsetup1808 $·sudo·dnf·install·cryptsetup
1809 Rationale:···LUKS·is·the·upcoming·standard·for·Linux·hard·disk·encryption.·By·providing·a·standard·on-disk·format,·it·does·not·only·facilitate·compatibility·among·distributions,·but·also·provide·secure·management·of·multiple·user·passwords.·In·contrast·to·existing·solution,·LUKS·stores·all·necessary·setup·information·in·the·partition·header,·enabling·the·user·to·transport·or·migrate·their·data·seamlessly.·LUKS·for·dm-crypt·is·implemented·in·cryptsetup.1809 Rationale:···LUKS·is·the·upcoming·standard·for·Linux·hard·disk·encryption.·By·providing·a·standard·on-disk·format,·it·does·not·only·facilitate·compatibility·among·distributions,·but·also·provide·secure·management·of·multiple·user·passwords.·In·contrast·to·existing·solution,·LUKS·stores·all·necessary·setup·information·in·the·partition·header,·enabling·the·user·to·transport·or·migrate·their·data·seamlessly.·LUKS·for·dm-crypt·is·implemented·in·cryptsetup.
1810 Severity: ···medium1810 Severity: ···medium
1811 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_cryptsetup-luks_installed1811 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_cryptsetup-luks_installed
1812 Identifiers:·CCE-86612-91812 Identifiers:·CCE-86612-9
1813 References:··_\x8c_\x8c_\x8n·····A.25.SEC-RHEL11813 References:··_\x8c_\x8c_\x8n·····A.25.SEC-RHEL1
1814 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·3.5.1.2,·3.5.1,·3.51814 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·3.5.1.2,·3.5.1,·3.5
1815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81815 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1816 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1817 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1818 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1819 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1820 package·install·cryptsetup
1816 [[packages]] 
1817 name·=·"cryptsetup" 
1818 version·=·"*" 
1819 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81821 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1820 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1822 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1821 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1823 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1822 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1824 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1823 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1825 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
1824 if·!·rpm·-q·--quiet·"cryptsetup"·;·then1826 if·!·rpm·-q·--quiet·"cryptsetup"·;·then
Offset 1842, 14 lines modifiedOffset 1844, 26 lines modified
1842 ··-·PCI-DSSv4-3.5.1.21844 ··-·PCI-DSSv4-3.5.1.2
1843 ··-·enable_strategy1845 ··-·enable_strategy
1844 ··-·low_complexity1846 ··-·low_complexity
1845 ··-·low_disruption1847 ··-·low_disruption
1846 ··-·medium_severity1848 ··-·medium_severity
1847 ··-·no_reboot_needed1849 ··-·no_reboot_needed
1848 ··-·package_cryptsetup-luks_installed1850 ··-·package_cryptsetup-luks_installed
 1851 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1852 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1853 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1854 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1855 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1856 package·--add=cryptsetup
 1857 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1858 [[packages]]
 1859 name·=·"cryptsetup"
 1860 version·=·"*"
1849 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81861 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1850 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1862 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1851 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1863 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 136403/141811 bytes (96.19%) of diff not shown.
1.29 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ccn_basic.html
    
Offset 15198, 192 lines modifiedOffset 15198, 192 lines modified
0003b5d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b5d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b5e0:·743d·2223·6964·6d39·3236·3522·2074·6162··t="#idm9265"·tab0003b5e0:·743d·2223·6964·6d39·3236·3522·2074·6162··t="#idm9265"·tab
0003b5f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b5f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b600:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b600:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b610:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b610:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b620:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b620:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b630:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b630:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b640:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A0003b640:·2122·3e52·656d·6564·6961·7469·6f6e·204b··!">Remediation·K
0003b650:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b660:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b670:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b680:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b690:·643d·2269·646d·3932·3635·223e·3c74·6162··d="idm9265"><tab 
0003b6a0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b6b0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b6c0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b6d0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b6e0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity0003b650:·7562·6572·6e65·7465·7320·736e·6970·7065··ubernetes·snippe
 0003b660:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b670:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b680:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b690:·2220·6964·3d22·6964·6d39·3236·3522·3e3c··"·id="idm9265"><
 0003b6a0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b6b0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b6c0:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b6d0:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b6e0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003b6f0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003b700:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b710:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003b6f0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t0003b720:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b730:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003b740:·743a·3c2f·7468·3e3c·7464·3e74·7275·653c··t:</th><td>true<
0003b700:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b710:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b720:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b730:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b740:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b750:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S0003b750:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b760:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td0003b760:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b770:·3e72·6573·7472·6963·743c·2f74·643e·3c2f··>restrict</td></0003b770:·7464·3e72·6573·7472·6963·743c·2f74·643e··td>restrict</td>
0003b780:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b780:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b790:·653e·3c63·6f64·653e·2d2d·2d0a·6170·6956··e><code>---.apiV
 0003b7a0:·6572·7369·6f6e·3a20·6d61·6368·696e·6563··ersion:·machinec
 0003b7b0:·6f6e·6669·6775·7261·7469·6f6e·2e6f·7065··onfiguration.ope
 0003b7c0:·6e73·6869·6674·2e69·6f2f·7631·0a6b·696e··nshift.io/v1.kin
 0003b7d0:·643a·204d·6163·6869·6e65·436f·6e66·6967··d:·MachineConfig
 0003b7e0:·0a73·7065·633a·0a20·2063·6f6e·6669·673a··.spec:.··config:
 0003b7f0:·0a20·2020·2069·676e·6974·696f·6e3a·0a20··.····ignition:.·
 0003b800:·2020·2020·2076·6572·7369·6f6e·3a20·332e·······version:·3.
 0003b810:·312e·300a·2020·2020·7379·7374·656d·643a··1.0.····systemd:
 0003b820:·0a20·2020·2020·2075·6e69·7473·3a0a·2020··.······units:.··
 0003b830:·2020·2020·2020·2d20·6e61·6d65·3a20·636f········-·name:·co
 0003b840:·6e66·6967·7572·652d·6372·7970·746f·2d70··nfigure-crypto-p
 0003b850:·6f6c·6963·792e·7365·7276·6963·650a·2020··olicy.service.··
 0003b860:·2020·2020·2020·2020·656e·6162·6c65·643a··········enabled:
 0003b870:·2074·7275·650a·2020·2020·2020·2020·2020···true.··········
 0003b880:·636f·6e74·656e·7473·3a20·7c0a·2020·2020··contents:·|.····
 0003b890:·2020·2020·2020·2020·5b55·6e69·745d·0a20··········[Unit].·
 0003b8a0:·2020·2020·2020·2020·2020·2042·6566·6f72·············Befor
 0003b8b0:·653d·6b75·6265·6c65·742e·7365·7276·6963··e=kubelet.servic
 0003b8c0:·650a·2020·2020·2020·2020·2020·2020·5b53··e.············[S
 0003b8d0:·6572·7669·6365·5d0a·2020·2020·2020·2020··ervice].········
 0003b8e0:·2020·2020·5479·7065·3d6f·6e65·7368·6f74······Type=oneshot
 0003b8f0:·0a20·2020·2020·2020·2020·2020·2045·7865··.············Exe
 0003b900:·6353·7461·7274·3d75·7064·6174·652d·6372··cStart=update-cr
 0003b910:·7970·746f·2d70·6f6c·6963·6965·7320·2d2d··ypto-policies·--
 0003b920:·7365·7420·7b7b·2e76·6172·5f73·7973·7465··set·{{.var_syste
 0003b930:·6d5f·6372·7970·746f·5f70·6f6c·6963·797d··m_crypto_policy}
 0003b940:·7d0a·2020·2020·2020·2020·2020·2020·5265··}.············Re
 0003b950:·6d61·696e·4166·7465·7245·7869·743d·7965··mainAfterExit=ye
 0003b960:·730a·2020·2020·2020·2020·2020·2020·5b49··s.············[I
 0003b970:·6e73·7461·6c6c·5d0a·2020·2020·2020·2020··nstall].········
 0003b980:·2020·2020·5761·6e74·6564·4279·3d6d·756c······WantedBy=mul
 0003b990:·7469·2d75·7365·722e·7461·7267·6574·0a3c··ti-user.target.<
 0003b9a0:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 0003b9b0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 0003b9c0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 0003b9d0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 0003b9e0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 0003b9f0:·2223·6964·6d39·3236·3622·2074·6162·696e··"#idm9266"·tabin
 0003ba00:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 0003ba10:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 0003ba20:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 0003ba30:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 0003ba40:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 0003ba50:·3e52·656d·6564·6961·7469·6f6e·2041·6e73··>Remediation·Ans
 0003ba60:·6962·6c65·2073·6e69·7070·6574·20e2·87b2··ible·snippet·...
 0003ba70:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003ba80:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003ba90:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003baa0:·2269·646d·3932·3636·223e·3c74·6162·6c65··"idm9266"><table
 0003bab0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003bac0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003bad0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003bae0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003baf0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003bb00:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003bb10:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003bb20:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 0003bb30:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003bb40:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 0003bb50:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 0003bb60:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 0003bb70:·6174·6567·793a·3c2f·7468·3e3c·7464·3e72··ategy:</th><td>r
 0003bb80:·6573·7472·6963·743c·2f74·643e·3c2f·7472··estrict</td></tr
 0003bb90:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
0003b790:·3c63·6f64·653e·2d20·6e61·6d65·3a20·5843··<code>-·name:·XC0003bba0:·6f64·653e·2d20·6e61·6d65·3a20·5843·4344··ode>-·name:·XCCD
0003b7a0:·4344·4620·5661·6c75·6520·7661·725f·7379··CDF·Value·var_sy0003bbb0:·4620·5661·6c75·6520·7661·725f·7379·7374··F·Value·var_syst
0003b7b0:·7374·656d·5f63·7279·7074·6f5f·706f·6c69··stem_crypto_poli0003bbc0:·656d·5f63·7279·7074·6f5f·706f·6c69·6379··em_crypto_policy
0003b7c0:·6379·2023·2070·726f·6d6f·7465·2074·6f20··cy·#·promote·to·0003bbd0:·2023·2070·726f·6d6f·7465·2074·6f20·7661···#·promote·to·va
0003b7d0:·7661·7269·6162·6c65·0a20·2073·6574·5f66··variable.··set_f0003bbe0:·7269·6162·6c65·0a20·2073·6574·5f66·6163··riable.··set_fac
0003b7e0:·6163·743a·0a20·2020·2076·6172·5f73·7973··act:.····var_sys0003bbf0:·743a·0a20·2020·2076·6172·5f73·7973·7465··t:.····var_syste
 0003bc00:·6d5f·6372·7970·746f·5f70·6f6c·6963·793a··m_crypto_policy:
 0003bc10:·2021·2173·7472·203c·6162·6272·2074·6974···!!str·<abbr·tit
 0003bc20:·6c65·3d22·6672·6f6d·2050·726f·6669·6c65··le="from·Profile
 0003bc30:·2f72·6566·696e·652d·7661·6c75·653a·2078··/refine-value:·x
 0003bc40:·6363·6466·5f6f·7267·2e73·7367·7072·6f6a··ccdf_org.ssgproj
 0003bc50:·6563·742e·636f·6e74·656e·745f·7661·6c75··ect.content_valu
 0003bc60:·655f·7661·725f·7379·7374·656d·5f63·7279··e_var_system_cry
 0003bc70:·7074·6f5f·706f·6c69·6379·223e·4445·4641··pto_policy">DEFA
 0003bc80:·554c·543c·2f61·6262·723e·0a20·2074·6167··ULT</abbr>.··tag
 0003bc90:·733a·0a20·2020·202d·2061·6c77·6179·730a··s:.····-·always.
 0003bca0:·0a2d·206e·616d·653a·2043·6f6e·6669·6775··.-·name:·Configu
 0003bcb0:·7265·2053·7973·7465·6d20·4372·7970·746f··re·System·Crypto
 0003bcc0:·6772·6170·6879·2050·6f6c·6963·790a·2020··graphy·Policy.··
 0003bcd0:·6c69·6e65·696e·6669·6c65·3a0a·2020·2020··lineinfile:.····
Max diff block lines reached; 1235327/1260471 bytes (98.01%) of diff not shown.
93.1 KB
html2text {}
    
Offset 116, 14 lines modifiedOffset 116, 39 lines modified
116 »       echo·"to·see·what·package·to·(re)install"·>&2116 »       echo·"to·see·what·package·to·(re)install"·>&2
  
117 »       false··#·end·with·an·error·code117 »       false··#·end·with·an·error·code
118 elif·test·"$rc"·!=·0;·then118 elif·test·"$rc"·!=·0;·then
119 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2119 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
120 »       false··#·end·with·an·error·code120 »       false··#·end·with·an·error·code
121 fi121 fi
 122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 127 ---
 128 apiVersion:·machineconfiguration.openshift.io/v1
 129 kind:·MachineConfig
 130 spec:
 131 ··config:
 132 ····ignition:
 133 ······version:·3.1.0
 134 ····systemd:
 135 ······units:
 136 ········-·name:·configure-crypto-policy.service
 137 ··········enabled:·true
 138 ··········contents:·|
 139 ············[Unit]
 140 ············Before=kubelet.service
 141 ············[Service]
 142 ············Type=oneshot
 143 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 144 ············RemainAfterExit=yes
 145 ············[Install]
 146 ············WantedBy=multi-user.target
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
127 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable152 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
128 ··set_fact:153 ··set_fact:
Offset 176, 39 lines modifiedOffset 201, 14 lines modified
176 ··-·PCI-DSSv4-2.2.7201 ··-·PCI-DSSv4-2.2.7
177 ··-·configure_crypto_policy202 ··-·configure_crypto_policy
178 ··-·high_severity203 ··-·high_severity
179 ··-·low_complexity204 ··-·low_complexity
180 ··-·low_disruption205 ··-·low_disruption
181 ··-·no_reboot_needed206 ··-·no_reboot_needed
182 ··-·restrict_strategy207 ··-·restrict_strategy
183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
184 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
185 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
186 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
187 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
188 --- 
189 apiVersion:·machineconfiguration.openshift.io/v1 
190 kind:·MachineConfig 
191 spec: 
192 ··config: 
193 ····ignition: 
194 ······version:·3.1.0 
195 ····systemd: 
196 ······units: 
197 ········-·name:·configure-crypto-policy.service 
198 ··········enabled:·true 
199 ··········contents:·| 
200 ············[Unit] 
201 ············Before=kubelet.service 
202 ············[Service] 
203 ············Type=oneshot 
204 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
205 ············RemainAfterExit=yes 
206 ············[Install] 
207 ············WantedBy=multi-user.target 
208 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*208 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
209 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.209 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
210 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.210 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
211 Severity: ···medium211 Severity: ···medium
212 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy212 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
213 Identifiers:·CCE-83445-7213 Identifiers:·CCE-83445-7
214 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453214 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
Offset 1145, 14 lines modifiedOffset 1145, 36 lines modified
1145 cat·<<EOF·>/etc/issue1145 cat·<<EOF·>/etc/issue
1146 $formatted1146 $formatted
1147 EOF1147 EOF
  
1148 else1148 else
1149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1149 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1150 fi1150 fi
 1151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1152 ---
 1153 apiVersion:·machineconfiguration.openshift.io/v1
 1154 kind:·MachineConfig
 1155 metadata:
 1156 ··labels:
 1157 ····machineconfiguration.openshift.io/role:·master
 1158 ····machineconfiguration.openshift.io/role:·worker
 1159 ··name:·75-banner-etc-issue
 1160 spec:
 1161 ··config:
 1162 ····ignition:
 1163 ······version:·3.1.0
 1164 ····storage:
 1165 ······files:
 1166 ······-·contents:
 1167 ··········source:·data:,You%20are%20accessing%20a%20U.S.%20Government%20%28USG%29%20Information%20System%20%28IS%29%20that%20is%20%0Aprovided%20for%20USG-authorized%20use%20only.%20By%20using%20this%20IS%20%28which%20includes%20any%20%0Adevice%20attached%20to%20this%20IS%29%2C%20you%20consent%20to%20the%20following%20conditions%3A%0A%0A-The%20USG%20routinely%20intercepts%20and%20monitors%20communications%20on%20this%20IS%20for%20%0Apurposes%20including%2C%20but%20not%20limited%20to%2C%20penetration%20testing%2C%20COMSEC%20monitoring%2C%20%0Anetwork%20operations%20and%20defense%2C%20personnel%20misconduct%20%28PM%29%2C%20law%20enforcement%20%0A%28LE%29%2C%20and%20counterintelligence%20%28CI%29%20investigations.%0A%0A-At%20any%20time%2C%20the%20USG%20may%20inspect%20and%20seize%20data%20stored%20on%20this%20IS.%0A%0A-
 1168 Communications%20using%2C%20or%20data%20stored%20on%2C%20this%20IS%20are%20not%20private%2C%20are%20subject%20%0Ato%20routine%20monitoring%2C%20interception%2C%20and%20search%2C%20and%20may%20be%20disclosed%20or%20used%20%0Afor%20any%20USG-authorized%20purpose.%0A%0A-This%20IS%20includes%20security%20measures%20%28e.g.%2C%20authentication%20and%20access%20controls%29%20%0Ato%20protect%20USG%20interests--not%20for%20your%20personal%20benefit%20or%20privacy.%0A%0A-
 1169 Notwithstanding%20the%20above%2C%20using%20this%20IS%20does%20not%20constitute%20consent%20to%20PM%2C%20LE%20%0Aor%20CI%20investigative%20searching%20or%20monitoring%20of%20the%20content%20of%20privileged%20%0Acommunications%2C%20or%20work%20product%2C%20related%20to%20personal%20representation%20or%20services%20%0Aby%20attorneys%2C%20psychotherapists%2C%20or%20clergy%2C%20and%20their%20assistants.%20Such%20%0Acommunications%20and%20work%20product%20are%20private%20and%20confidential.%20See%20User%20%0AAgreement%20for%20details.
 1170 ········mode:·0644
 1171 ········path:·/etc/issue.d/legal-notice
 1172 ········overwrite:·true
1151 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1152 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1153 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium1175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
1154 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1155 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown1177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
1156 -·name:·Gather·the·package·facts1178 -·name:·Gather·the·package·facts
1157 ··package_facts:1179 ··package_facts:
Offset 1190, 36 lines modifiedOffset 1212, 14 lines modified
1190 ··-·NIST-800-53-AC-8(c)1212 ··-·NIST-800-53-AC-8(c)
1191 ··-·banner_etc_issue1213 ··-·banner_etc_issue
1192 ··-·low_complexity1214 ··-·low_complexity
1193 ··-·medium_disruption1215 ··-·medium_disruption
1194 ··-·medium_severity1216 ··-·medium_severity
1195 ··-·no_reboot_needed1217 ··-·no_reboot_needed
1196 ··-·unknown_strategy1218 ··-·unknown_strategy
1197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
1198 --- 
1199 apiVersion:·machineconfiguration.openshift.io/v1 
Max diff block lines reached; 86626/95341 bytes (90.86%) of diff not shown.
1.72 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ccn_intermediate.html
    
Offset 15239, 192 lines modifiedOffset 15239, 192 lines modified
0003b860:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b860:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b870:·3d22·2369·646d·3932·3635·2220·7461·6269··="#idm9265"·tabi0003b870:·3d22·2369·646d·3932·3635·2220·7461·6269··="#idm9265"·tabi
0003b880:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b880:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b890:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b890:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b8a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b8a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b8b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b8b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b8c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b8c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b8d0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b8d0:·223e·5265·6d65·6469·6174·696f·6e20·4b75··">Remediation·Ku
0003b8e0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b8f0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b900:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b910:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b920:·3d22·6964·6d39·3236·3522·3e3c·7461·626c··="idm9265"><tabl 
0003b930:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b940:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b950:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b960:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b970:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:0003b8e0:·6265·726e·6574·6573·2073·6e69·7070·6574··bernetes·snippet
 0003b8f0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b900:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b910:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b920:·2069·643d·2269·646d·3932·3635·223e·3c74···id="idm9265"><t
 0003b930:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b940:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b950:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b960:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b970:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b980:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b990:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b9a0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b980:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td0003b9b0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b9c0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b9d0:·3a3c·2f74·683e·3c74·643e·7472·7565·3c2f··:</th><td>true</
0003b990:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b9a0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b9b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b9c0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b9d0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b9e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St0003b9e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b9f0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>0003b9f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
0003ba00:·7265·7374·7269·6374·3c2f·7464·3e3c·2f74··restrict</td></t0003ba00:·643e·7265·7374·7269·6374·3c2f·7464·3e3c··d>restrict</td><
0003ba10:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><0003ba10:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003ba20:·3e3c·636f·6465·3e2d·2d2d·0a61·7069·5665··><code>---.apiVe
 0003ba30:·7273·696f·6e3a·206d·6163·6869·6e65·636f··rsion:·machineco
 0003ba40:·6e66·6967·7572·6174·696f·6e2e·6f70·656e··nfiguration.open
 0003ba50:·7368·6966·742e·696f·2f76·310a·6b69·6e64··shift.io/v1.kind
 0003ba60:·3a20·4d61·6368·696e·6543·6f6e·6669·670a··:·MachineConfig.
 0003ba70:·7370·6563·3a0a·2020·636f·6e66·6967·3a0a··spec:.··config:.
 0003ba80:·2020·2020·6967·6e69·7469·6f6e·3a0a·2020······ignition:.··
 0003ba90:·2020·2020·7665·7273·696f·6e3a·2033·2e31······version:·3.1
 0003baa0:·2e30·0a20·2020·2073·7973·7465·6d64·3a0a··.0.····systemd:.
 0003bab0:·2020·2020·2020·756e·6974·733a·0a20·2020········units:.···
 0003bac0:·2020·2020·202d·206e·616d·653a·2063·6f6e·······-·name:·con
 0003bad0:·6669·6775·7265·2d63·7279·7074·6f2d·706f··figure-crypto-po
 0003bae0:·6c69·6379·2e73·6572·7669·6365·0a20·2020··licy.service.···
 0003baf0:·2020·2020·2020·2065·6e61·626c·6564·3a20·········enabled:·
 0003bb00:·7472·7565·0a20·2020·2020·2020·2020·2063··true.··········c
 0003bb10:·6f6e·7465·6e74·733a·207c·0a20·2020·2020··ontents:·|.·····
 0003bb20:·2020·2020·2020·205b·556e·6974·5d0a·2020·········[Unit].··
 0003bb30:·2020·2020·2020·2020·2020·4265·666f·7265············Before
 0003bb40:·3d6b·7562·656c·6574·2e73·6572·7669·6365··=kubelet.service
 0003bb50:·0a20·2020·2020·2020·2020·2020·205b·5365··.············[Se
 0003bb60:·7276·6963·655d·0a20·2020·2020·2020·2020··rvice].·········
 0003bb70:·2020·2054·7970·653d·6f6e·6573·686f·740a·····Type=oneshot.
 0003bb80:·2020·2020·2020·2020·2020·2020·4578·6563··············Exec
 0003bb90:·5374·6172·743d·7570·6461·7465·2d63·7279··Start=update-cry
 0003bba0:·7074·6f2d·706f·6c69·6369·6573·202d·2d73··pto-policies·--s
 0003bbb0:·6574·207b·7b2e·7661·725f·7379·7374·656d··et·{{.var_system
 0003bbc0:·5f63·7279·7074·6f5f·706f·6c69·6379·7d7d··_crypto_policy}}
 0003bbd0:·0a20·2020·2020·2020·2020·2020·2052·656d··.············Rem
 0003bbe0:·6169·6e41·6674·6572·4578·6974·3d79·6573··ainAfterExit=yes
 0003bbf0:·0a20·2020·2020·2020·2020·2020·205b·496e··.············[In
 0003bc00:·7374·616c·6c5d·0a20·2020·2020·2020·2020··stall].·········
 0003bc10:·2020·2057·616e·7465·6442·793d·6d75·6c74·····WantedBy=mult
 0003bc20:·692d·7573·6572·2e74·6172·6765·740a·3c2f··i-user.target.</
 0003bc30:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003bc40:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003bc50:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003bc60:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003bc70:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003bc80:·2369·646d·3932·3636·2220·7461·6269·6e64··#idm9266"·tabind
 0003bc90:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003bca0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003bcb0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003bcc0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003bcd0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003bce0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
 0003bcf0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
 0003bd00:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003bd10:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003bd20:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003bd30:·6964·6d39·3236·3622·3e3c·7461·626c·6520··idm9266"><table·
 0003bd40:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003bd50:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003bd60:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003bd70:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003bd80:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003bd90:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003bda0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003bdb0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003bdc0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003bdd0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003bde0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003bdf0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003be00:·7465·6779·3a3c·2f74·683e·3c74·643e·7265··tegy:</th><td>re
 0003be10:·7374·7269·6374·3c2f·7464·3e3c·2f74·723e··strict</td></tr>
 0003be20:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
0003ba20:·636f·6465·3e2d·206e·616d·653a·2058·4343··code>-·name:·XCC0003be30:·6465·3e2d·206e·616d·653a·2058·4343·4446··de>-·name:·XCCDF
0003ba30:·4446·2056·616c·7565·2076·6172·5f73·7973··DF·Value·var_sys0003be40:·2056·616c·7565·2076·6172·5f73·7973·7465···Value·var_syste
0003ba40:·7465·6d5f·6372·7970·746f·5f70·6f6c·6963··tem_crypto_polic0003be50:·6d5f·6372·7970·746f·5f70·6f6c·6963·7920··m_crypto_policy·
0003ba50:·7920·2320·7072·6f6d·6f74·6520·746f·2076··y·#·promote·to·v0003be60:·2320·7072·6f6d·6f74·6520·746f·2076·6172··#·promote·to·var
0003ba60:·6172·6961·626c·650a·2020·7365·745f·6661··ariable.··set_fa0003be70:·6961·626c·650a·2020·7365·745f·6661·6374··iable.··set_fact
0003ba70:·6374·3a0a·2020·2020·7661·725f·7379·7374··ct:.····var_syst0003be80:·3a0a·2020·2020·7661·725f·7379·7374·656d··:.····var_system
 0003be90:·5f63·7279·7074·6f5f·706f·6c69·6379·3a20··_crypto_policy:·
 0003bea0:·2121·7374·7220·3c61·6262·7220·7469·746c··!!str·<abbr·titl
 0003beb0:·653d·2266·726f·6d20·5072·6f66·696c·652f··e="from·Profile/
 0003bec0:·7265·6669·6e65·2d76·616c·7565·3a20·7863··refine-value:·xc
 0003bed0:·6364·665f·6f72·672e·7373·6770·726f·6a65··cdf_org.ssgproje
 0003bee0:·6374·2e63·6f6e·7465·6e74·5f76·616c·7565··ct.content_value
 0003bef0:·5f76·6172·5f73·7973·7465·6d5f·6372·7970··_var_system_cryp
 0003bf00:·746f·5f70·6f6c·6963·7922·3e44·4546·4155··to_policy">DEFAU
 0003bf10:·4c54·3c2f·6162·6272·3e0a·2020·7461·6773··LT</abbr>.··tags
 0003bf20:·3a0a·2020·2020·2d20·616c·7761·7973·0a0a··:.····-·always..
 0003bf30:·2d20·6e61·6d65·3a20·436f·6e66·6967·7572··-·name:·Configur
 0003bf40:·6520·5379·7374·656d·2043·7279·7074·6f67··e·System·Cryptog
 0003bf50:·7261·7068·7920·506f·6c69·6379·0a20·206c··raphy·Policy.··l
 0003bf60:·696e·6569·6e66·696c·653a·0a20·2020·2070··ineinfile:.····p
Max diff block lines reached; 1644654/1669798 bytes (98.49%) of diff not shown.
134 KB
html2text {}
    
Offset 124, 14 lines modifiedOffset 124, 39 lines modified
124 »       echo·"to·see·what·package·to·(re)install"·>&2124 »       echo·"to·see·what·package·to·(re)install"·>&2
  
125 »       false··#·end·with·an·error·code125 »       false··#·end·with·an·error·code
126 elif·test·"$rc"·!=·0;·then126 elif·test·"$rc"·!=·0;·then
127 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2127 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
128 »       false··#·end·with·an·error·code128 »       false··#·end·with·an·error·code
129 fi129 fi
 130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 135 ---
 136 apiVersion:·machineconfiguration.openshift.io/v1
 137 kind:·MachineConfig
 138 spec:
 139 ··config:
 140 ····ignition:
 141 ······version:·3.1.0
 142 ····systemd:
 143 ······units:
 144 ········-·name:·configure-crypto-policy.service
 145 ··········enabled:·true
 146 ··········contents:·|
 147 ············[Unit]
 148 ············Before=kubelet.service
 149 ············[Service]
 150 ············Type=oneshot
 151 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 152 ············RemainAfterExit=yes
 153 ············[Install]
 154 ············WantedBy=multi-user.target
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8155 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low156 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low157 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false158 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict159 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
135 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable160 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
136 ··set_fact:161 ··set_fact:
Offset 184, 39 lines modifiedOffset 209, 14 lines modified
184 ··-·PCI-DSSv4-2.2.7209 ··-·PCI-DSSv4-2.2.7
185 ··-·configure_crypto_policy210 ··-·configure_crypto_policy
186 ··-·high_severity211 ··-·high_severity
187 ··-·low_complexity212 ··-·low_complexity
188 ··-·low_disruption213 ··-·low_disruption
189 ··-·no_reboot_needed214 ··-·no_reboot_needed
190 ··-·restrict_strategy215 ··-·restrict_strategy
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
196 --- 
197 apiVersion:·machineconfiguration.openshift.io/v1 
198 kind:·MachineConfig 
199 spec: 
200 ··config: 
201 ····ignition: 
202 ······version:·3.1.0 
203 ····systemd: 
204 ······units: 
205 ········-·name:·configure-crypto-policy.service 
206 ··········enabled:·true 
207 ··········contents:·| 
208 ············[Unit] 
209 ············Before=kubelet.service 
210 ············[Service] 
211 ············Type=oneshot 
212 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
213 ············RemainAfterExit=yes 
214 ············[Install] 
215 ············WantedBy=multi-user.target 
216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*216 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
217 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.217 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
218 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.218 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
219 Severity: ···medium219 Severity: ···medium
220 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy220 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
221 Identifiers:·CCE-83445-7221 Identifiers:·CCE-83445-7
222 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453222 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
Offset 2245, 14 lines modifiedOffset 2245, 36 lines modified
2245 cat·<<EOF·>/etc/issue2245 cat·<<EOF·>/etc/issue
2246 $formatted2246 $formatted
2247 EOF2247 EOF
  
2248 else2248 else
2249 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'2249 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
2250 fi2250 fi
 2251 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2252 ---
 2253 apiVersion:·machineconfiguration.openshift.io/v1
 2254 kind:·MachineConfig
 2255 metadata:
 2256 ··labels:
 2257 ····machineconfiguration.openshift.io/role:·master
 2258 ····machineconfiguration.openshift.io/role:·worker
 2259 ··name:·75-banner-etc-issue
 2260 spec:
 2261 ··config:
 2262 ····ignition:
 2263 ······version:·3.1.0
 2264 ····storage:
 2265 ······files:
 2266 ······-·contents:
 2267 ··········source:·data:,You%20are%20accessing%20a%20U.S.%20Government%20%28USG%29%20Information%20System%20%28IS%29%20that%20is%20%0Aprovided%20for%20USG-authorized%20use%20only.%20By%20using%20this%20IS%20%28which%20includes%20any%20%0Adevice%20attached%20to%20this%20IS%29%2C%20you%20consent%20to%20the%20following%20conditions%3A%0A%0A-The%20USG%20routinely%20intercepts%20and%20monitors%20communications%20on%20this%20IS%20for%20%0Apurposes%20including%2C%20but%20not%20limited%20to%2C%20penetration%20testing%2C%20COMSEC%20monitoring%2C%20%0Anetwork%20operations%20and%20defense%2C%20personnel%20misconduct%20%28PM%29%2C%20law%20enforcement%20%0A%28LE%29%2C%20and%20counterintelligence%20%28CI%29%20investigations.%0A%0A-At%20any%20time%2C%20the%20USG%20may%20inspect%20and%20seize%20data%20stored%20on%20this%20IS.%0A%0A-
 2268 Communications%20using%2C%20or%20data%20stored%20on%2C%20this%20IS%20are%20not%20private%2C%20are%20subject%20%0Ato%20routine%20monitoring%2C%20interception%2C%20and%20search%2C%20and%20may%20be%20disclosed%20or%20used%20%0Afor%20any%20USG-authorized%20purpose.%0A%0A-This%20IS%20includes%20security%20measures%20%28e.g.%2C%20authentication%20and%20access%20controls%29%20%0Ato%20protect%20USG%20interests--not%20for%20your%20personal%20benefit%20or%20privacy.%0A%0A-
 2269 Notwithstanding%20the%20above%2C%20using%20this%20IS%20does%20not%20constitute%20consent%20to%20PM%2C%20LE%20%0Aor%20CI%20investigative%20searching%20or%20monitoring%20of%20the%20content%20of%20privileged%20%0Acommunications%2C%20or%20work%20product%2C%20related%20to%20personal%20representation%20or%20services%20%0Aby%20attorneys%2C%20psychotherapists%2C%20or%20clergy%2C%20and%20their%20assistants.%20Such%20%0Acommunications%20and%20work%20product%20are%20private%20and%20confidential.%20See%20User%20%0AAgreement%20for%20details.
 2270 ········mode:·0644
 2271 ········path:·/etc/issue.d/legal-notice
 2272 ········overwrite:·true
2251 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82273 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2252 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2274 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2253 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium2275 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
2254 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2276 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2255 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown2277 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···unknown
2256 -·name:·Gather·the·package·facts2278 -·name:·Gather·the·package·facts
2257 ··package_facts:2279 ··package_facts:
Offset 2290, 36 lines modifiedOffset 2312, 14 lines modified
2290 ··-·NIST-800-53-AC-8(c)2312 ··-·NIST-800-53-AC-8(c)
2291 ··-·banner_etc_issue2313 ··-·banner_etc_issue
2292 ··-·low_complexity2314 ··-·low_complexity
2293 ··-·medium_disruption2315 ··-·medium_disruption
2294 ··-·medium_severity2316 ··-·medium_severity
2295 ··-·no_reboot_needed2317 ··-·no_reboot_needed
2296 ··-·unknown_strategy2318 ··-·unknown_strategy
2297 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
2298 --- 
2299 apiVersion:·machineconfiguration.openshift.io/v1 
Max diff block lines reached; 128898/137613 bytes (93.67%) of diff not shown.
4.75 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis.html
    
Offset 15165, 284 lines modifiedOffset 15165, 284 lines modified
0003b3c0:·6574·3d22·2369·646d·3834·3538·2220·7461··et="#idm8458"·ta0003b3c0:·6574·3d22·2369·646d·3834·3538·2220·7461··et="#idm8458"·ta
0003b3d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=0003b3d0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b3e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex0003b3e0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b3f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t0003b3f0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b400:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t0003b400:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b410:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="0003b410:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b420:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·0003b420:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b430:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
0003b440:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
0003b450:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b460:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b470:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b480:·6d38·3435·3822·3e3c·7072·653e·3c63·6f64··m8458"><pre><cod 
0003b490:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
0003b4a0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
0003b4b0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
0003b4c0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b4d0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b4e0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b4f0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b500:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b510:·646d·3834·3539·2220·7461·6269·6e64·6578··dm8459"·tabindex 
0003b520:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b530:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b540:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b550:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b560:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b570:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
0003b580:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b0003b430:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
0003b590:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa0003b440:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003b5a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col0003b450:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003b5b0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm840003b460:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
0003b5c0:·3539·223e·3c74·6162·6c65·2063·6c61·7373··59"><table·class0003b470:·3538·223e·3c74·6162·6c65·2063·6c61·7373··58"><table·class
0003b5d0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st0003b480:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b5e0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord0003b490:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b5f0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde0003b4a0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
0003b600:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co0003b4b0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
0003b610:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t0003b4c0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
0003b620:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><0003b4d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
0003b630:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio0003b4e0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
0003b640:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</0003b4f0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
0003b650:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>0003b500:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
0003b660:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>0003b510:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
0003b670:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><0003b520:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
0003b680:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:0003b530:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
0003b690:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<0003b540:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b6a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table0003b550:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b6b0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re0003b560:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 0003b570:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
0003b6c0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
0003b6d0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
0003b6e0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
0003b6f0:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
0003b700:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
0003b710:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
0003b720:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
0003b730:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
0003b740:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
0003b750:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b760:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b770:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b780:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b790:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b7a0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d0003b580:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
0003b7b0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn0003b590:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003b7c0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da0003b5a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003b7d0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla0003b5b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003b7e0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b5c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003b7f0:·3d22·2369·646d·3834·3630·2220·7461·6269··="#idm8460"·tabi0003b5d0:·6574·3d22·2369·646d·3834·3539·2220·7461··et="#idm8459"·ta
0003b800:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b5e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b810:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b5f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b820:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b600:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b830:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b610:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b840:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b620:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b850:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b630:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0003b640:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 0003b650:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 0003b660:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 0003b670:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 0003b680:·2269·646d·3834·3539·223e·3c74·6162·6c65··"idm8459"><table
 0003b690:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 0003b6a0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 0003b6b0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 0003b6c0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 0003b6d0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 0003b6e0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 0003b6f0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 0003b700:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
0003b860:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b870:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b880:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b890:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b8a0:·3d22·6964·6d38·3436·3022·3e3c·7461·626c··="idm8460"><tabl 
0003b8b0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b8c0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b8d0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b8e0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b8f0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b900:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b910:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b920:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b930:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b940:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b950:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b960:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b970:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b980:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b990:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b9a0:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
0003b9b0:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
0003b9c0:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
0003b9d0:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
0003b9e0:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
0003b9f0:·202d·2043·4345·2d39·3038·3433·2d34·0a20···-·CCE-90843-4.· 
0003ba00:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003ba10:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R 
0003ba20:·4845·4c2d·3039·2d36·3531·3031·300a·2020··HEL-09-651010.·· 
0003ba30:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
0003ba40:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
0003ba50:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
0003ba60:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
0003ba70:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
0003ba80:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
0003ba90:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d 
0003baa0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me 
0003bab0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.·· 
0003bac0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need 
Max diff block lines reached; 4546396/4584236 bytes (99.17%) of diff not shown.
384 KB
html2text {}
    
Offset 112, 19 lines modifiedOffset 112, 21 lines modified
112 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5112 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
113 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199113 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
114 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79114 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
115 ·············_\x8c_\x8i_\x8s············6.1.1115 ·············_\x8c_\x8i_\x8s············6.1.1
116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2116 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
117 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010117 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
118 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule118 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 124 package·install·aide
120 [[packages]] 
121 name·=·"aide" 
122 version·=·"*" 
123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
124 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
125 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
126 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
127 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
128 #·Remediation·is·applicable·only·in·certain·platforms130 #·Remediation·is·applicable·only·in·certain·platforms
129 if·rpm·--quiet·-q·kernel;·then131 if·rpm·--quiet·-q·kernel;·then
Offset 172, 14 lines modifiedOffset 174, 26 lines modified
172 ··-·PCI-DSSv4-11.5.2174 ··-·PCI-DSSv4-11.5.2
173 ··-·enable_strategy175 ··-·enable_strategy
174 ··-·low_complexity176 ··-·low_complexity
175 ··-·low_disruption177 ··-·low_disruption
176 ··-·medium_severity178 ··-·medium_severity
177 ··-·no_reboot_needed179 ··-·no_reboot_needed
178 ··-·package_aide_installed180 ··-·package_aide_installed
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 186 package·--add=aide
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 188 [[packages]]
 189 name·=·"aide"
 190 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
184 dnf·install·aide196 dnf·install·aide
Offset 191, 28 lines modifiedOffset 205, 14 lines modified
191 include·install_aide205 include·install_aide
  
192 class·install_aide·{206 class·install_aide·{
193 ··package·{·'aide':207 ··package·{·'aide':
194 ····ensure·=>·'installed',208 ····ensure·=>·'installed',
195 ··}209 ··}
196 }210 }
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
202 package·install·aide 
203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
208 package·--add=aide 
209 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*211 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
210 Run·the·following·command·to·generate·a·new·database:212 Run·the·following·command·to·generate·a·new·database:
211 $·sudo·/usr/sbin/aide·--init213 $·sudo·/usr/sbin/aide·--init
212 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:214 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
213 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz215 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
214 To·initiate·a·manual·check,·run·the·following·command:216 To·initiate·a·manual·check,·run·the·following·command:
215 $·sudo·/usr/sbin/aide·--check217 $·sudo·/usr/sbin/aide·--check
Offset 777, 14 lines modifiedOffset 777, 39 lines modified
777 »       echo·"to·see·what·package·to·(re)install"·>&2777 »       echo·"to·see·what·package·to·(re)install"·>&2
  
778 »       false··#·end·with·an·error·code778 »       false··#·end·with·an·error·code
779 elif·test·"$rc"·!=·0;·then779 elif·test·"$rc"·!=·0;·then
780 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2780 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
781 »       false··#·end·with·an·error·code781 »       false··#·end·with·an·error·code
782 fi782 fi
 783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 784 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 785 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 786 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 787 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 788 ---
 789 apiVersion:·machineconfiguration.openshift.io/v1
 790 kind:·MachineConfig
 791 spec:
 792 ··config:
 793 ····ignition:
 794 ······version:·3.1.0
 795 ····systemd:
 796 ······units:
 797 ········-·name:·configure-crypto-policy.service
 798 ··········enabled:·true
 799 ··········contents:·|
 800 ············[Unit]
 801 ············Before=kubelet.service
 802 ············[Service]
 803 ············Type=oneshot
 804 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 805 ············RemainAfterExit=yes
 806 ············[Install]
 807 ············WantedBy=multi-user.target
783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8808 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
784 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low809 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
785 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low810 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
786 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false811 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
787 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict812 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
788 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable813 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
789 ··set_fact:814 ··set_fact:
Offset 837, 39 lines modifiedOffset 862, 14 lines modified
837 ··-·PCI-DSSv4-2.2.7862 ··-·PCI-DSSv4-2.2.7
838 ··-·configure_crypto_policy863 ··-·configure_crypto_policy
839 ··-·high_severity864 ··-·high_severity
840 ··-·low_complexity865 ··-·low_complexity
841 ··-·low_disruption866 ··-·low_disruption
842 ··-·no_reboot_needed867 ··-·no_reboot_needed
Max diff block lines reached; 388588/393444 bytes (98.77%) of diff not shown.
2.88 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_server_l1.html
    
Offset 15126, 285 lines modifiedOffset 15126, 285 lines modified
0003b150:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b150:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b160:·6964·6d38·3435·3822·2074·6162·696e·6465··idm8458"·tabinde0003b160:·6964·6d38·3435·3822·2074·6162·696e·6465··idm8458"·tabinde
0003b170:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b170:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b180:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b180:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b190:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b190:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b1a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b1a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b1b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b1b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b1c0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
0003b1d0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003b1e0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b1f0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b200:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b210:·7073·6522·2069·643d·2269·646d·3834·3538··pse"·id="idm8458 
0003b220:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[ 
0003b230:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003b240:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003b250:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></ 
0003b260:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
0003b270:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
0003b280:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
0003b290:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
0003b2a0:·2d74·6172·6765·743d·2223·6964·6d38·3435··-target="#idm845 
0003b2b0:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"· 
0003b2c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
0003b2d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
0003b2e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
0003b2f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
0003b300:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
0003b310:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip 
0003b320:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b330:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b340:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b350:·2220·6964·3d22·6964·6d38·3435·3922·3e3c··"·id="idm8459">< 
0003b360:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab 
0003b370:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped 
0003b380:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered· 
0003b390:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed" 
0003b3a0:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex 
0003b3b0:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low 
0003b3c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b3d0:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t 
0003b3e0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></ 
0003b3f0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo 
0003b400:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false 
0003b410:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b420:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th> 
0003b430:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td>< 
0003b440:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre 
0003b450:·3e3c·636f·6465·3e23·2052·656d·6564·6961··><code>#·Remedia 
0003b460:·7469·6f6e·2069·7320·6170·706c·6963·6162··tion·is·applicab 
0003b470:·6c65·206f·6e6c·7920·696e·2063·6572·7461··le·only·in·certa 
0003b480:·696e·2070·6c61·7466·6f72·6d73·0a69·6620··in·platforms.if· 
0003b490:·7270·6d20·2d2d·7175·6965·7420·2d71·206b··rpm·--quiet·-q·k 
0003b4a0:·6572·6e65·6c3b·2074·6865·6e0a·0a69·6620··ernel;·then..if· 
0003b4b0:·2120·7270·6d20·2d71·202d·2d71·7569·6574··!·rpm·-q·--quiet 
0003b4c0:·2022·6169·6465·2220·3b20·7468·656e·0a20···"aide"·;·then.· 
0003b4d0:·2020·2064·6e66·2069·6e73·7461·6c6c·202d·····dnf·install·- 
0003b4e0:·7920·2261·6964·6522·0a66·690a·0a65·6c73··y·"aide".fi..els 
0003b4f0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2 
0003b500:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati 
0003b510:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic 
0003b520:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa 
0003b530:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod 
0003b540:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003b550:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003b560:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003b570:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003b580:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003b590:·6d38·3436·3022·2074·6162·696e·6465·783d··m8460"·tabindex= 
0003b5a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003b5b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003b5c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003b5d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003b5e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003b5f0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible 
0003b600:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b610:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b620:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b630:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b640:·3834·3630·223e·3c74·6162·6c65·2063·6c61··8460"><table·cla 
0003b650:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
0003b660:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
0003b670:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
0003b680:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
0003b690:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th> 
0003b6a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
0003b6b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
0003b6c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
0003b6d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
0003b6e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
0003b6f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
0003b700:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg 
0003b710:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl 
0003b720:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab 
0003b730:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-· 
0003b740:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the 
0003b750:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.· 
0003b760:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:. 
0003b770:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut 
0003b780:·6f0a·2020·7461·6773·3a0a·2020·2d20·4343··o.··tags:.··-·CC 
0003b790:·452d·3930·3834·332d·340a·2020·2d20·434a··E-90843-4.··-·CJ 
0003b7a0:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-· 
0003b7b0:·4449·5341·2d53·5449·472d·5248·454c·2d30··DISA-STIG-RHEL-0 
0003b7c0:·392d·3635·3130·3130·0a20·202d·204e·4953··9-651010.··-·NIS 
0003b7d0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
0003b7e0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req 
0003b7f0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS 
0003b800:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e 
0003b810:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.· 
0003b820:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit 
0003b830:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup 
0003b840:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_ 
0003b850:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_ 
0003b860:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.·· 
0003b870:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i 
0003b880:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name 
0003b890:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is 
0003b8a0:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac 
0003b8b0:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:· 
0003b8c0:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:· 
0003b8d0:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:· 
0003b8e0:·2722·6b65·726e·656c·2220·696e·2061·6e73··'"kernel"·in·ans 
0003b8f0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa 
0003b900:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··- 
0003b910:·2043·4345·2d39·3038·3433·2d34·0a20·202d···CCE-90843-4.··- 
0003b920:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.· 
0003b930:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE 
Max diff block lines reached; 2712928/2750906 bytes (98.62%) of diff not shown.
263 KB
html2text {}
    
Offset 106, 19 lines modifiedOffset 106, 21 lines modified
106 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5106 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
108 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79108 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
109 ·············_\x8c_\x8i_\x8s············6.1.1109 ·············_\x8c_\x8i_\x8s············6.1.1
110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
111 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010111 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
112 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule112 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 118 package·install·aide
114 [[packages]] 
115 name·=·"aide" 
116 version·=·"*" 
117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8119 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low120 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low121 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false122 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable123 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
122 #·Remediation·is·applicable·only·in·certain·platforms124 #·Remediation·is·applicable·only·in·certain·platforms
123 if·rpm·--quiet·-q·kernel;·then125 if·rpm·--quiet·-q·kernel;·then
Offset 166, 14 lines modifiedOffset 168, 26 lines modified
166 ··-·PCI-DSSv4-11.5.2168 ··-·PCI-DSSv4-11.5.2
167 ··-·enable_strategy169 ··-·enable_strategy
168 ··-·low_complexity170 ··-·low_complexity
169 ··-·low_disruption171 ··-·low_disruption
170 ··-·medium_severity172 ··-·medium_severity
171 ··-·no_reboot_needed173 ··-·no_reboot_needed
172 ··-·package_aide_installed174 ··-·package_aide_installed
 175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 176 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 177 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 178 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 179 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 180 package·--add=aide
 181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 182 [[packages]]
 183 name·=·"aide"
 184 version·=·"*"
173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
174 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low186 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
175 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low187 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
176 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false188 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
177 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable189 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
178 dnf·install·aide190 dnf·install·aide
Offset 185, 28 lines modifiedOffset 199, 14 lines modified
185 include·install_aide199 include·install_aide
  
186 class·install_aide·{200 class·install_aide·{
187 ··package·{·'aide':201 ··package·{·'aide':
188 ····ensure·=>·'installed',202 ····ensure·=>·'installed',
189 ··}203 ··}
190 }204 }
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
196 package·install·aide 
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
202 package·--add=aide 
203 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*205 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
204 Run·the·following·command·to·generate·a·new·database:206 Run·the·following·command·to·generate·a·new·database:
205 $·sudo·/usr/sbin/aide·--init207 $·sudo·/usr/sbin/aide·--init
206 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:208 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
207 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz209 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
208 To·initiate·a·manual·check,·run·the·following·command:210 To·initiate·a·manual·check,·run·the·following·command:
209 $·sudo·/usr/sbin/aide·--check211 $·sudo·/usr/sbin/aide·--check
Offset 771, 14 lines modifiedOffset 771, 39 lines modified
771 »       echo·"to·see·what·package·to·(re)install"·>&2771 »       echo·"to·see·what·package·to·(re)install"·>&2
  
772 »       false··#·end·with·an·error·code772 »       false··#·end·with·an·error·code
773 elif·test·"$rc"·!=·0;·then773 elif·test·"$rc"·!=·0;·then
774 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2774 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
775 »       false··#·end·with·an·error·code775 »       false··#·end·with·an·error·code
776 fi776 fi
 777 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 778 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 779 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 780 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 781 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 782 ---
 783 apiVersion:·machineconfiguration.openshift.io/v1
 784 kind:·MachineConfig
 785 spec:
 786 ··config:
 787 ····ignition:
 788 ······version:·3.1.0
 789 ····systemd:
 790 ······units:
 791 ········-·name:·configure-crypto-policy.service
 792 ··········enabled:·true
 793 ··········contents:·|
 794 ············[Unit]
 795 ············Before=kubelet.service
 796 ············[Service]
 797 ············Type=oneshot
 798 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 799 ············RemainAfterExit=yes
 800 ············[Install]
 801 ············WantedBy=multi-user.target
777 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8802 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
778 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low803 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
779 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low804 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
780 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false805 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
781 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict806 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
782 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable807 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
783 ··set_fact:808 ··set_fact:
Offset 831, 39 lines modifiedOffset 856, 14 lines modified
831 ··-·PCI-DSSv4-2.2.7856 ··-·PCI-DSSv4-2.2.7
832 ··-·configure_crypto_policy857 ··-·configure_crypto_policy
833 ··-·high_severity858 ··-·high_severity
834 ··-·low_complexity859 ··-·low_complexity
835 ··-·low_disruption860 ··-·low_disruption
836 ··-·no_reboot_needed861 ··-·no_reboot_needed
Max diff block lines reached; 264746/269602 bytes (98.20%) of diff not shown.
2.56 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_workstation_l1.html
    
Offset 15118, 284 lines modifiedOffset 15118, 284 lines modified
0003b0d0:·6765·743d·2223·6964·6d38·3435·3822·2074··get="#idm8458"·t0003b0d0:·6765·743d·2223·6964·6d38·3435·3822·2074··get="#idm8458"·t
0003b0e0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b0e0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b0f0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b0f0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b100:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b100:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b110:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b110:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b120:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b120:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b130:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b130:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b140:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003b150:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003b160:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b170:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b180:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b190:·646d·3834·3538·223e·3c70·7265·3e3c·636f··dm8458"><pre><co 
0003b1a0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003b1b0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003b1c0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
0003b1d0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
0003b1e0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
0003b1f0:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
0003b200:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
0003b210:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
0003b220:·6964·6d38·3435·3922·2074·6162·696e·6465··idm8459"·tabinde 
0003b230:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
0003b240:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
0003b250:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
0003b260:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
0003b270:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
0003b280:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
0003b290:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><0003b140:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003b2a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003b150:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003b2b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003b160:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003b2c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003b170:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8
0003b2d0:·3435·3922·3e3c·7461·626c·6520·636c·6173··459"><table·clas0003b180:·3435·3822·3e3c·7461·626c·6520·636c·6173··458"><table·clas
0003b2e0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003b190:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
0003b2f0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b300:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond 
0003b310:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b320:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b330:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b340:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b350:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low< 
0003b360:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b370:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td 
0003b380:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr> 
0003b390:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
0003b3a0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
0003b3b0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
0003b3c0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R 
0003b3d0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003b3e0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003b3f0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003b400:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie 
0003b410:·7420·2d71·206b·6572·6e65·6c3b·2074·6865··t·-q·kernel;·the 
0003b420:·6e0a·0a69·6620·2120·7270·6d20·2d71·202d··n..if·!·rpm·-q·- 
0003b430:·2d71·7569·6574·2022·6169·6465·2220·3b20··-quiet·"aide"·;· 
0003b440:·7468·656e·0a20·2020·2064·6e66·2069·6e73··then.····dnf·ins 
0003b450:·7461·6c6c·202d·7920·2261·6964·6522·0a66··tall·-y·"aide".f 
0003b460:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003b470:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003b480:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003b490:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth 
0003b4a0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi 
0003b4b0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
0003b4c0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
0003b4d0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
0003b4e0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
0003b4f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
0003b500:·743d·2223·6964·6d38·3436·3022·2074·6162··t="#idm8460"·tab 
0003b510:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
0003b520:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
0003b530:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
0003b540:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
0003b550:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
0003b560:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A 
0003b570:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·. 
0003b580:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
0003b590:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
0003b5a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
0003b5b0:·643d·2269·646d·3834·3630·223e·3c74·6162··d="idm8460"><tab 
0003b5c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table· 
0003b5d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta 
0003b5e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab 
0003b5f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t 
0003b600:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity 
0003b610:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
0003b620:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D 
0003b630:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th>< 
0003b640:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b650:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:< 
0003b660:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t 
0003b670:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S 
0003b680:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td 
0003b690:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr 
0003b6a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
0003b6b0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath 
0003b6c0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f 
0003b6d0:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f 
0003b6e0:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage 
0003b6f0:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:. 
0003b700:·2020·2d20·4343·452d·3930·3834·332d·340a····-·CCE-90843-4. 
0003b710:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1. 
0003b720:·330a·2020·2d20·4449·5341·2d53·5449·472d··3.··-·DISA-STIG- 
0003b730:·5248·454c·2d30·392d·3635·3130·3130·0a20··RHEL-09-651010.· 
0003b740:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C 
0003b750:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D 
0003b760:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-· 
0003b770:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2 
0003b780:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra 
0003b790:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com 
0003b7a0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
0003b7b0:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m 
0003b7c0:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.· 
0003b7d0:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee 
0003b7e0:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_ 
0003b7f0:·6169·6465·5f69·6e73·7461·6c6c·6564·0a0a··aide_installed.. 
0003b800:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a 
0003b810:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed 
0003b820:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.···· 
0003b830:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s 
0003b840:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.·· 
0003b850:·7768·656e·3a20·2722·6b65·726e·656c·2220··when:·'"kernel"· 
0003b860:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts 
0003b870:·2e70·6163·6b61·6765·7327·0a20·2074·6167··.packages'.··tag 
0003b880:·733a·0a20·202d·2043·4345·2d39·3038·3433··s:.··-·CCE-90843 
0003b890:·2d34·0a20·202d·2043·4a49·532d·352e·3130··-4.··-·CJIS-5.10 
0003b8a0:·2e31·2e33·0a20·202d·2044·4953·412d·5354··.1.3.··-·DISA-ST 
0003b8b0:·4947·2d52·4845·4c2d·3039·2d36·3531·3031··IG-RHEL-09-65101 
Max diff block lines reached; 2408799/2446639 bytes (98.45%) of diff not shown.
237 KB
html2text {}
    
Offset 105, 19 lines modifiedOffset 105, 21 lines modified
105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5105 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199106 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79107 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
108 ·············_\x8c_\x8i_\x8s············6.1.1108 ·············_\x8c_\x8i_\x8s············6.1.1
109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2109 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
110 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010110 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
111 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule111 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8112 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 113 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 114 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 115 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 116 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 117 package·install·aide
113 [[packages]] 
114 name·=·"aide" 
115 version·=·"*" 
116 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
117 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
118 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
119 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
120 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
121 #·Remediation·is·applicable·only·in·certain·platforms123 #·Remediation·is·applicable·only·in·certain·platforms
122 if·rpm·--quiet·-q·kernel;·then124 if·rpm·--quiet·-q·kernel;·then
Offset 165, 14 lines modifiedOffset 167, 26 lines modified
165 ··-·PCI-DSSv4-11.5.2167 ··-·PCI-DSSv4-11.5.2
166 ··-·enable_strategy168 ··-·enable_strategy
167 ··-·low_complexity169 ··-·low_complexity
168 ··-·low_disruption170 ··-·low_disruption
169 ··-·medium_severity171 ··-·medium_severity
170 ··-·no_reboot_needed172 ··-·no_reboot_needed
171 ··-·package_aide_installed173 ··-·package_aide_installed
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 175 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 176 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 177 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 178 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 179 package·--add=aide
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 181 [[packages]]
 182 name·=·"aide"
 183 version·=·"*"
172 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8184 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
173 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low185 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
174 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low186 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
175 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false187 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
176 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable188 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
177 dnf·install·aide189 dnf·install·aide
Offset 184, 28 lines modifiedOffset 198, 14 lines modified
184 include·install_aide198 include·install_aide
  
185 class·install_aide·{199 class·install_aide·{
186 ··package·{·'aide':200 ··package·{·'aide':
187 ····ensure·=>·'installed',201 ····ensure·=>·'installed',
188 ··}202 ··}
189 }203 }
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
195 package·install·aide 
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
201 package·--add=aide 
202 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*204 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
203 Run·the·following·command·to·generate·a·new·database:205 Run·the·following·command·to·generate·a·new·database:
204 $·sudo·/usr/sbin/aide·--init206 $·sudo·/usr/sbin/aide·--init
205 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:207 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
206 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz208 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
207 To·initiate·a·manual·check,·run·the·following·command:209 To·initiate·a·manual·check,·run·the·following·command:
208 $·sudo·/usr/sbin/aide·--check210 $·sudo·/usr/sbin/aide·--check
Offset 770, 14 lines modifiedOffset 770, 39 lines modified
770 »       echo·"to·see·what·package·to·(re)install"·>&2770 »       echo·"to·see·what·package·to·(re)install"·>&2
  
771 »       false··#·end·with·an·error·code771 »       false··#·end·with·an·error·code
772 elif·test·"$rc"·!=·0;·then772 elif·test·"$rc"·!=·0;·then
773 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2773 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
774 »       false··#·end·with·an·error·code774 »       false··#·end·with·an·error·code
775 fi775 fi
 776 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 777 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 778 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 779 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 780 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 781 ---
 782 apiVersion:·machineconfiguration.openshift.io/v1
 783 kind:·MachineConfig
 784 spec:
 785 ··config:
 786 ····ignition:
 787 ······version:·3.1.0
 788 ····systemd:
 789 ······units:
 790 ········-·name:·configure-crypto-policy.service
 791 ··········enabled:·true
 792 ··········contents:·|
 793 ············[Unit]
 794 ············Before=kubelet.service
 795 ············[Service]
 796 ············Type=oneshot
 797 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 798 ············RemainAfterExit=yes
 799 ············[Install]
 800 ············WantedBy=multi-user.target
776 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8801 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
777 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low802 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
778 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low803 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
779 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false804 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
780 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict805 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
781 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable806 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
782 ··set_fact:807 ··set_fact:
Offset 830, 39 lines modifiedOffset 855, 14 lines modified
830 ··-·PCI-DSSv4-2.2.7855 ··-·PCI-DSSv4-2.2.7
831 ··-·configure_crypto_policy856 ··-·configure_crypto_policy
832 ··-·high_severity857 ··-·high_severity
833 ··-·low_complexity858 ··-·low_complexity
834 ··-·low_disruption859 ··-·low_disruption
835 ··-·no_reboot_needed860 ··-·no_reboot_needed
Max diff block lines reached; 237639/242495 bytes (98.00%) of diff not shown.
4.58 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cis_workstation_l2.html
    
Offset 15156, 285 lines modifiedOffset 15156, 285 lines modified
0003b330:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b330:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b340:·646d·3834·3538·2220·7461·6269·6e64·6578··dm8458"·tabindex0003b340:·646d·3834·3538·2220·7461·6269·6e64·6578··dm8458"·tabindex
0003b350:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b350:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b360:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b360:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b370:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b370:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b380:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b380:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b390:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b390:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b3a0:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b3a0:·6d65·6469·6174·696f·6e20·7363·7269·7074··mediation·script
0003b3b0:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b3c0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b3d0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b3e0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b3f0:·7365·2220·6964·3d22·6964·6d38·3435·3822··se"·id="idm8458" 
0003b400:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p 
0003b410:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b420:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b430:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p 
0003b440:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
0003b450:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
0003b460:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
0003b470:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
0003b480:·7461·7267·6574·3d22·2369·646d·3834·3539··target="#idm8459 
0003b490:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
0003b4a0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
0003b4b0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
0003b4c0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
0003b4d0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
0003b4e0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
0003b4f0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script 
0003b500:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div0003b3b0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
0003b510:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co0003b3c0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
0003b520:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"0003b3d0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
0003b530:·2069·643d·2269·646d·3834·3539·223e·3c74···id="idm8459"><t0003b3e0:·2069·643d·2269·646d·3834·3538·223e·3c74···id="idm8458"><t
0003b540:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl0003b3f0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
0003b550:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·0003b400:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
0003b560:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t0003b410:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
0003b570:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">0003b420:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
0003b580:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi0003b430:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
0003b590:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<0003b440:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
0003b5a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b450:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b5b0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th0003b460:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
0003b5c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b470:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b5d0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot0003b480:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
0003b5e0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b490:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
0003b5f0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b4a0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
0003b600:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><0003b4b0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
0003b610:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></0003b4c0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
0003b620:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>0003b4d0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b4e0:·3c63·6f64·653e·0a70·6163·6b61·6765·2069··<code>.package·i
 0003b4f0:·6e73·7461·6c6c·2061·6964·650a·3c2f·636f··nstall·aide.</co
0003b630:·3c63·6f64·653e·2320·5265·6d65·6469·6174··<code>#·Remediat 
0003b640:·696f·6e20·6973·2061·7070·6c69·6361·626c··ion·is·applicabl 
0003b650:·6520·6f6e·6c79·2069·6e20·6365·7274·6169··e·only·in·certai 
0003b660:·6e20·706c·6174·666f·726d·730a·6966·2072··n·platforms.if·r 
0003b670:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke 
0003b680:·726e·656c·3b20·7468·656e·0a0a·6966·2021··rnel;·then..if·! 
0003b690:·2072·706d·202d·7120·2d2d·7175·6965·7420···rpm·-q·--quiet· 
0003b6a0:·2261·6964·6522·203b·2074·6865·6e0a·2020··"aide"·;·then.·· 
0003b6b0:·2020·646e·6620·696e·7374·616c·6c20·2d79····dnf·install·-y 
0003b6c0:·2022·6169·6465·220a·6669·0a0a·656c·7365···"aide".fi..else 
0003b6d0:·0a20·2020·2026·6774·3b26·616d·703b·3220··.····&gt;&amp;2· 
0003b6e0:·6563·686f·2027·5265·6d65·6469·6174·696f··echo·'Remediatio 
0003b6f0:·6e20·6973·206e·6f74·2061·7070·6c69·6361··n·is·not·applica 
0003b700:·626c·652c·206e·6f74·6869·6e67·2077·6173··ble,·nothing·was 
0003b710:·2064·6f6e·6527·0a66·690a·3c2f·636f·6465···done'.fi.</code 
0003b720:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·0003b500:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
0003b730:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s0003b510:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
0003b740:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog0003b520:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
0003b750:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d0003b530:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse"
0003b760:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b540:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b770:·3834·3630·2220·7461·6269·6e64·6578·3d22··8460"·tabindex="0003b550:·646d·3834·3539·2220·7461·6269·6e64·6578··dm8459"·tabindex
0003b780:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b560:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b790:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b570:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b7a0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b580:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b7b0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b590:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b7c0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b5a0:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b7d0:·6469·6174·696f·6e20·416e·7369·626c·6520··diation·Ansible·0003b5b0:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003b7e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a><0003b5c0:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003b5d0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b5e0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b5f0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
 0003b600:·3539·223e·3c74·6162·6c65·2063·6c61·7373··59"><table·class
 0003b610:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
0003b7f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b800:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b810:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm8 
0003b820:·3436·3022·3e3c·7461·626c·6520·636c·6173··460"><table·clas 
0003b830:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s 
0003b840:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor 
0003b850:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003b620:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
0003b860:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C 
0003b870:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th>< 
0003b880:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr> 
0003b890:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti 
0003b8a0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003b630:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b640:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b650:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b660:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b670:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b680:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b690:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b6a0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b6b0:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b6c0:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b6d0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
0003b8b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003b6e0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b8c0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003b6f0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
 0003b700:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003b710:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003b720:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003b730:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet
 0003b740:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then
 0003b750:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·--
 0003b760:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t
 0003b770:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst
 0003b780:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi
 0003b790:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003b7a0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003b7b0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003b7c0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003b7d0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
 0003b7e0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003b7f0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b800:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
 0003b810:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
 0003b820:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
 0003b830:·3d22·2369·646d·3834·3630·2220·7461·6269··="#idm8460"·tabi
Max diff block lines reached; 4383783/4421761 bytes (99.14%) of diff not shown.
370 KB
html2text {}
    
Offset 111, 19 lines modifiedOffset 111, 21 lines modified
111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
112 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199112 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
113 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79113 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
114 ·············_\x8c_\x8i_\x8s············6.1.1114 ·············_\x8c_\x8i_\x8s············6.1.1
115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
116 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010116 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
117 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule117 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 123 package·install·aide
119 [[packages]] 
120 name·=·"aide" 
121 version·=·"*" 
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
127 #·Remediation·is·applicable·only·in·certain·platforms129 #·Remediation·is·applicable·only·in·certain·platforms
128 if·rpm·--quiet·-q·kernel;·then130 if·rpm·--quiet·-q·kernel;·then
Offset 171, 14 lines modifiedOffset 173, 26 lines modified
171 ··-·PCI-DSSv4-11.5.2173 ··-·PCI-DSSv4-11.5.2
172 ··-·enable_strategy174 ··-·enable_strategy
173 ··-·low_complexity175 ··-·low_complexity
174 ··-·low_disruption176 ··-·low_disruption
175 ··-·medium_severity177 ··-·medium_severity
176 ··-·no_reboot_needed178 ··-·no_reboot_needed
177 ··-·package_aide_installed179 ··-·package_aide_installed
 180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 185 package·--add=aide
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 187 [[packages]]
 188 name·=·"aide"
 189 version·=·"*"
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
183 dnf·install·aide195 dnf·install·aide
Offset 190, 28 lines modifiedOffset 204, 14 lines modified
190 include·install_aide204 include·install_aide
  
191 class·install_aide·{205 class·install_aide·{
192 ··package·{·'aide':206 ··package·{·'aide':
193 ····ensure·=>·'installed',207 ····ensure·=>·'installed',
194 ··}208 ··}
195 }209 }
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
201 package·install·aide 
202 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
203 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
204 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
205 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
206 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
207 package·--add=aide 
208 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*210 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
209 Run·the·following·command·to·generate·a·new·database:211 Run·the·following·command·to·generate·a·new·database:
210 $·sudo·/usr/sbin/aide·--init212 $·sudo·/usr/sbin/aide·--init
211 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:213 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
212 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz214 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
213 To·initiate·a·manual·check,·run·the·following·command:215 To·initiate·a·manual·check,·run·the·following·command:
214 $·sudo·/usr/sbin/aide·--check216 $·sudo·/usr/sbin/aide·--check
Offset 776, 14 lines modifiedOffset 776, 39 lines modified
776 »       echo·"to·see·what·package·to·(re)install"·>&2776 »       echo·"to·see·what·package·to·(re)install"·>&2
  
777 »       false··#·end·with·an·error·code777 »       false··#·end·with·an·error·code
778 elif·test·"$rc"·!=·0;·then778 elif·test·"$rc"·!=·0;·then
779 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2779 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
780 »       false··#·end·with·an·error·code780 »       false··#·end·with·an·error·code
781 fi781 fi
 782 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 783 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 784 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 785 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 786 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 787 ---
 788 apiVersion:·machineconfiguration.openshift.io/v1
 789 kind:·MachineConfig
 790 spec:
 791 ··config:
 792 ····ignition:
 793 ······version:·3.1.0
 794 ····systemd:
 795 ······units:
 796 ········-·name:·configure-crypto-policy.service
 797 ··········enabled:·true
 798 ··········contents:·|
 799 ············[Unit]
 800 ············Before=kubelet.service
 801 ············[Service]
 802 ············Type=oneshot
 803 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 804 ············RemainAfterExit=yes
 805 ············[Install]
 806 ············WantedBy=multi-user.target
782 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8807 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
783 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low808 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
784 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low809 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
785 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false810 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
786 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict811 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
787 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable812 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
788 ··set_fact:813 ··set_fact:
Offset 836, 39 lines modifiedOffset 861, 14 lines modified
836 ··-·PCI-DSSv4-2.2.7861 ··-·PCI-DSSv4-2.2.7
837 ··-·configure_crypto_policy862 ··-·configure_crypto_policy
838 ··-·high_severity863 ··-·high_severity
839 ··-·low_complexity864 ··-·low_complexity
840 ··-·low_disruption865 ··-·low_disruption
841 ··-·no_reboot_needed866 ··-·no_reboot_needed
Max diff block lines reached; 373956/378812 bytes (98.72%) of diff not shown.
3.18 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-cui.html
    
Offset 15474, 62 lines modifiedOffset 15474, 62 lines modified
0003c710:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003c710:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003c720:·646d·3930·3335·2220·7461·6269·6e64·6578··dm9035"·tabindex0003c720:·646d·3930·3335·2220·7461·6269·6e64·6578··dm9035"·tabindex
0003c730:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003c730:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003c740:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003c740:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003c750:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003c750:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003c760:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003c760:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003c770:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003c770:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003c780:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil 
0003c790:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003c7a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003c7b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003c7c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003c7d0:·7365·2220·6964·3d22·6964·6d39·3033·3522··se"·id="idm9035" 
0003c7e0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·6375··><pre><code>.[cu 
0003c7f0:·7374·6f6d·697a·6174·696f·6e73·5d0a·6669··stomizations].fi 
0003c800:·7073·203d·2074·7275·650a·3c2f·636f·6465··ps·=·true.</code 
0003c810:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003c820:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003c830:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003c840:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003c850:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003c860:·3930·3336·2220·7461·6269·6e64·6578·3d22··9036"·tabindex=" 
0003c870:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003c880:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003c890:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003c8a0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003c8b0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003c8c0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc0003c780:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003c8d0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>0003c790:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
0003c8e0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane0003c7a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
0003c8f0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla0003c7b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
0003c900:·7073·6522·2069·643d·2269·646d·3930·3336··pse"·id="idm90360003c7c0:·6c61·7073·6522·2069·643d·2269·646d·3930··lapse"·id="idm90
0003c910:·223e·3c70·7265·3e3c·636f·6465·3e23·2052··"><pre><code>#·R0003c7d0:·3335·223e·3c70·7265·3e3c·636f·6465·3e23··35"><pre><code>#
 0003c7e0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003c7f0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003c800:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003c810:·6f72·6d73·0a69·6620·2820·2120·2820·5b20··orms.if·(·!·(·[·
 0003c820:·2224·7b63·6f6e·7461·696e·6572·3a2d·7d22··"${container:-}"
 0003c830:·203d·3d20·2262·7772·6170·2d6f·7362·7569···==·"bwrap-osbui
 0003c840:·6c64·2220·5d20·2920·2661·6d70·3b26·616d··ld"·]·)·&amp;&am
 0003c850:·703b·2072·706d·202d·2d71·7569·6574·202d··p;·rpm·--quiet·-
 0003c860:·7120·6b65·726e·656c·2029·3b20·7468·656e··q·kernel·);·then
 0003c870:·0a0a·6966·205b·5b20·2224·4f53·4341·505f··..if·[[·"$OSCAP_
 0003c880:·424f·4f54·435f·4255·494c·4422·203d·3d20··BOOTC_BUILD"·==·
 0003c890:·2259·4553·2220·5d5d·3b20·7468·656e·0a09··"YES"·]];·then..
 0003c8a0:·6361·7420·2667·743b·202f·7573·722f·6c69··cat·&gt;·/usr/li
 0003c8b0:·622f·626f·6f74·632f·6b61·7267·732e·642f··b/bootc/kargs.d/
 0003c8c0:·3031·2d66·6970·732e·746f·6d6c·2026·6c74··01-fips.toml·&lt
 0003c8d0:·3b26·6c74·3b20·454f·460a·6b61·7267·7320··;&lt;·EOF.kargs·
 0003c8e0:·3d20·5b22·6669·7073·3d31·225d·0a45·4f46··=·["fips=1"].EOF
 0003c8f0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 0003c900:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
0003c920:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap0003c910:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
0003c930:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003c940:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003c950:·6d73·0a69·6620·2820·2120·2820·5b20·2224··ms.if·(·!·(·[·"$ 
0003c960:·7b63·6f6e·7461·696e·6572·3a2d·7d22·203d··{container:-}"·= 
0003c970:·3d20·2262·7772·6170·2d6f·7362·7569·6c64··=·"bwrap-osbuild 
0003c980:·2220·5d20·2920·2661·6d70·3b26·616d·703b··"·]·)·&amp;&amp; 
0003c990:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003c9a0:·6b65·726e·656c·2029·3b20·7468·656e·0a0a··kernel·);·then.. 
0003c9b0:·6966·205b·5b20·2224·4f53·4341·505f·424f··if·[[·"$OSCAP_BO 
0003c9c0:·4f54·435f·4255·494c·4422·203d·3d20·2259··OTC_BUILD"·==·"Y 
0003c9d0:·4553·2220·5d5d·3b20·7468·656e·0a09·6361··ES"·]];·then..ca 
0003c9e0:·7420·2667·743b·202f·7573·722f·6c69·622f··t·&gt;·/usr/lib/ 
0003c9f0:·626f·6f74·632f·6b61·7267·732e·642f·3031··bootc/kargs.d/01 
0003ca00:·2d66·6970·732e·746f·6d6c·2026·6c74·3b26··-fips.toml·&lt;& 
0003ca10:·6c74·3b20·454f·460a·6b61·7267·7320·3d20··lt;·EOF.kargs·=· 
0003ca20:·5b22·6669·7073·3d31·225d·0a45·4f46·0a66··["fips=1"].EOF.f 
0003ca30:·690a·0a65·6c73·650a·2020·2020·2667·743b··i..else.····&gt; 
0003ca40:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
0003ca50:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not· 
0003ca60:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth0003c920:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
0003ca70:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi0003c930:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 0003c940:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 0003c950:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 0003c960:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 0003c970:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 0003c980:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 0003c990:·6765·743d·2223·6964·6d39·3033·3622·2074··get="#idm9036"·t
 0003c9a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 0003c9b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 0003c9c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 0003c9d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 0003c9e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 0003c9f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 0003ca00:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri
 0003ca10:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</
 0003ca20:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003ca30:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003ca40:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003ca50:·646d·3930·3336·223e·3c70·7265·3e3c·636f··dm9036"><pre><co
 0003ca60:·6465·3e0a·5b63·7573·746f·6d69·7a61·7469··de>.[customizati
 0003ca70:·6f6e·735d·0a66·6970·7320·3d20·7472·7565··ons].fips·=·true
0003ca80:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></0003ca80:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003ca90:·6469·763e·3c2f·6469·763e·3c2f·7464·3e3c··div></div></td><0003ca90:·6469·763e·3c2f·6469·763e·3c2f·7464·3e3c··div></div></td><
0003caa0:·2f74·723e·3c2f·7462·6f64·793e·3c2f·7461··/tr></tbody></ta0003caa0:·2f74·723e·3c2f·7462·6f64·793e·3c2f·7461··/tr></tbody></ta
0003cab0:·626c·653e·3c2f·7464·3e3c·2f74·723e·3c74··ble></td></tr><t0003cab0:·626c·653e·3c2f·7464·3e3c·2f74·723e·3c74··ble></td></tr><t
0003cac0:·7220·6461·7461·2d74·742d·6964·3d22·6368··r·data-tt-id="ch0003cac0:·7220·6461·7461·2d74·742d·6964·3d22·6368··r·data-tt-id="ch
0003cad0:·696c·6472·656e·2d78·6363·6466·5f6f·7267··ildren-xccdf_org0003cad0:·696c·6472·656e·2d78·6363·6466·5f6f·7267··ildren-xccdf_org
0003cae0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont0003cae0:·2e73·7367·7072·6f6a·6563·742e·636f·6e74··.ssgproject.cont
Offset 15843, 254 lines modifiedOffset 15843, 254 lines modified
0003de20:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003de20:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003de30:·6964·6d39·3136·3922·2074·6162·696e·6465··idm9169"·tabinde0003de30:·6964·6d39·3136·3922·2074·6162·696e·6465··idm9169"·tabinde
0003de40:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003de40:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003de50:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003de50:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003de60:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003de60:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003de70:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003de70:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003de80:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003de80:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003de90:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003de90:·656d·6564·6961·7469·6f6e·2073·6372·6970··emediation·scrip
 0003dea0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003deb0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003dec0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003ded0:·2220·6964·3d22·6964·6d39·3136·3922·3e3c··"·id="idm9169"><
 0003dee0:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003def0:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003df00:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003df10:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003df20:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003df30:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003df40:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003df50:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
0003dea0:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003deb0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003dec0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003ded0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003dee0:·7073·6522·2069·643d·2269·646d·3931·3639··pse"·id="idm9169 
Max diff block lines reached; 2935867/2977183 bytes (98.61%) of diff not shown.
350 KB
html2text {}
    
Offset 119, 31 lines modifiedOffset 119, 31 lines modified
119 ·············_\x8i_\x8s_\x8m······1446119 ·············_\x8i_\x8s_\x8m······1446
120 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1120 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
121 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12121 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
122 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1122 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010
125 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule125 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
127 [customizations] 
128 fips·=·true 
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
130 #·Remediation·is·applicable·only·in·certain·platforms127 #·Remediation·is·applicable·only·in·certain·platforms
131 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then128 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
132 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then129 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
133 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF130 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
134 kargs·=·["fips=1"]131 kargs·=·["fips=1"]
135 EOF132 EOF
136 fi133 fi
  
137 else134 else
138 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'135 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
139 fi136 fi
 137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 138 [customizations]
 139 fips·=·true
140 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules140 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules
141 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:141 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
142 ····*·GnuTLS·library142 ····*·GnuTLS·library
143 ····*·OpenSSL·library143 ····*·OpenSSL·library
144 ····*·NSS·library144 ····*·NSS·library
145 ····*·OpenJDK145 ····*·OpenJDK
146 ····*·Libkrb5146 ····*·Libkrb5
Offset 158, 19 lines modifiedOffset 158, 21 lines modified
158 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed158 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
159 Identifiers:·CCE-83442-4159 Identifiers:·CCE-83442-4
160 ·············_\x8d_\x8i_\x8s_\x8a····CCI-002890,·CCI-002450,·CCI-003123160 ·············_\x8d_\x8i_\x8s_\x8a····CCI-002890,·CCI-002450,·CCI-003123
161 ·············_\x8o_\x8s_\x8p_\x8p····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1161 ·············_\x8o_\x8s_\x8p_\x8p····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
162 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174162 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
163 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··RHEL-09-215100163 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··RHEL-09-215100
164 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-258234r1051250_rule164 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-258234r1051250_rule
165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 170 package·install·crypto-policies
166 [[packages]] 
167 name·=·"crypto-policies" 
168 version·=·"*" 
169 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
170 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
171 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
172 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
173 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
174 if·!·rpm·-q·--quiet·"crypto-policies"·;·then176 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 190, 14 lines modifiedOffset 192, 26 lines modified
190 ··-·DISA-STIG-RHEL-09-215100192 ··-·DISA-STIG-RHEL-09-215100
191 ··-·enable_strategy193 ··-·enable_strategy
192 ··-·low_complexity194 ··-·low_complexity
193 ··-·low_disruption195 ··-·low_disruption
194 ··-·medium_severity196 ··-·medium_severity
195 ··-·no_reboot_needed197 ··-·no_reboot_needed
196 ··-·package_crypto-policies_installed198 ··-·package_crypto-policies_installed
 199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 200 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 201 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 202 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 203 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 204 package·--add=crypto-policies
 205 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 206 [[packages]]
 207 name·=·"crypto-policies"
 208 version·=·"*"
197 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8209 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
198 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low210 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
199 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low211 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
200 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false212 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
201 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable213 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
202 dnf·install·crypto-policies214 dnf·install·crypto-policies
Offset 209, 28 lines modifiedOffset 223, 14 lines modified
209 include·install_crypto-policies223 include·install_crypto-policies
  
210 class·install_crypto-policies·{224 class·install_crypto-policies·{
211 ··package·{·'crypto-policies':225 ··package·{·'crypto-policies':
212 ····ensure·=>·'installed',226 ····ensure·=>·'installed',
213 ··}227 ··}
214 }228 }
215 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
216 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
217 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
218 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
219 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
220 package·install·crypto-policies 
221 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
222 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
223 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
224 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
225 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
226 package·--add=crypto-policies 
227 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*229 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
228 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS·policy,·run·the·following·command:230 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS·policy,·run·the·following·command:
229 $·sudo·update-crypto-policies·--set·FIPS231 $·sudo·update-crypto-policies·--set·FIPS
230 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.232 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
231 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.233 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
232 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.234 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
233 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.235 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 264, 14 lines modifiedOffset 264, 39 lines modified
264 »       echo·"to·see·what·package·to·(re)install"·>&2264 »       echo·"to·see·what·package·to·(re)install"·>&2
  
265 »       false··#·end·with·an·error·code265 »       false··#·end·with·an·error·code
266 elif·test·"$rc"·!=·0;·then266 elif·test·"$rc"·!=·0;·then
267 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2267 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
268 »       false··#·end·with·an·error·code268 »       false··#·end·with·an·error·code
269 fi269 fi
 270 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 271 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 272 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 349891/358231 bytes (97.67%) of diff not shown.
1.99 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-e8.html
    
Offset 17677, 192 lines modifiedOffset 17677, 192 lines modified
000450c0:·612d·7461·7267·6574·3d22·2369·646d·3932··a-target="#idm92000450c0:·612d·7461·7267·6574·3d22·2369·646d·3932··a-target="#idm92
000450d0:·3635·2220·7461·6269·6e64·6578·3d22·3022··65"·tabindex="0"000450d0:·3635·2220·7461·6269·6e64·6578·3d22·3022··65"·tabindex="0"
000450e0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a000450e0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
000450f0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa000450f0:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
00045100:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti00045100:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
00045110:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·00045110:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
00045120:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi00045120:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
00045130:·6174·696f·6e20·416e·7369·626c·6520·736e··ation·Ansible·sn 
00045140:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
00045150:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
00045160:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
00045170:·6170·7365·2220·6964·3d22·6964·6d39·3236··apse"·id="idm926 
00045180:·3522·3e3c·7461·626c·6520·636c·6173·733d··5"><table·class= 
00045190:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str 
000451a0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde 
000451b0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden 
000451c0:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com 
000451d0:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td 
000451e0:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t 
000451f0:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption 
00045200:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t 
00045210:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R 
00045220:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f 
00045230:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t 
00045240:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:< 
00045250:·2f74·683e·3c74·643e·7265·7374·7269·6374··/th><td>restrict 
00045260:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00045270:·653e·3c70·7265·3e3c·636f·6465·3e2d·206e··e><pre><code>-·n 
00045280:·616d·653a·2058·4343·4446·2056·616c·7565··ame:·XCCDF·Value 
00045290:·2076·6172·5f73·7973·7465·6d5f·6372·7970···var_system_cryp 
000452a0:·746f·5f70·6f6c·6963·7920·2320·7072·6f6d··to_policy·#·prom 
000452b0:·6f74·6520·746f·2076·6172·6961·626c·650a··ote·to·variable. 
000452c0:·2020·7365·745f·6661·6374·3a0a·2020·2020····set_fact:.···· 
000452d0:·7661·725f·7379·7374·656d·5f63·7279·7074··var_system_crypt 
000452e0:·6f5f·706f·6c69·6379·3a20·2121·7374·7220··o_policy:·!!str· 
000452f0:·3c61·6262·7220·7469·746c·653d·2266·726f··<abbr·title="fro 
00045300:·6d20·5072·6f66·696c·652f·7265·6669·6e65··m·Profile/refine 
00045310:·2d76·616c·7565·3a20·7863·6364·665f·6f72··-value:·xccdf_or 
00045320:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con 
00045330:·7465·6e74·5f76·616c·7565·5f76·6172·5f73··tent_value_var_s 
00045340:·7973·7465·6d5f·6372·7970·746f·5f70·6f6c··ystem_crypto_pol 
00045350:·6963·7922·3e44·4546·4155·4c54·3a4e·4f2d··icy">DEFAULT:NO- 
00045360:·5348·4131·3c2f·6162·6272·3e0a·2020·7461··SHA1</abbr>.··ta 
00045370:·6773·3a0a·2020·2020·2d20·616c·7761·7973··gs:.····-·always 
00045380:·0a0a·2d20·6e61·6d65·3a20·436f·6e66·6967··..-·name:·Config 
00045390:·7572·6520·5379·7374·656d·2043·7279·7074··ure·System·Crypt 
000453a0:·6f67·7261·7068·7920·506f·6c69·6379·0a20··ography·Policy.· 
000453b0:·206c·696e·6569·6e66·696c·653a·0a20·2020···lineinfile:.··· 
000453c0:·2070·6174·683a·202f·6574·632f·6372·7970···path:·/etc/cryp 
000453d0:·746f·2d70·6f6c·6963·6965·732f·636f·6e66··to-policies/conf 
000453e0:·6967·0a20·2020·2072·6567·6578·703a·205e··ig.····regexp:·^ 
000453f0:·283f·2123·2928·5c53·2b29·240a·2020·2020··(?!#)(\S+)$.···· 
00045400:·6c69·6e65·3a20·277b·7b20·7661·725f·7379··line:·'{{·var_sy 
00045410:·7374·656d·5f63·7279·7074·6f5f·706f·6c69··stem_crypto_poli 
00045420:·6379·207d·7d27·0a20·2020·2063·7265·6174··cy·}}'.····creat 
00045430:·653a·2074·7275·650a·2020·7461·6773·3a0a··e:·true.··tags:. 
00045440:·2020·2d20·4343·452d·3833·3435·302d·370a····-·CCE-83450-7. 
00045450:·2020·2d20·4449·5341·2d53·5449·472d·5248····-·DISA-STIG-RH 
00045460:·454c·2d30·392d·3231·3531·3035·0a20·202d··EL-09-215105.··- 
00045470:·2044·4953·412d·5354·4947·2d52·4845·4c2d···DISA-STIG-RHEL- 
00045480:·3039·2d36·3731·3031·300a·2020·2d20·4449··09-671010.··-·DI 
00045490:·5341·2d53·5449·472d·5248·454c·2d30·392d··SA-STIG-RHEL-09- 
000454a0:·3637·3230·3330·0a20·202d·204e·4953·542d··672030.··-·NIST- 
000454b0:·3830·302d·3533·2d41·432d·3137·2832·290a··800-53-AC-17(2). 
000454c0:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
000454d0:·4143·2d31·3728·6129·0a20·202d·204e·4953··AC-17(a).··-·NIS 
000454e0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a) 
000454f0:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53 
00045500:·2d4d·412d·3428·3629·0a20·202d·204e·4953··-MA-4(6).··-·NIS 
00045510:·542d·3830·302d·3533·2d53·432d·3132·2832··T-800-53-SC-12(2 
00045520:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
00045530:·332d·5343·2d31·3228·3329·0a20·202d·204e··3-SC-12(3).··-·N 
00045540:·4953·542d·3830·302d·3533·2d53·432d·3133··IST-800-53-SC-13 
00045550:·0a20·202d·2050·4349·2d44·5353·7634·2d32··.··-·PCI-DSSv4-2 
00045560:·2e32·0a20·202d·2050·4349·2d44·5353·7634··.2.··-·PCI-DSSv4 
00045570:·2d32·2e32·2e37·0a20·202d·2063·6f6e·6669··-2.2.7.··-·confi 
00045580:·6775·7265·5f63·7279·7074·6f5f·706f·6c69··gure_crypto_poli 
00045590:·6379·0a20·202d·2068·6967·685f·7365·7665··cy.··-·high_seve 
000455a0:·7269·7479·0a20·202d·206c·6f77·5f63·6f6d··rity.··-·low_com 
000455b0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_ 
000455c0:·6469·7372·7570·7469·6f6e·0a20·202d·206e··disruption.··-·n 
000455d0:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed. 
000455e0:·2020·2d20·7265·7374·7269·6374·5f73·7472····-·restrict_str 
000455f0:·6174·6567·790a·0a2d·206e·616d·653a·2056··ategy..-·name:·V 
00045600:·6572·6966·7920·7468·6174·2043·7279·7074··erify·that·Crypt 
00045610:·6f20·506f·6c69·6379·2069·7320·5365·7420··o·Policy·is·Set· 
00045620:·2872·756e·7469·6d65·290a·2020·636f·6d6d··(runtime).··comm 
00045630:·616e·643a·202f·7573·722f·6269·6e2f·7570··and:·/usr/bin/up 
00045640:·6461·7465·2d63·7279·7074·6f2d·706f·6c69··date-crypto-poli 
00045650:·6369·6573·202d·2d73·6574·207b·7b20·7661··cies·--set·{{·va 
00045660:·725f·7379·7374·656d·5f63·7279·7074·6f5f··r_system_crypto_ 
00045670:·706f·6c69·6379·207d·7d0a·2020·7461·6773··policy·}}.··tags 
00045680:·3a0a·2020·2d20·4343·452d·3833·3435·302d··:.··-·CCE-83450- 
00045690:·370a·2020·2d20·4449·5341·2d53·5449·472d··7.··-·DISA-STIG- 
000456a0:·5248·454c·2d30·392d·3231·3531·3035·0a20··RHEL-09-215105.· 
000456b0:·202d·2044·4953·412d·5354·4947·2d52·4845···-·DISA-STIG-RHE 
000456c0:·4c2d·3039·2d36·3731·3031·300a·2020·2d20··L-09-671010.··-· 
000456d0:·4449·5341·2d53·5449·472d·5248·454c·2d30··DISA-STIG-RHEL-0 
000456e0:·392d·3637·3230·3330·0a20·202d·204e·4953··9-672030.··-·NIS 
000456f0:·542d·3830·302d·3533·2d41·432d·3137·2832··T-800-53-AC-17(2 
00045700:·290a·2020·2d20·4e49·5354·2d38·3030·2d35··).··-·NIST-800-5 
00045710:·332d·4143·2d31·3728·6129·0a20·202d·204e··3-AC-17(a).··-·N 
00045720:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6( 
00045730:·6129·0a20·202d·204e·4953·542d·3830·302d··a).··-·NIST-800- 
00045740:·3533·2d4d·412d·3428·3629·0a20·202d·204e··53-MA-4(6).··-·N 
00045750:·4953·542d·3830·302d·3533·2d53·432d·3132··IST-800-53-SC-12 
00045760:·2832·290a·2020·2d20·4e49·5354·2d38·3030··(2).··-·NIST-800 
00045770:·2d35·332d·5343·2d31·3228·3329·0a20·202d··-53-SC-12(3).··- 
00045780:·204e·4953·542d·3830·302d·3533·2d53·432d···NIST-800-53-SC- 
00045790:·3133·0a20·202d·2050·4349·2d44·5353·7634··13.··-·PCI-DSSv4 
000457a0:·2d32·2e32·0a20·202d·2050·4349·2d44·5353··-2.2.··-·PCI-DSS 
000457b0:·7634·2d32·2e32·2e37·0a20·202d·2063·6f6e··v4-2.2.7.··-·con 
000457c0:·6669·6775·7265·5f63·7279·7074·6f5f·706f··figure_crypto_po 
000457d0:·6c69·6379·0a20·202d·2068·6967·685f·7365··licy.··-·high_se 
000457e0:·7665·7269·7479·0a20·202d·206c·6f77·5f63··verity.··-·low_c 
000457f0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo 
00045800:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··- 
00045810:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede 
00045820:·640a·2020·2d20·7265·7374·7269·6374·5f73··d.··-·restrict_s 
00045830:·7472·6174·6567·790a·3c2f·636f·6465·3e3c··trategy.</code>< 
00045840:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
00045850:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
00045860:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
00045870:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
00045880:·612d·7461·7267·6574·3d22·2369·646d·3932··a-target="#idm92 
00045890:·3637·2220·7461·6269·6e64·6578·3d22·3022··67"·tabindex="0" 
000458a0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
Max diff block lines reached; 1893276/1918420 bytes (98.69%) of diff not shown.
164 KB
html2text {}
    
Offset 720, 14 lines modifiedOffset 720, 39 lines modified
720 »       echo·"to·see·what·package·to·(re)install"·>&2720 »       echo·"to·see·what·package·to·(re)install"·>&2
  
721 »       false··#·end·with·an·error·code721 »       false··#·end·with·an·error·code
722 elif·test·"$rc"·!=·0;·then722 elif·test·"$rc"·!=·0;·then
723 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2723 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
724 »       false··#·end·with·an·error·code724 »       false··#·end·with·an·error·code
725 fi725 fi
 726 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 727 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 728 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 729 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 730 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 731 ---
 732 apiVersion:·machineconfiguration.openshift.io/v1
 733 kind:·MachineConfig
 734 spec:
 735 ··config:
 736 ····ignition:
 737 ······version:·3.1.0
 738 ····systemd:
 739 ······units:
 740 ········-·name:·configure-crypto-policy.service
 741 ··········enabled:·true
 742 ··········contents:·|
 743 ············[Unit]
 744 ············Before=kubelet.service
 745 ············[Service]
 746 ············Type=oneshot
 747 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 748 ············RemainAfterExit=yes
 749 ············[Install]
 750 ············WantedBy=multi-user.target
726 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
727 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low752 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
728 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low753 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
729 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false754 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
730 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict755 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
731 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable756 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
732 ··set_fact:757 ··set_fact:
Offset 780, 39 lines modifiedOffset 805, 14 lines modified
780 ··-·PCI-DSSv4-2.2.7805 ··-·PCI-DSSv4-2.2.7
781 ··-·configure_crypto_policy806 ··-·configure_crypto_policy
782 ··-·high_severity807 ··-·high_severity
783 ··-·low_complexity808 ··-·low_complexity
784 ··-·low_disruption809 ··-·low_disruption
785 ··-·no_reboot_needed810 ··-·no_reboot_needed
786 ··-·restrict_strategy811 ··-·restrict_strategy
787 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
788 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
789 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
790 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
791 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
792 --- 
793 apiVersion:·machineconfiguration.openshift.io/v1 
794 kind:·MachineConfig 
795 spec: 
796 ··config: 
797 ····ignition: 
798 ······version:·3.1.0 
799 ····systemd: 
800 ······units: 
801 ········-·name:·configure-crypto-policy.service 
802 ··········enabled:·true 
803 ··········contents:·| 
804 ············[Unit] 
805 ············Before=kubelet.service 
806 ············[Service] 
807 ············Type=oneshot 
808 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
809 ············RemainAfterExit=yes 
810 ············[Install] 
811 ············WantedBy=multi-user.target 
812 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*812 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
813 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.813 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
814 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.814 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
815 Severity: ···medium815 Severity: ···medium
816 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy816 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
817 Identifiers:·CCE-83445-7817 Identifiers:·CCE-83445-7
818 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453818 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
Offset 1169, 19 lines modifiedOffset 1169, 21 lines modified
1169 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*1169 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·r\x8re\x8ea\x8ar\x8r·P\x8Pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
1170 The·rear·package·can·be·installed·with·the·following·command:1170 The·rear·package·can·be·installed·with·the·following·command:
1171 $·sudo·dnf·install·rear1171 $·sudo·dnf·install·rear
1172 Rationale:···rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.1172 Rationale:···rear·contains·the·Relax-and-Recover·(ReaR)·utility.·ReaR·produces·a·bootable·image·of·a·system·and·restores·from·backup·using·this·image.
1173 Severity: ···medium1173 Severity: ···medium
1174 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_rear_installed1174 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_rear_installed
1175 Identifiers:·CCE-83503-31175 Identifiers:·CCE-83503-3
1176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81176 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1177 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1178 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1179 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1180 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1181 package·install·rear
1177 [[packages]] 
1178 name·=·"rear" 
1179 version·=·"*" 
1180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1185 #·Remediation·is·applicable·only·in·certain·platforms1187 #·Remediation·is·applicable·only·in·certain·platforms
1186 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then1188 if·!·(·(·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?ol[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·(·grep·-sqE·"^.*\.aarch64$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^aarch64$"·/proc/sys/kernel/arch;·)·&&·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="9.0";·printf·"%s\n%s"·"$expected"·"$real"·|·sort·-VC;·}·)·||·(·grep·-qP·"^ID=[\"']?rhel[\"']?$"·"/etc/os-release"·&&·{·real="$(grep·-P·"^VERSION_ID=[\"']?[\w.]+[\"']?$"·/etc/os-release·|·sed·"s/^VERSION_ID=[\"']\?\([^\"']\+\)[\"']\?$/\1/")";·expected="8.4";·printf·"%s\n%s"·"$real"·"$expected"·|·sort·-VC;·}·&&·(·grep·-sqE·"^.*\.s390x$"·/proc/sys/kernel/osrelease·||·grep·-sqE·"^s390x$"·/proc/sys/kernel/arch;·)·)·)·);·then
Offset 1211, 14 lines modifiedOffset 1213, 26 lines modified
1211 ··-·CCE-83503-31213 ··-·CCE-83503-3
1212 ··-·enable_strategy1214 ··-·enable_strategy
1213 ··-·low_complexity1215 ··-·low_complexity
1214 ··-·low_disruption1216 ··-·low_disruption
1215 ··-·medium_severity1217 ··-·medium_severity
1216 ··-·no_reboot_needed1218 ··-·no_reboot_needed
1217 ··-·package_rear_installed1219 ··-·package_rear_installed
 1220 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1221 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1222 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1223 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1224 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 1225 package·--add=rear
 1226 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1227 [[packages]]
 1228 name·=·"rear"
 1229 version·=·"*"
1218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81230 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1231 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1232 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 161417/167657 bytes (96.28%) of diff not shown.
1.95 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-hipaa.html
    
Offset 16969, 191 lines modifiedOffset 16969, 191 lines modified
00042480:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id00042480:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
00042490:·6d39·3236·3522·2074·6162·696e·6465·783d··m9265"·tabindex=00042490:·6d39·3236·3522·2074·6162·696e·6465·783d··m9265"·tabindex=
000424a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button000424a0:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
000424b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=000424b0:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
000424c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A000424c0:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
000424d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea000424d0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
000424e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem000424e0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
000424f0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible000424f0:·6564·6961·7469·6f6e·204b·7562·6572·6e65··ediation·Kuberne
00042500:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
00042510:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
00042520:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
00042530:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
00042540:·3932·3635·223e·3c74·6162·6c65·2063·6c61··9265"><table·cla 
00042550:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table- 
00042560:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo 
00042570:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con 
00042580:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th> 
00042590:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>00042500:·7465·7320·736e·6970·7065·7420·e287·b23c··tes·snippet·...<
 00042510:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 00042520:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 00042530:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 00042540:·6964·6d39·3236·3522·3e3c·7461·626c·6520··idm9265"><table·
 00042550:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 00042560:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 00042570:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 00042580:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 00042590:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 000425a0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 000425b0:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 000425c0:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
000425a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr000425d0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 000425e0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 000425f0:·3e3c·7464·3e74·7275·653c·2f74·643e·3c2f··><td>true</td></
000425b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt 
000425c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low 
000425d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t 
000425e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t 
000425f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr 
00042600:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg00042600:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
00042610:·793a·3c2f·7468·3e3c·7464·3e72·6573·7472··y:</th><td>restr00042610:·6567·793a·3c2f·7468·3e3c·7464·3e72·6573··egy:</th><td>res
00042620:·6963·743c·2f74·643e·3c2f·7472·3e3c·2f74··ict</td></tr></t00042620:·7472·6963·743c·2f74·643e·3c2f·7472·3e3c··trict</td></tr><
00042630:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>00042630:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
 00042640:·653e·2d2d·2d0a·6170·6956·6572·7369·6f6e··e>---.apiVersion
 00042650:·3a20·6d61·6368·696e·6563·6f6e·6669·6775··:·machineconfigu
 00042660:·7261·7469·6f6e·2e6f·7065·6e73·6869·6674··ration.openshift
 00042670:·2e69·6f2f·7631·0a6b·696e·643a·204d·6163··.io/v1.kind:·Mac
 00042680:·6869·6e65·436f·6e66·6967·0a73·7065·633a··hineConfig.spec:
 00042690:·0a20·2063·6f6e·6669·673a·0a20·2020·2069··.··config:.····i
 000426a0:·676e·6974·696f·6e3a·0a20·2020·2020·2076··gnition:.······v
 000426b0:·6572·7369·6f6e·3a20·332e·312e·300a·2020··ersion:·3.1.0.··
 000426c0:·2020·7379·7374·656d·643a·0a20·2020·2020····systemd:.·····
 000426d0:·2075·6e69·7473·3a0a·2020·2020·2020·2020···units:.········
 000426e0:·2d20·6e61·6d65·3a20·636f·6e66·6967·7572··-·name:·configur
 000426f0:·652d·6372·7970·746f·2d70·6f6c·6963·792e··e-crypto-policy.
 00042700:·7365·7276·6963·650a·2020·2020·2020·2020··service.········
 00042710:·2020·656e·6162·6c65·643a·2074·7275·650a····enabled:·true.
 00042720:·2020·2020·2020·2020·2020·636f·6e74·656e············conten
 00042730:·7473·3a20·7c0a·2020·2020·2020·2020·2020··ts:·|.··········
 00042740:·2020·5b55·6e69·745d·0a20·2020·2020·2020····[Unit].·······
 00042750:·2020·2020·2042·6566·6f72·653d·6b75·6265·······Before=kube
 00042760:·6c65·742e·7365·7276·6963·650a·2020·2020··let.service.····
 00042770:·2020·2020·2020·2020·5b53·6572·7669·6365··········[Service
 00042780:·5d0a·2020·2020·2020·2020·2020·2020·5479··].············Ty
 00042790:·7065·3d6f·6e65·7368·6f74·0a20·2020·2020··pe=oneshot.·····
 000427a0:·2020·2020·2020·2045·7865·6353·7461·7274·········ExecStart
 000427b0:·3d75·7064·6174·652d·6372·7970·746f·2d70··=update-crypto-p
 000427c0:·6f6c·6963·6965·7320·2d2d·7365·7420·7b7b··olicies·--set·{{
 000427d0:·2e76·6172·5f73·7973·7465·6d5f·6372·7970··.var_system_cryp
 000427e0:·746f·5f70·6f6c·6963·797d·7d0a·2020·2020··to_policy}}.····
 000427f0:·2020·2020·2020·2020·5265·6d61·696e·4166··········RemainAf
 00042800:·7465·7245·7869·743d·7965·730a·2020·2020··terExit=yes.····
 00042810:·2020·2020·2020·2020·5b49·6e73·7461·6c6c··········[Install
 00042820:·5d0a·2020·2020·2020·2020·2020·2020·5761··].············Wa
 00042830:·6e74·6564·4279·3d6d·756c·7469·2d75·7365··ntedBy=multi-use
 00042840:·722e·7461·7267·6574·0a3c·2f63·6f64·653e··r.target.</code>
 00042850:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00042860:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 00042870:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 00042880:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
 00042890:·7461·2d74·6172·6765·743d·2223·6964·6d39··ta-target="#idm9
 000428a0:·3236·3622·2074·6162·696e·6465·783d·2230··266"·tabindex="0
 000428b0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
 000428c0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
 000428d0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
 000428e0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
 000428f0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
 00042900:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
 00042910:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 00042920:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00042930:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00042940:·6c61·7073·6522·2069·643d·2269·646d·3932··lapse"·id="idm92
 00042950:·3636·223e·3c74·6162·6c65·2063·6c61·7373··66"><table·class
 00042960:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 00042970:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 00042980:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 00042990:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 000429a0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 000429b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 000429c0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 000429d0:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 000429e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 000429f0:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 00042a00:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 00042a10:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 00042a20:·3c2f·7468·3e3c·7464·3e72·6573·7472·6963··</th><td>restric
 00042a30:·743c·2f74·643e·3c2f·7472·3e3c·2f74·6162··t</td></tr></tab
 00042a40:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
00042640:·2d20·6e61·6d65·3a20·5843·4344·4620·5661··-·name:·XCCDF·Va00042a50:·6e61·6d65·3a20·5843·4344·4620·5661·6c75··name:·XCCDF·Valu
00042650:·6c75·6520·7661·725f·7379·7374·656d·5f63··lue·var_system_c 
00042660:·7279·7074·6f5f·706f·6c69·6379·2023·2070··rypto_policy·#·p 
00042670:·726f·6d6f·7465·2074·6f20·7661·7269·6162··romote·to·variab 
00042680:·6c65·0a20·2073·6574·5f66·6163·743a·0a20··le.··set_fact:.· 
00042690:·2020·2076·6172·5f73·7973·7465·6d5f·6372·····var_system_cr 
000426a0:·7970·746f·5f70·6f6c·6963·793a·2021·2173··ypto_policy:·!!s 
000426b0:·7472·203c·6162·6272·2074·6974·6c65·3d22··tr·<abbr·title=" 
000426c0:·6672·6f6d·2050·726f·6669·6c65·2f72·6566··from·Profile/ref 
000426d0:·696e·652d·7661·6c75·653a·2078·6363·6466··ine-value:·xccdf 
000426e0:·5f6f·7267·2e73·7367·7072·6f6a·6563·742e··_org.ssgproject. 
000426f0:·636f·6e74·656e·745f·7661·6c75·655f·7661··content_value_va 
00042700:·725f·7379·7374·656d·5f63·7279·7074·6f5f··r_system_crypto_ 
00042710:·706f·6c69·6379·223e·4649·5053·3c2f·6162··policy">FIPS</ab 
00042720:·6272·3e0a·2020·7461·6773·3a0a·2020·2020··br>.··tags:.···· 
00042730:·2d20·616c·7761·7973·0a0a·2d20·6e61·6d65··-·always..-·name 
00042740:·3a20·436f·6e66·6967·7572·6520·5379·7374··:·Configure·Syst 
00042750:·656d·2043·7279·7074·6f67·7261·7068·7920··em·Cryptography· 
00042760:·506f·6c69·6379·0a20·206c·696e·6569·6e66··Policy.··lineinf 
00042770:·696c·653a·0a20·2020·2070·6174·683a·202f··ile:.····path:·/ 
Max diff block lines reached; 1883315/1908321 bytes (98.69%) of diff not shown.
136 KB
html2text {}
    
Offset 547, 14 lines modifiedOffset 547, 39 lines modified
547 »       echo·"to·see·what·package·to·(re)install"·>&2547 »       echo·"to·see·what·package·to·(re)install"·>&2
  
548 »       false··#·end·with·an·error·code548 »       false··#·end·with·an·error·code
549 elif·test·"$rc"·!=·0;·then549 elif·test·"$rc"·!=·0;·then
550 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2550 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
551 »       false··#·end·with·an·error·code551 »       false··#·end·with·an·error·code
552 fi552 fi
 553 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 554 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 555 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 556 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 557 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 558 ---
 559 apiVersion:·machineconfiguration.openshift.io/v1
 560 kind:·MachineConfig
 561 spec:
 562 ··config:
 563 ····ignition:
 564 ······version:·3.1.0
 565 ····systemd:
 566 ······units:
 567 ········-·name:·configure-crypto-policy.service
 568 ··········enabled:·true
 569 ··········contents:·|
 570 ············[Unit]
 571 ············Before=kubelet.service
 572 ············[Service]
 573 ············Type=oneshot
 574 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 575 ············RemainAfterExit=yes
 576 ············[Install]
 577 ············WantedBy=multi-user.target
553 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8578 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
554 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low579 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
555 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low580 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
556 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false581 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
557 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict582 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
558 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable583 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
559 ··set_fact:584 ··set_fact:
Offset 607, 39 lines modifiedOffset 632, 14 lines modified
607 ··-·PCI-DSSv4-2.2.7632 ··-·PCI-DSSv4-2.2.7
608 ··-·configure_crypto_policy633 ··-·configure_crypto_policy
609 ··-·high_severity634 ··-·high_severity
610 ··-·low_complexity635 ··-·low_complexity
611 ··-·low_disruption636 ··-·low_disruption
612 ··-·no_reboot_needed637 ··-·no_reboot_needed
613 ··-·restrict_strategy638 ··-·restrict_strategy
614 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
615 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
616 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
617 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true 
618 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict 
619 --- 
620 apiVersion:·machineconfiguration.openshift.io/v1 
621 kind:·MachineConfig 
622 spec: 
623 ··config: 
624 ····ignition: 
625 ······version:·3.1.0 
626 ····systemd: 
627 ······units: 
628 ········-·name:·configure-crypto-policy.service 
629 ··········enabled:·true 
630 ··········contents:·| 
631 ············[Unit] 
632 ············Before=kubelet.service 
633 ············[Service] 
634 ············Type=oneshot 
635 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}} 
636 ············RemainAfterExit=yes 
637 ············[Install] 
638 ············WantedBy=multi-user.target 
639 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*639 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8SS\x8SH\x8H·t\x8to\x8o·u\x8us\x8se\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8o·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
640 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.640 Crypto·Policies·provide·a·centralized·control·over·crypto·algorithms·usage·of·many·packages.·SSH·is·supported·by·crypto·policy,·but·the·SSH·configuration·may·be·set·up·to·ignore·it.·To·check·that·Crypto·Policies·settings·are·configured·correctly,·ensure·that·the·CRYPTO_POLICY·variable·is·either·commented·or·not·set·at·all·in·the·/etc/sysconfig/sshd.
641 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.641 Rationale:···Overriding·the·system·crypto·policy·makes·the·behavior·of·the·SSH·service·violate·expectations,·and·makes·system·configuration·more·fragmented.
642 Severity: ···medium642 Severity: ···medium
643 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy643 Rule·ID:·····xccdf_org.ssgproject.content_rule_configure_ssh_crypto_policy
644 Identifiers:·CCE-83445-7644 Identifiers:·CCE-83445-7
645 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453645 ·············_\x8d_\x8i_\x8s_\x8a·····CCI-001453
Offset 1656, 18 lines modifiedOffset 1656, 21 lines modified
1656 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-0022351656 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-002235
1657 ·············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)1657 ·············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),·164.310(d)(2)(iii)
1658 References:··_\x8n_\x8i_\x8s_\x8t····CM-61658 References:··_\x8n_\x8i_\x8s_\x8t····CM-6
1659 ·············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.11659 ·············_\x8o_\x8s_\x8p_\x8p····FIA_UAU.1
1660 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271660 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1661 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··RHEL-09-2110551661 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··RHEL-09-211055
1662 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-257786r1044834_rule1662 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-257786r1044834_rule
1663 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x81663 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 1664 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1665 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 1666 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 1667 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 1668 service·disable·debug-shell
1664 [customizations.services] 
1665 masked·=·["debug-shell"] 
1666 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81669 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1667 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1670 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1668 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1671 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1669 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1672 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1670 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1673 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1671 #·Remediation·is·applicable·only·in·certain·platforms1674 #·Remediation·is·applicable·only·in·certain·platforms
1672 if·rpm·--quiet·-q·kernel;·then1675 if·rpm·--quiet·-q·kernel;·then
Offset 1689, 14 lines modifiedOffset 1692, 33 lines modified
1689 #·so·let's·reset·the·state·so·OVAL·checks·pass.1692 #·so·let's·reset·the·state·so·OVAL·checks·pass.
1690 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.1693 #·Service·should·be·'inactive',·not·'failed'·after·reboot·though.
1691 "$SYSTEMCTL_EXEC"·reset-failed·'debug-shell.service'·||·true1694 "$SYSTEMCTL_EXEC"·reset-failed·'debug-shell.service'·||·true
  
1692 else1695 else
1693 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1696 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1694 fi1697 fi
 1698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 1699 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 1700 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·medium
 1701 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 1702 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
 1703 apiVersion:·machineconfiguration.openshift.io/v1
 1704 kind:·MachineConfig
 1705 spec:
 1706 ··config:
 1707 ····ignition:
 1708 ······version:·3.1.0
 1709 ····systemd:
 1710 ······units:
 1711 ······-·name:·debug-shell.service
 1712 ········enabled:·false
 1713 ········mask:·true
Max diff block lines reached; 133866/139277 bytes (96.11%) of diff not shown.
2.59 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ism_o.html
    
Offset 17499, 284 lines modifiedOffset 17499, 284 lines modified
000445a0:·2d74·6172·6765·743d·2223·6964·6d38·3435··-target="#idm845000445a0:·2d74·6172·6765·743d·2223·6964·6d38·3435··-target="#idm845
000445b0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·000445b0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
000445c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar000445c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
000445d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal000445d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
000445e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ000445e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
000445f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h000445f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
00044600:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia00044600:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
00044610:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu 
00044620:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·. 
00044630:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c 
00044640:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll 
00044650:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i 
00044660:·643d·2269·646d·3834·3538·223e·3c70·7265··d="idm8458"><pre 
00044670:·3e3c·636f·6465·3e0a·5b5b·7061·636b·6167··><code>.[[packag 
00044680:·6573·5d5d·0a6e·616d·6520·3d20·2261·6964··es]].name·=·"aid 
00044690:·6522·0a76·6572·7369·6f6e·203d·2022·2a22··e".version·=·"*" 
000446a0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
000446b0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt 
000446c0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
000446d0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
000446e0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
000446f0:·743d·2223·6964·6d38·3435·3922·2074·6162··t="#idm8459"·tab 
00044700:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role=" 
00044710:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp 
00044720:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti 
00044730:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to 
00044740:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="# 
00044750:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S 
00044760:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<00044610:·7469·6f6e·2073·6372·6970·7420·e287·b23c··tion·script·...<
00044770:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas00044620:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00044780:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps00044630:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00044790:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="00044640:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
000447a0:·6964·6d38·3435·3922·3e3c·7461·626c·6520··idm8459"><table·00044650:·6964·6d38·3435·3822·3e3c·7461·626c·6520··idm8458"><table·
000447b0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab00044660:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
000447c0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table00044670:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
000447d0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-00044680:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
000447e0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><00044690:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
000447f0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</000446a0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00044800:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
00044810:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr 
00044820:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td> 
00044830:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00044840:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th 
00044850:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td>< 
00044860:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra 
00044870:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en 
00044880:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></ 
00044890:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code 
000448a0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i 
000448b0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl 
000448c0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla 
000448d0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·-- 
000448e0:·7175·6965·7420·2d71·206b·6572·6e65·6c3b··quiet·-q·kernel; 
000448f0:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm· 
00044900:·2d71·202d·2d71·7569·6574·2022·6169·6465··-q·--quiet·"aide 
00044910:·2220·3b20·7468·656e·0a20·2020·2064·6e66··"·;·then.····dnf 
00044920:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
00044930:·6522·0a66·690a·0a65·6c73·650a·2020·2020··e".fi..else.···· 
00044940:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo· 
00044950:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is· 
00044960:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,· 
00044970:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done 
00044980:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr 
00044990:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
000449a0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
000449b0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
000449c0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
000449d0:·6172·6765·743d·2223·6964·6d38·3436·3022··arget="#idm8460" 
000449e0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
000449f0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
00044a00:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
00044a10:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
00044a20:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
00044a30:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
00044a40:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp 
00044a50:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
00044a60:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
00044a70:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
00044a80:·6522·2069·643d·2269·646d·3834·3630·223e··e"·id="idm8460"> 
00044a90:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta 
00044aa0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe 
00044ab0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered 
00044ac0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed 
00044ad0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple 
00044ae0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo 
00044af0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
00044b00:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
00044b10:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><000446b0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00044b20:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
00044b30:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
00044b40:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
00044b50:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
00044b60:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
00044b70:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
00044b80:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:· 
00044b90:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa 
00044ba0:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa 
00044bb0:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma 
00044bc0:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta 
00044bd0:·6773·3a0a·2020·2d20·4343·452d·3930·3834··gs:.··-·CCE-9084 
00044be0:·332d·340a·2020·2d20·434a·4953·2d35·2e31··3-4.··-·CJIS-5.1 
00044bf0:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S 
00044c00:·5449·472d·5248·454c·2d30·392d·3635·3130··TIG-RHEL-09-6510 
00044c10:·3130·0a20·202d·204e·4953·542d·3830·302d··10.··-·NIST-800- 
00044c20:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P 
00044c30:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5. 
00044c40:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11 
00044c50:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_ 
00044c60:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low 
00044c70:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-· 
00044c80:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.· 
00044c90:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi 
00044ca0:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot 
00044cb0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack 
00044cc0:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install 
00044cd0:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu 
00044ce0:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta 
00044cf0:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:. 
00044d00:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.· 
00044d10:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen 
00044d20:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern 
00044d30:·656c·2220·696e·2061·6e73·6962·6c65·5f66··el"·in·ansible_f 
00044d40:·6163·7473·2e70·6163·6b61·6765·7327·0a20··acts.packages'.· 
00044d50:·2074·6167·733a·0a20·202d·2043·4345·2d39···tags:.··-·CCE-9 
00044d60:·3038·3433·2d34·0a20·202d·2043·4a49·532d··0843-4.··-·CJIS- 
00044d70:·352e·3130·2e31·2e33·0a20·202d·2044·4953··5.10.1.3.··-·DIS 
00044d80:·412d·5354·4947·2d52·4845·4c2d·3039·2d36··A-STIG-RHEL-09-6 
Max diff block lines reached; 2455846/2493686 bytes (98.48%) of diff not shown.
216 KB
html2text {}
    
Offset 702, 19 lines modifiedOffset 702, 21 lines modified
702 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5702 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
703 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199703 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
704 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79704 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
705 ·············_\x8c_\x8i_\x8s············6.1.1705 ·············_\x8c_\x8i_\x8s············6.1.1
706 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2706 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
707 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010707 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
708 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule708 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
709 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8709 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 710 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 711 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 712 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 713 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 714 package·install·aide
710 [[packages]] 
711 name·=·"aide" 
712 version·=·"*" 
713 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8715 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
714 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low716 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
715 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low717 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
716 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false718 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
717 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable719 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
718 #·Remediation·is·applicable·only·in·certain·platforms720 #·Remediation·is·applicable·only·in·certain·platforms
719 if·rpm·--quiet·-q·kernel;·then721 if·rpm·--quiet·-q·kernel;·then
Offset 762, 14 lines modifiedOffset 764, 26 lines modified
762 ··-·PCI-DSSv4-11.5.2764 ··-·PCI-DSSv4-11.5.2
763 ··-·enable_strategy765 ··-·enable_strategy
764 ··-·low_complexity766 ··-·low_complexity
765 ··-·low_disruption767 ··-·low_disruption
766 ··-·medium_severity768 ··-·medium_severity
767 ··-·no_reboot_needed769 ··-·no_reboot_needed
768 ··-·package_aide_installed770 ··-·package_aide_installed
 771 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 772 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 773 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 774 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 775 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 776 package·--add=aide
 777 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 778 [[packages]]
 779 name·=·"aide"
 780 version·=·"*"
769 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8781 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
770 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low782 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
771 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low783 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
772 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false784 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
773 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable785 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
774 dnf·install·aide786 dnf·install·aide
Offset 781, 28 lines modifiedOffset 795, 14 lines modified
781 include·install_aide795 include·install_aide
  
782 class·install_aide·{796 class·install_aide·{
783 ··package·{·'aide':797 ··package·{·'aide':
784 ····ensure·=>·'installed',798 ····ensure·=>·'installed',
785 ··}799 ··}
786 }800 }
787 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
788 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
789 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
790 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
791 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
792 package·install·aide 
793 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
794 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
795 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
796 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
797 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
798 package·--add=aide 
799 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules801 Group  ·Federal·Information·Processing·Standard·(FIPS)·  Group·contains·2·rules
800 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.802 _\x8[_\x8r_\x8e_\x8f_\x8]  ·The·Federal·Information·Processing·Standard·(FIPS)·is·a·computer·security·standard·which·is·developed·by·the·U.S.·Government·and·industry·working·groups·to·validate·the·quality·of·cryptographic·modules.·The·FIPS·standard·provides·four·security·levels·to·ensure·adequate·coverage·of·different·industries,·implementation·of·cryptographic·modules,·and·organizational·sizes·and·requirements.
  
801 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·9.803 FIPS·140-2·is·the·current·standard·for·validating·that·mechanisms·used·to·access·cryptographic·modules·utilize·authentication·that·meets·industry·and·government·requirements.·For·government·systems,·this·allows·Security·Levels·1,·2,·3,·or·4·for·use·on·Red·Hat·Enterprise·Linux·9.
  
802 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.804 See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8c\x8c_\x8s\x8s_\x8r\x8r_\x8c\x8c_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8l\x8l_\x8i\x8i_\x8c\x8c_\x8a\x8a_\x8t\x8t_\x8i\x8i_\x8o\x8o_\x8n\x8n_\x8s\x8s_\x8/\x8/_\x8P\x8P_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x8h\x8h_\x8t\x8t_\x8m\x8m_\x8l\x8l·for·more·information.
803 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*805 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·E\x8En\x8na\x8ab\x8bl\x8le\x8e·D\x8Dr\x8ra\x8ac\x8cu\x8ut\x8t·F\x8FI\x8IP\x8PS\x8S·M\x8Mo\x8od\x8du\x8ul\x8le\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
Offset 837, 31 lines modifiedOffset 837, 31 lines modified
837 ·············_\x8i_\x8s_\x8m······1446837 ·············_\x8i_\x8s_\x8m······1446
838 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1838 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
839 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12839 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
840 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1840 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
841 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176841 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
842 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010842 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010
843 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule843 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule
844 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
845 [customizations] 
846 fips·=·true 
847 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8844 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
848 #·Remediation·is·applicable·only·in·certain·platforms845 #·Remediation·is·applicable·only·in·certain·platforms
849 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then846 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
850 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then847 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
851 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF848 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
852 kargs·=·["fips=1"]849 kargs·=·["fips=1"]
853 EOF850 EOF
854 fi851 fi
  
855 else852 else
856 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'853 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
857 fi854 fi
 855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 856 [customizations]
 857 fips·=·true
858 Group  ·System·Cryptographic·Policies·  Group·contains·2·rules858 Group  ·System·Cryptographic·Policies·  Group·contains·2·rules
859 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:859 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
860 ····*·GnuTLS·library860 ····*·GnuTLS·library
861 ····*·OpenSSL·library861 ····*·OpenSSL·library
862 ····*·NSS·library862 ····*·NSS·library
863 ····*·OpenJDK863 ····*·OpenJDK
864 ····*·Libkrb5864 ····*·Libkrb5
Offset 905, 14 lines modifiedOffset 905, 39 lines modified
905 »       echo·"to·see·what·package·to·(re)install"·>&2905 »       echo·"to·see·what·package·to·(re)install"·>&2
  
906 »       false··#·end·with·an·error·code906 »       false··#·end·with·an·error·code
907 elif·test·"$rc"·!=·0;·then907 elif·test·"$rc"·!=·0;·then
908 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2908 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
909 »       false··#·end·with·an·error·code909 »       false··#·end·with·an·error·code
910 fi910 fi
 911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 912 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 913 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 213812/220764 bytes (96.85%) of diff not shown.
3.18 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-ospp.html
    
Offset 15442, 63 lines modifiedOffset 15442, 63 lines modified
0003c510:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003c510:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003c520:·6964·6d39·3033·3522·2074·6162·696e·6465··idm9035"·tabinde0003c520:·6964·6d39·3033·3522·2074·6162·696e·6465··idm9035"·tabinde
0003c530:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003c530:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003c540:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003c540:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003c550:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003c550:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003c560:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003c560:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003c570:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003c570:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003c580:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui 
0003c590:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003c5a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003c5b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003c5c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003c5d0:·7073·6522·2069·643d·2269·646d·3930·3335··pse"·id="idm9035 
0003c5e0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b63··"><pre><code>.[c 
0003c5f0:·7573·746f·6d69·7a61·7469·6f6e·735d·0a66··ustomizations].f 
0003c600:·6970·7320·3d20·7472·7565·0a3c·2f63·6f64··ips·=·true.</cod 
0003c610:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a 
0003c620:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn- 
0003c630:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to 
0003c640:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"· 
0003c650:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id 
0003c660:·6d39·3033·3622·2074·6162·696e·6465·783d··m9036"·tabindex= 
0003c670:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button 
0003c680:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded= 
0003c690:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A 
0003c6a0:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea 
0003c6b0:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem 
0003c6c0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s0003c580:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0003c6d0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br0003c590:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
0003c6e0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan0003c5a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
0003c6f0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll0003c5b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
0003c700:·6170·7365·2220·6964·3d22·6964·6d39·3033··apse"·id="idm9030003c5c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d39··llapse"·id="idm9
0003c710:·3622·3e3c·7072·653e·3c63·6f64·653e·2320··6"><pre><code>#·0003c5d0:·3033·3522·3e3c·7072·653e·3c63·6f64·653e··035"><pre><code>
 0003c5e0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
 0003c5f0:·2061·7070·6c69·6361·626c·6520·6f6e·6c79···applicable·only
 0003c600:·2069·6e20·6365·7274·6169·6e20·706c·6174···in·certain·plat
 0003c610:·666f·726d·730a·6966·2028·2021·2028·205b··forms.if·(·!·(·[
 0003c620:·2022·247b·636f·6e74·6169·6e65·723a·2d7d···"${container:-}
 0003c630:·2220·3d3d·2022·6277·7261·702d·6f73·6275··"·==·"bwrap-osbu
 0003c640:·696c·6422·205d·2029·2026·616d·703b·2661··ild"·]·)·&amp;&a
 0003c650:·6d70·3b20·7270·6d20·2d2d·7175·6965·7420··mp;·rpm·--quiet·
 0003c660:·2d71·206b·6572·6e65·6c20·293b·2074·6865··-q·kernel·);·the
 0003c670:·6e0a·0a69·6620·5b5b·2022·244f·5343·4150··n..if·[[·"$OSCAP
 0003c680:·5f42·4f4f·5443·5f42·5549·4c44·2220·3d3d··_BOOTC_BUILD"·==
 0003c690:·2022·5945·5322·205d·5d3b·2074·6865·6e0a···"YES"·]];·then.
 0003c6a0:·0963·6174·2026·6774·3b20·2f75·7372·2f6c··.cat·&gt;·/usr/l
 0003c6b0:·6962·2f62·6f6f·7463·2f6b·6172·6773·2e64··ib/bootc/kargs.d
 0003c6c0:·2f30·312d·6669·7073·2e74·6f6d·6c20·266c··/01-fips.toml·&l
 0003c6d0:·743b·266c·743b·2045·4f46·0a6b·6172·6773··t;&lt;·EOF.kargs
 0003c6e0:·203d·205b·2266·6970·733d·3122·5d0a·454f···=·["fips=1"].EO
 0003c6f0:·460a·6669·0a0a·656c·7365·0a20·2020·2026··F.fi..else.····&
 0003c700:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
0003c720:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a0003c710:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
0003c730:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i 
0003c740:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo 
0003c750:·726d·730a·6966·2028·2021·2028·205b·2022··rms.if·(·!·(·[·" 
0003c760:·247b·636f·6e74·6169·6e65·723a·2d7d·2220··${container:-}"· 
0003c770:·3d3d·2022·6277·7261·702d·6f73·6275·696c··==·"bwrap-osbuil 
0003c780:·6422·205d·2029·2026·616d·703b·2661·6d70··d"·]·)·&amp;&amp 
0003c790:·3b20·7270·6d20·2d2d·7175·6965·7420·2d71··;·rpm·--quiet·-q 
0003c7a0:·206b·6572·6e65·6c20·293b·2074·6865·6e0a···kernel·);·then. 
0003c7b0:·0a69·6620·5b5b·2022·244f·5343·4150·5f42··.if·[[·"$OSCAP_B 
0003c7c0:·4f4f·5443·5f42·5549·4c44·2220·3d3d·2022··OOTC_BUILD"·==·" 
0003c7d0:·5945·5322·205d·5d3b·2074·6865·6e0a·0963··YES"·]];·then..c 
0003c7e0:·6174·2026·6774·3b20·2f75·7372·2f6c·6962··at·&gt;·/usr/lib 
0003c7f0:·2f62·6f6f·7463·2f6b·6172·6773·2e64·2f30··/bootc/kargs.d/0 
0003c800:·312d·6669·7073·2e74·6f6d·6c20·266c·743b··1-fips.toml·&lt; 
0003c810:·266c·743b·2045·4f46·0a6b·6172·6773·203d··&lt;·EOF.kargs·= 
0003c820:·205b·2266·6970·733d·3122·5d0a·454f·460a···["fips=1"].EOF. 
0003c830:·6669·0a0a·656c·7365·0a20·2020·2026·6774··fi..else.····&gt 
0003c840:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
0003c850:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
0003c860:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not0003c720:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
0003c870:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f0003c730:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 0003c740:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
 0003c750:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
 0003c760:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
 0003c770:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
 0003c780:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
 0003c790:·7267·6574·3d22·2369·646d·3930·3336·2220··rget="#idm9036"·
 0003c7a0:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
 0003c7b0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
 0003c7c0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
 0003c7d0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
 0003c7e0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
 0003c7f0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
 0003c800:·6e20·4f53·4275·696c·6420·426c·7565·7072··n·OSBuild·Bluepr
 0003c810:·696e·7420·736e·6970·7065·7420·e287·b23c··int·snippet·...<
 0003c820:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003c830:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003c840:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003c850:·6964·6d39·3033·3622·3e3c·7072·653e·3c63··idm9036"><pre><c
 0003c860:·6f64·653e·0a5b·6375·7374·6f6d·697a·6174··ode>.[customizat
 0003c870:·696f·6e73·5d0a·6669·7073·203d·2074·7275··ions].fips·=·tru
0003c880:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><0003c880:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
0003c890:·2f64·6976·3e3c·2f64·6976·3e3c·2f74·643e··/div></div></td>0003c890:·2f64·6976·3e3c·2f64·6976·3e3c·2f74·643e··/div></div></td>
0003c8a0:·3c2f·7472·3e3c·2f74·626f·6479·3e3c·2f74··</tr></tbody></t0003c8a0:·3c2f·7472·3e3c·2f74·626f·6479·3e3c·2f74··</tr></tbody></t
0003c8b0:·6162·6c65·3e3c·2f74·643e·3c2f·7472·3e3c··able></td></tr><0003c8b0:·6162·6c65·3e3c·2f74·643e·3c2f·7472·3e3c··able></td></tr><
0003c8c0:·7472·2064·6174·612d·7474·2d69·643d·2263··tr·data-tt-id="c0003c8c0:·7472·2064·6174·612d·7474·2d69·643d·2263··tr·data-tt-id="c
0003c8d0:·6869·6c64·7265·6e2d·7863·6364·665f·6f72··hildren-xccdf_or0003c8d0:·6869·6c64·7265·6e2d·7863·6364·665f·6f72··hildren-xccdf_or
0003c8e0:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con0003c8e0:·672e·7373·6770·726f·6a65·6374·2e63·6f6e··g.ssgproject.con
0003c8f0:·7465·6e74·5f67·726f·7570·5f63·7279·7074··tent_group_crypt0003c8f0:·7465·6e74·5f67·726f·7570·5f63·7279·7074··tent_group_crypt
Offset 15811, 254 lines modifiedOffset 15811, 254 lines modified
0003dc20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003dc20:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003dc30:·2369·646d·3931·3639·2220·7461·6269·6e64··#idm9169"·tabind0003dc30:·2369·646d·3931·3639·2220·7461·6269·6e64··#idm9169"·tabind
0003dc40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003dc40:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003dc50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003dc50:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003dc60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003dc60:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003dc70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003dc70:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003dc80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003dc80:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003dc90:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu 
0003dca0:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003dcb0:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003dcc0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003dcd0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003dce0:·6170·7365·2220·6964·3d22·6964·6d39·3136··apse"·id="idm916 
0003dcf0:·3922·3e3c·7072·653e·3c63·6f64·653e·0a5b··9"><pre><code>.[ 
0003dd00:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0003dd10:·203d·2022·6372·7970·746f·2d70·6f6c·6963···=·"crypto-polic 
0003dd20:·6965·7322·0a76·6572·7369·6f6e·203d·2022··ies".version·=·" 
0003dd30:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
0003dd40:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
0003dd50:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
0003dd60:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
0003dd70:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
0003dd80:·6765·743d·2223·6964·6d39·3137·3022·2074··get="#idm9170"·t 
0003dd90:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
Max diff block lines reached; 2934694/2976148 bytes (98.61%) of diff not shown.
350 KB
html2text {}
    
Offset 110, 31 lines modifiedOffset 110, 31 lines modified
110 ·············_\x8i_\x8s_\x8m······1446110 ·············_\x8i_\x8s_\x8m······1446
111 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1111 ·············_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
112 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12112 References:··_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
113 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1113 ·············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
114 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176114 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
115 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010115 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d···RHEL-09-671010
116 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule116 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f··SV-258230r958408_rule
117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
118 [customizations] 
119 fips·=·true 
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
121 #·Remediation·is·applicable·only·in·certain·platforms118 #·Remediation·is·applicable·only·in·certain·platforms
122 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then119 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
123 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then120 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
124 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF121 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
125 kargs·=·["fips=1"]122 kargs·=·["fips=1"]
126 EOF123 EOF
127 fi124 fi
  
128 else125 else
129 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'126 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
130 fi127 fi
 128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 129 [customizations]
 130 fips·=·true
131 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules131 Group  ·System·Cryptographic·Policies·  Group·contains·4·rules
132 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:132 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
133 ····*·GnuTLS·library133 ····*·GnuTLS·library
134 ····*·OpenSSL·library134 ····*·OpenSSL·library
135 ····*·NSS·library135 ····*·NSS·library
136 ····*·OpenJDK136 ····*·OpenJDK
137 ····*·Libkrb5137 ····*·Libkrb5
Offset 149, 19 lines modifiedOffset 149, 21 lines modified
149 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed149 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_crypto-policies_installed
150 Identifiers:·CCE-83442-4150 Identifiers:·CCE-83442-4
151 ·············_\x8d_\x8i_\x8s_\x8a····CCI-002890,·CCI-002450,·CCI-003123151 ·············_\x8d_\x8i_\x8s_\x8a····CCI-002890,·CCI-002450,·CCI-003123
152 ·············_\x8o_\x8s_\x8p_\x8p····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1152 ·············_\x8o_\x8s_\x8p_\x8p····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1
153 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174153 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000396-GPOS-00176,·SRG-OS-000393-GPOS-00173,·SRG-OS-000394-GPOS-00174
154 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··RHEL-09-215100154 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··RHEL-09-215100
155 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-258234r1051250_rule155 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-258234r1051250_rule
156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8156 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 157 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 158 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 159 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 160 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 161 package·install·crypto-policies
157 [[packages]] 
158 name·=·"crypto-policies" 
159 version·=·"*" 
160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8162 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
161 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low163 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
162 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low164 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
163 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false165 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
164 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable166 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
165 if·!·rpm·-q·--quiet·"crypto-policies"·;·then167 if·!·rpm·-q·--quiet·"crypto-policies"·;·then
Offset 181, 14 lines modifiedOffset 183, 26 lines modified
181 ··-·DISA-STIG-RHEL-09-215100183 ··-·DISA-STIG-RHEL-09-215100
182 ··-·enable_strategy184 ··-·enable_strategy
183 ··-·low_complexity185 ··-·low_complexity
184 ··-·low_disruption186 ··-·low_disruption
185 ··-·medium_severity187 ··-·medium_severity
186 ··-·no_reboot_needed188 ··-·no_reboot_needed
187 ··-·package_crypto-policies_installed189 ··-·package_crypto-policies_installed
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 195 package·--add=crypto-policies
 196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 197 [[packages]]
 198 name·=·"crypto-policies"
 199 version·=·"*"
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8200 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low201 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low202 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false203 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable204 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
193 dnf·install·crypto-policies205 dnf·install·crypto-policies
Offset 200, 28 lines modifiedOffset 214, 14 lines modified
200 include·install_crypto-policies214 include·install_crypto-policies
  
201 class·install_crypto-policies·{215 class·install_crypto-policies·{
202 ··package·{·'crypto-policies':216 ··package·{·'crypto-policies':
203 ····ensure·=>·'installed',217 ····ensure·=>·'installed',
204 ··}218 ··}
205 }219 }
206 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
207 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
208 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
209 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
210 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
211 package·install·crypto-policies 
212 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
213 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
214 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
215 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
216 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
217 package·--add=crypto-policies 
218 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*220 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·C\x8Co\x8on\x8nf\x8fi\x8ig\x8gu\x8ur\x8re\x8e·S\x8Sy\x8ys\x8st\x8te\x8em\x8m·C\x8Cr\x8ry\x8yp\x8pt\x8to\x8og\x8gr\x8ra\x8ap\x8ph\x8hy\x8y·P\x8Po\x8ol\x8li\x8ic\x8cy\x8y·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
219 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:221 To·configure·the·system·cryptography·policy·to·use·ciphers·only·from·the·FIPS:OSPP·policy,·run·the·following·command:
220 $·sudo·update-crypto-policies·--set·FIPS:OSPP222 $·sudo·update-crypto-policies·--set·FIPS:OSPP
221 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.223 The·rule·checks·if·settings·for·selected·crypto·policy·are·configured·as·expected.·Configuration·files·in·the·/etc/crypto-policies/back-ends·are·either·symlinks·to·correct·files·provided·by·Crypto-policies·package·or·they·are·regular·files·in·case·crypto·policy·customizations·are·applied.·Crypto·policies·may·be·customized·by·crypto·policy·modules,·in·which·case·it·is·delimited·from·the·base·policy·using·a·colon.
222 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.224 Warning: ·The·system·needs·to·be·rebooted·for·these·changes·to·take·effect.
223 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.225 Warning: ·System·Crypto·Modules·must·be·provided·by·a·vendor·that·undergoes·FIPS-140·certifications.·FIPS-140·is·applicable·to·all·Federal·agencies·that·use·cryptographic-based·security·systems·to·protect·sensitive·information·in·computer·and·telecommunication·systems·(including·voice·systems)·as·defined·in·Section·5131·of·the·Information·Technology·Management·Reform·Act·of·1996,·Public·Law·104-106.·This·standard·shall·be·used·in·designing·and·implementing·cryptographic·modules·that·Federal·departments·and·agencies·operate·or·are·operated·for·them·under·contract.·See·_\x8h\x8h_\x8t\x8t_\x8t\x8t_\x8p\x8p_\x8s\x8s_\x8:\x8:_\x8/\x8/_\x8/\x8/_\x8n\x8n_\x8v\x8v_\x8l\x8l_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8.\x8._\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8.\x8._\x8g\x8g_\x8o\x8o_\x8v\x8v_\x8/\x8/_\x8n\x8n_\x8i\x8i_\x8s\x8s_\x8t\x8t_\x8p\x8p_\x8u\x8u_\x8b\x8b_\x8s\x8s_\x8/\x8/_\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8/\x8/_\x8N\x8N_\x8I\x8I_\x8S\x8S_\x8T\x8T_\x8.\x8._\x8F\x8F_\x8I\x8I_\x8P\x8P_\x8S\x8S_\x8.\x8._\x81\x81_\x84\x84_\x80\x80_\x8-\x8-_\x82\x82_\x8.\x8._\x8p\x8p_\x8d\x8d_\x8f\x8f·To·meet·this,·the·system·has·to·have·cryptographic·software·provided·by·a·vendor·that·has·undergone·this·certification.·This·means·providing·documentation,·test·results,·design·information,·and·independent·third·party·review·by·an·accredited·lab.·While·open·source·software·is·capable·of·meeting·this,·it·does·not·meet·FIPS-140·unless·the·vendor·submits·to·this·process.
224 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.226 Rationale:···Centralized·cryptographic·policies·simplify·applying·secure·ciphers·across·an·operating·system·and·the·applications·that·run·on·that·operating·system.·Use·of·weak·or·untested·encryption·algorithms·undermines·the·purposes·of·utilizing·encryption·to·protect·data.
Offset 255, 14 lines modifiedOffset 255, 39 lines modified
255 »       echo·"to·see·what·package·to·(re)install"·>&2255 »       echo·"to·see·what·package·to·(re)install"·>&2
  
256 »       false··#·end·with·an·error·code256 »       false··#·end·with·an·error·code
257 elif·test·"$rc"·!=·0;·then257 elif·test·"$rc"·!=·0;·then
258 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2258 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
259 »       false··#·end·with·an·error·code259 »       false··#·end·with·an·error·code
260 fi260 fi
 261 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 262 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 263 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 349891/358241 bytes (97.67%) of diff not shown.
2.86 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-pci-dss.html
    
Offset 16718, 284 lines modifiedOffset 16718, 284 lines modified
000414d0:·6574·3d22·2369·646d·3834·3538·2220·7461··et="#idm8458"·ta000414d0:·6574·3d22·2369·646d·3834·3538·2220·7461··et="#idm8458"·ta
000414e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=000414e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
000414f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex000414f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00041500:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00041500:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00041510:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00041510:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00041520:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00041520:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00041530:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00041530:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
00041540:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
00041550:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
00041560:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00041570:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00041580:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00041590:·6d38·3435·3822·3e3c·7072·653e·3c63·6f64··m8458"><pre><cod 
000415a0:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
000415b0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
000415c0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
000415d0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
000415e0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
000415f0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
00041600:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
00041610:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
00041620:·646d·3834·3539·2220·7461·6269·6e64·6578··dm8459"·tabindex 
00041630:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00041640:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00041650:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00041660:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
00041670:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
00041680:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
00041690:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b00041540:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
000416a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa00041550:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
000416b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col00041560:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
000416c0:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm8400041570:·6c61·7073·6522·2069·643d·2269·646d·3834··lapse"·id="idm84
000416d0:·3539·223e·3c74·6162·6c65·2063·6c61·7373··59"><table·class00041580:·3538·223e·3c74·6162·6c65·2063·6c61·7373··58"><table·class
000416e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st00041590:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
000416f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord000415a0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
00041700:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde000415b0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
00041710:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co000415c0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
00041720:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t000415d0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
00041730:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><000415e0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
00041740:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio000415f0:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
00041750:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</00041600:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
00041760:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>00041610:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
00041770:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>00041620:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
00041780:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><00041630:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
00041790:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:00041640:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
000417a0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<00041650:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
000417b0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table00041660:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
000417c0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re00041670:·3e3c·7072·653e·3c63·6f64·653e·0a70·6163··><pre><code>.pac
 00041680:·6b61·6765·2069·6e73·7461·6c6c·2061·6964··kage·install·aid
000417d0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
000417e0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
000417f0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
00041800:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
00041810:·202d·7120·6b65·726e·656c·3b20·7468·656e···-q·kernel;·then 
00041820:·0a0a·6966·2021·2072·706d·202d·7120·2d2d··..if·!·rpm·-q·-- 
00041830:·7175·6965·7420·2261·6964·6522·203b·2074··quiet·"aide"·;·t 
00041840:·6865·6e0a·2020·2020·646e·6620·696e·7374··hen.····dnf·inst 
00041850:·616c·6c20·2d79·2022·6169·6465·220a·6669··all·-y·"aide".fi 
00041860:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
00041870:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
00041880:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
00041890:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
000418a0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
000418b0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d00041690:·650a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··e.</code></pre><
000418c0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn000416a0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
000418d0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da000416b0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
000418e0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla000416c0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
000418f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target000416d0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
00041900:·3d22·2369·646d·3834·3630·2220·7461·6269··="#idm8460"·tabi000416e0:·6574·3d22·2369·646d·3834·3539·2220·7461··et="#idm8459"·ta
00041910:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b000416f0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00041920:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00041700:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00041930:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00041710:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00041940:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00041720:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00041950:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00041730:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00041960:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An00041740:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00041750:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 00041760:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00041770:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00041780:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00041790:·2269·646d·3834·3539·223e·3c74·6162·6c65··"idm8459"><table
 000417a0:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 000417b0:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 000417c0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 000417d0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 000417e0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 000417f0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00041800:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 00041810:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
00041970:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
00041980:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00041990:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
000419a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
000419b0:·3d22·6964·6d38·3436·3022·3e3c·7461·626c··="idm8460"><tabl 
000419c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
000419d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
000419e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
000419f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00041a00:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00041a10:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00041a20:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00041a30:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00041a40:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00041a50:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00041a60:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00041a70:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00041a80:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00041a90:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00041aa0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00041ab0:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
00041ac0:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
00041ad0:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
00041ae0:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
00041af0:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
00041b00:·202d·2043·4345·2d39·3038·3433·2d34·0a20···-·CCE-90843-4.· 
00041b10:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
00041b20:·0a20·202d·2044·4953·412d·5354·4947·2d52··.··-·DISA-STIG-R 
00041b30:·4845·4c2d·3039·2d36·3531·3031·300a·2020··HEL-09-651010.·· 
00041b40:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
00041b50:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
00041b60:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
00041b70:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
00041b80:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
00041b90:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
00041ba0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d 
00041bb0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me 
00041bc0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.·· 
00041bd0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need 
Max diff block lines reached; 2724569/2762409 bytes (98.63%) of diff not shown.
230 KB
html2text {}
    
Offset 513, 19 lines modifiedOffset 513, 21 lines modified
513 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5513 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
514 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199514 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
515 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79515 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
516 ·············_\x8c_\x8i_\x8s············6.1.1516 ·············_\x8c_\x8i_\x8s············6.1.1
517 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2517 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
518 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010518 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········RHEL-09-651010
519 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule519 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-258134r1045265_rule
520 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_.S_.B_.u_.i_.l_.d_.·_.B_.l_.u_.e_.p_.r_.i_.n_.t_.·_.s_.n_.i_.p_.p_.e_\x8t_\x8·_\x8520 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_.c_.r_.i_.p_\x8t_\x8·_\x8
 521 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 522 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 523 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 524 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 525 package·install·aide
521 [[packages]] 
522 name·=·"aide" 
523 version·=·"*" 
524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8526 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
525 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low527 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
526 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low528 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
527 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false529 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
528 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable530 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
529 #·Remediation·is·applicable·only·in·certain·platforms531 #·Remediation·is·applicable·only·in·certain·platforms
530 if·rpm·--quiet·-q·kernel;·then532 if·rpm·--quiet·-q·kernel;·then
Offset 573, 14 lines modifiedOffset 575, 26 lines modified
573 ··-·PCI-DSSv4-11.5.2575 ··-·PCI-DSSv4-11.5.2
574 ··-·enable_strategy576 ··-·enable_strategy
575 ··-·low_complexity577 ··-·low_complexity
576 ··-·low_disruption578 ··-·low_disruption
577 ··-·medium_severity579 ··-·medium_severity
578 ··-·no_reboot_needed580 ··-·no_reboot_needed
579 ··-·package_aide_installed581 ··-·package_aide_installed
 582 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 583 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 584 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 585 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 586 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 587 package·--add=aide
 588 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 589 [[packages]]
 590 name·=·"aide"
 591 version·=·"*"
580 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8592 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
581 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low593 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
582 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low594 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
583 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false595 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
584 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable596 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
585 dnf·install·aide597 dnf·install·aide
Offset 592, 28 lines modifiedOffset 606, 14 lines modified
592 include·install_aide606 include·install_aide
  
593 class·install_aide·{607 class·install_aide·{
594 ··package·{·'aide':608 ··package·{·'aide':
595 ····ensure·=>·'installed',609 ····ensure·=>·'installed',
596 ··}610 ··}
597 }611 }
598 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8 
599 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
600 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
601 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
602 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
603 package·install·aide 
604 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
605 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
606 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
607 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
608 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
609 package·--add=aide 
610 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*612 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
611 Run·the·following·command·to·generate·a·new·database:613 Run·the·following·command·to·generate·a·new·database:
612 $·sudo·/usr/sbin/aide·--init614 $·sudo·/usr/sbin/aide·--init
613 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:615 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
614 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz616 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
615 To·initiate·a·manual·check,·run·the·following·command:617 To·initiate·a·manual·check,·run·the·following·command:
616 $·sudo·/usr/sbin/aide·--check618 $·sudo·/usr/sbin/aide·--check
Offset 985, 14 lines modifiedOffset 985, 39 lines modified
985 »       echo·"to·see·what·package·to·(re)install"·>&2985 »       echo·"to·see·what·package·to·(re)install"·>&2
  
986 »       false··#·end·with·an·error·code986 »       false··#·end·with·an·error·code
987 elif·test·"$rc"·!=·0;·then987 elif·test·"$rc"·!=·0;·then
988 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2988 »       echo·"Error·invoking·the·update-crypto-policies·script:·$stderr_of_call"·>&2
989 »       false··#·end·with·an·error·code989 »       false··#·end·with·an·error·code
990 fi990 fi
 991 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8K_\x8u_\x8b_\x8e_\x8r_\x8n_\x8e_\x8t_\x8e_\x8s_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 992 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 993 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 994 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····true
 995 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
 996 ---
 997 apiVersion:·machineconfiguration.openshift.io/v1
 998 kind:·MachineConfig
 999 spec:
 1000 ··config:
 1001 ····ignition:
 1002 ······version:·3.1.0
 1003 ····systemd:
 1004 ······units:
 1005 ········-·name:·configure-crypto-policy.service
 1006 ··········enabled:·true
 1007 ··········contents:·|
 1008 ············[Unit]
 1009 ············Before=kubelet.service
 1010 ············[Service]
 1011 ············Type=oneshot
 1012 ············ExecStart=update-crypto-policies·--set·{{.var_system_crypto_policy}}
 1013 ············RemainAfterExit=yes
 1014 ············[Install]
 1015 ············WantedBy=multi-user.target
991 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81016 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8s_\x8i_\x8b_\x8l_\x8e_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
992 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1017 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
993 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1018 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
994 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1019 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
995 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict1020 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···restrict
996 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable1021 -·name:·XCCDF·Value·var_system_crypto_policy·#·promote·to·variable
997 ··set_fact:1022 ··set_fact:
Offset 1045, 39 lines modifiedOffset 1070, 14 lines modified
1045 ··-·PCI-DSSv4-2.2.71070 ··-·PCI-DSSv4-2.2.7
1046 ··-·configure_crypto_policy1071 ··-·configure_crypto_policy
1047 ··-·high_severity1072 ··-·high_severity
1048 ··-·low_complexity1073 ··-·low_complexity
1049 ··-·low_disruption1074 ··-·low_disruption
1050 ··-·no_reboot_needed1075 ··-·no_reboot_needed
Max diff block lines reached; 230222/235080 bytes (97.93%) of diff not shown.
4.83 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-stig.html
    
Offset 15159, 284 lines modifiedOffset 15159, 284 lines modified
0003b360:·6172·6765·743d·2223·6964·6d38·3435·3822··arget="#idm8458"0003b360:·6172·6765·743d·2223·6964·6d38·3435·3822··arget="#idm8458"
0003b370:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b370:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b380:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b380:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b390:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b390:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b3a0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b3a0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b3b0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b3b0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b3c0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b3c0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003b3d0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003b3e0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·... 
0003b3f0:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
0003b400:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
0003b410:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
0003b420:·2269·646d·3834·3538·223e·3c70·7265·3e3c··"idm8458"><pre>< 
0003b430:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003b440:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003b450:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003b460:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b470:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b480:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b490:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b4a0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b4b0:·2223·6964·6d38·3435·3922·2074·6162·696e··"#idm8459"·tabin 
0003b4c0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b4d0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b4e0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b4f0:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b500:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b510:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b520:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a0003b3d0:·6f6e·2073·6372·6970·7420·e287·b23c·2f61··on·script·...</a
0003b530:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=0003b3e0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
0003b540:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·0003b3f0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
0003b550:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id0003b400:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
0003b560:·6d38·3435·3922·3e3c·7461·626c·6520·636c··m8459"><table·cl0003b410:·6d38·3435·3822·3e3c·7461·626c·6520·636c··m8458"><table·cl
0003b570:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table0003b420:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
0003b580:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b0003b430:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
0003b590:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co0003b440:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
0003b5a0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th0003b450:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
0003b5b0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th0003b460:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
0003b5c0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t0003b470:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
0003b5d0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup0003b480:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
0003b5e0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo0003b490:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
0003b5f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b4a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003b600:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><0003b4b0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
0003b610:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t0003b4c0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
0003b620:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b4d0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
0003b630:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003b4e0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
0003b640:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta0003b4f0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003b650:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#0003b500:·626c·653e·3c70·7265·3e3c·636f·6465·3e0a··ble><pre><code>.
 0003b510:·7061·636b·6167·6520·696e·7374·616c·6c20··package·install·
0003b660:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is· 
0003b670:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only· 
0003b680:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf 
0003b690:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu 
0003b6a0:·6965·7420·2d71·206b·6572·6e65·6c3b·2074··iet·-q·kernel;·t 
0003b6b0:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q 
0003b6c0:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"· 
0003b6d0:·3b20·7468·656e·0a20·2020·2064·6e66·2069··;·then.····dnf·i 
0003b6e0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003b6f0:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g 
0003b700:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R 
0003b710:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no 
0003b720:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no 
0003b730:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'. 
0003b740:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>0003b520:·6169·6465·0a3c·2f63·6f64·653e·3c2f·7072··aide.</code></pr
0003b750:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="0003b530:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003b760:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"0003b540:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003b770:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co0003b550:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003b780:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar0003b560:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003b790:·6765·743d·2223·6964·6d38·3436·3022·2074··get="#idm8460"·t0003b570:·6172·6765·743d·2223·6964·6d38·3435·3922··arget="#idm8459"
0003b7a0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b580:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b7b0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b590:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b7c0:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b5a0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b7d0:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b5b0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b7e0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b5c0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b7f0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b5d0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003b800:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet 
0003b810:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
0003b820:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
0003b830:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
0003b840:·2069·643d·2269·646d·3834·3630·223e·3c74···id="idm8460"><t 
0003b850:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl 
0003b860:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped· 
0003b870:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t 
0003b880:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed"> 
0003b890:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi 
0003b8a0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low< 
0003b8b0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th 
0003b8c0:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th 
0003b8d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b8e0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot 
0003b8f0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<0003b5e0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003b5f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b600:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b610:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b620:·6964·3d22·6964·6d38·3435·3922·3e3c·7461··id="idm8459"><ta
 0003b630:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003b640:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003b650:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003b660:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003b670:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003b680:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003b690:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b6a0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b6b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b6c0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003b6d0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003b6e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b6f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003b700:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003b710:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b720:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0003b730:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0003b740:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0003b750:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp
 0003b760:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
 0003b770:·6e65·6c3b·2074·6865·6e0a·0a69·6620·2120··nel;·then..if·!·
 0003b780:·7270·6d20·2d71·202d·2d71·7569·6574·2022··rpm·-q·--quiet·"
 0003b790:·6169·6465·2220·3b20·7468·656e·0a20·2020··aide"·;·then.···
 0003b7a0:·2064·6e66·2069·6e73·7461·6c6c·202d·7920···dnf·install·-y·
 0003b7b0:·2261·6964·6522·0a66·690a·0a65·6c73·650a··"aide".fi..else.
 0003b7c0:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 0003b7d0:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 0003b7e0:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 0003b7f0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 0003b800:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
 0003b810:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b820:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
Max diff block lines reached; 4550637/4588477 bytes (99.18%) of diff not shown.
466 KB
html2text {}
Max HTML report size reached
4.8 MB
./usr/share/doc/ssg-nondebian/ssg-rhel9-guide-stig_gui.html
    
Offset 15177, 285 lines modifiedOffset 15177, 285 lines modified
0003b480:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b480:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b490:·2369·646d·3834·3538·2220·7461·6269·6e64··#idm8458"·tabind0003b490:·2369·646d·3834·3538·2220·7461·6269·6e64··#idm8458"·tabind
0003b4a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b4a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b4b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b4b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b4c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b4c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b4d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b4d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b4e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b4e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b4f0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0003b4f0:·5265·6d65·6469·6174·696f·6e20·7363·7269··Remediation·scri
0003b500:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003b510:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003b520:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b530:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b540:·6170·7365·2220·6964·3d22·6964·6d38·3435··apse"·id="idm845 
0003b550:·3822·3e3c·7072·653e·3c63·6f64·653e·0a5b··8"><pre><code>.[ 
0003b560:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0003b570:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio 
0003b580:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code>< 
0003b590:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl 
0003b5a0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc 
0003b5b0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl 
0003b5c0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat 
0003b5d0:·612d·7461·7267·6574·3d22·2369·646d·3834··a-target="#idm84 
0003b5e0:·3539·2220·7461·6269·6e64·6578·3d22·3022··59"·tabindex="0" 
0003b5f0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a 
0003b600:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa 
0003b610:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti 
0003b620:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"· 
0003b630:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi 
0003b640:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri 
0003b650:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d0003b500:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
0003b660:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003b510:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
0003b670:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003b520:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
0003b680:·6522·2069·643d·2269·646d·3834·3539·223e··e"·id="idm8459">0003b530:·6522·2069·643d·2269·646d·3834·3538·223e··e"·id="idm8458">
0003b690:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta0003b540:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
0003b6a0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe0003b550:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
0003b6b0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered0003b560:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
0003b6c0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed0003b570:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
0003b6d0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple0003b580:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
0003b6e0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo0003b590:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
0003b6f0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr>< 
0003b700:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</ 
0003b710:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td>< 
0003b720:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo 
0003b730:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals 
0003b740:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr>< 
0003b750:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th 
0003b760:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td> 
0003b770:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr 
0003b780:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi 
0003b790:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica 
0003b7a0:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert 
0003b7b0:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if 
0003b7c0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q· 
0003b7d0:·6b65·726e·656c·3b20·7468·656e·0a0a·6966··kernel;·then..if 
0003b7e0:·2021·2072·706d·202d·7120·2d2d·7175·6965···!·rpm·-q·--quie 
0003b7f0:·7420·2261·6964·6522·203b·2074·6865·6e0a··t·"aide"·;·then. 
0003b800:·2020·2020·646e·6620·696e·7374·616c·6c20······dnf·install· 
0003b810:·2d79·2022·6169·6465·220a·6669·0a0a·656c··-y·"aide".fi..el 
0003b820:·7365·0a20·2020·2026·6774·3b26·616d·703b··se.····&gt;&amp; 
0003b830:·3220·6563·686f·2027·5265·6d65·6469·6174··2·echo·'Remediat 
0003b840:·696f·6e20·6973·206e·6f74·2061·7070·6c69··ion·is·not·appli 
0003b850:·6361·626c·652c·206e·6f74·6869·6e67·2077··cable,·nothing·w 
0003b860:·6173·2064·6f6e·6527·0a66·690a·3c2f·636f··as·done'.fi.</co 
0003b870:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
0003b880:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
0003b890:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
0003b8a0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
0003b8b0:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
0003b8c0:·646d·3834·3630·2220·7461·6269·6e64·6578··dm8460"·tabindex 
0003b8d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
0003b8e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
0003b8f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
0003b900:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
0003b910:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
0003b920:·6d65·6469·6174·696f·6e20·416e·7369·626c··mediation·Ansibl 
0003b930:·6520·736e·6970·7065·7420·e287·b23c·2f61··e·snippet·...</a 
0003b940:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
0003b950:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
0003b960:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
0003b970:·6d38·3436·3022·3e3c·7461·626c·6520·636c··m8460"><table·cl 
0003b980:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table 
0003b990:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b 
0003b9a0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co 
0003b9b0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th 
0003b9c0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th 
0003b9d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t 
0003b9e0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup 
0003b9f0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo 
0003ba00:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><0003b5a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
0003ba10:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th>< 
0003ba20:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t 
0003ba30:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate0003b5b0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b5c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b5d0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
0003ba40:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab0003b5e0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b5f0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b600:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b610:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b620:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b630:·653e·3c63·6f64·653e·0a70·6163·6b61·6765··e><code>.package
 0003b640:·2069·6e73·7461·6c6c·2061·6964·650a·3c2f···install·aide.</
 0003b650:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b660:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b670:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003b680:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003b690:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003b6a0:·2369·646d·3834·3539·2220·7461·6269·6e64··#idm8459"·tabind
 0003b6b0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003b6c0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003b6d0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003b6e0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003b6f0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003b700:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
 0003b710:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003b720:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b730:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b740:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b750:·3834·3539·223e·3c74·6162·6c65·2063·6c61··8459"><table·cla
 0003b760:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b770:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b780:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b790:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b7a0:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b7b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b7c0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
0003ba50:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta 
0003ba60:·626c·653e·3c70·7265·3e3c·636f·6465·3e2d··ble><pre><code>- 
Max diff block lines reached; 4524249/4562227 bytes (99.17%) of diff not shown.
463 KB
html2text {}
Max HTML report size reached
344 KB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-pci-dss.html
    
Offset 16581, 213 lines modifiedOffset 16581, 213 lines modified
00040c40:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=00040c40:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
00040c50:·2223·6964·6d31·3934·3322·2074·6162·696e··"#idm1943"·tabin00040c50:·2223·6964·6d31·3934·3322·2074·6162·696e··"#idm1943"·tabin
00040c60:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu00040c60:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
00040c70:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan00040c70:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
00040c80:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl00040c80:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
00040c90:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r00040c90:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
00040ca0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"00040ca0:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
00040cb0:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB00040cb0:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
 00040cc0:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 00040cd0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 00040ce0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 00040cf0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 00040d00:·6d31·3934·3322·3e3c·7461·626c·6520·636c··m1943"><table·cl
 00040d10:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 00040d20:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 00040d30:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 00040d40:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 00040d50:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 00040d60:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 00040d70:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 00040d80:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 00040d90:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 00040da0:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 00040db0:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 00040dc0:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 00040dd0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
00040cc0:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
00040cd0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
00040ce0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
00040cf0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
00040d00:·6c61·7073·6522·2069·643d·2269·646d·3139··lapse"·id="idm19 
00040d10:·3433·223e·3c70·7265·3e3c·636f·6465·3e0a··43"><pre><code>. 
00040d20:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
00040d30:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
00040d40:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code> 
00040d50:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c 
00040d60:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su 
00040d70:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg 
00040d80:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da 
00040d90:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1 
00040da0:·3934·3422·2074·6162·696e·6465·783d·2230··944"·tabindex="0 
00040db0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"· 
00040dc0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f 
00040dd0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act 
00040de0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal" 
00040df0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed 
00040e00:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr 
00040e10:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br>< 
00040e20:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00040e30:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00040e40:·7365·2220·6964·3d22·6964·6d31·3934·3422··se"·id="idm1944" 
00040e50:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t 
00040e60:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip 
00040e70:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere 
00040e80:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense 
00040e90:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl 
00040ea0:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l 
00040eb0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr> 
00040ec0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:< 
00040ed0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td> 
00040ee0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb 
00040ef0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal 
00040f00:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>00040de0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
 00040df0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
00040f10:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t 
00040f20:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td 
00040f30:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p 
00040f40:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed 
00040f50:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic 
00040f60:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer 
00040f70:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i 
00040f80:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q 
00040f90:·206b·6572·6e65·6c3b·2074·6865·6e0a·0a69···kernel;·then..i 
00040fa0:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui 
00040fb0:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then 
00040fc0:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install 
00040fd0:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e 
00040fe0:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp 
00040ff0:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia 
00041000:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl 
00041010:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing· 
00041020:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c 
00041030:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00041040:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00041050:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00041060:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00041070:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00041080:·6964·6d31·3934·3522·2074·6162·696e·6465··idm1945"·tabinde 
00041090:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
000410a0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
000410b0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
000410c0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
000410d0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
000410e0:·656d·6564·6961·7469·6f6e·2041·6e73·6962··emediation·Ansib00040e00:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 00040e10:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 00040e20:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 00040e30:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 00040e40:·6965·7420·2d71·206b·6572·6e65·6c3b·2074··iet·-q·kernel;·t
 00040e50:·6865·6e0a·0a69·6620·2120·7270·6d20·2d71··hen..if·!·rpm·-q
 00040e60:·202d·2d71·7569·6574·2022·6169·6465·2220···--quiet·"aide"·
 00040e70:·3b20·7468·656e·0a20·2020·2079·756d·2069··;·then.····yum·i
 00040e80:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 00040e90:·0a66·690a·0a65·6c73·650a·2020·2020·2667··.fi..else.····&g
 00040ea0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 00040eb0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 00040ec0:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 00040ed0:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 00040ee0:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
 00040ef0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
 00040f00:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
 00040f10:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
 00040f20:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
 00040f30:·6765·743d·2223·6964·6d31·3934·3422·2074··get="#idm1944"·t
 00040f40:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
 00040f50:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
 00040f60:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
 00040f70:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
 00040f80:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
 00040f90:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
 00040fa0:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
000410f0:·6c65·2073·6e69·7070·6574·20e2·87b2·3c2f··le·snippet·...</ 
00041100:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
00041110:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
00041120:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
00041130:·646d·3139·3435·223e·3c74·6162·6c65·2063··dm1945"><table·c 
00041140:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl 
00041150:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table- 
Max diff block lines reached; 284827/312869 bytes (91.04%) of diff not shown.
38.0 KB
html2text {}
    
Offset 495, 19 lines modifiedOffset 495, 14 lines modified
495 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3495 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
496 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)496 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
497 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3497 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
498 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5498 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
499 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199499 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
500 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79500 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
501 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2501 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
502 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
503 [[packages]] 
504 name·=·"aide" 
505 version·=·"*" 
506 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8502 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
507 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low503 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
508 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low504 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
509 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false505 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
510 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable506 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
511 #·Remediation·is·applicable·only·in·certain·platforms507 #·Remediation·is·applicable·only·in·certain·platforms
512 if·rpm·--quiet·-q·kernel;·then508 if·rpm·--quiet·-q·kernel;·then
Offset 551, 33 lines modifiedOffset 546, 38 lines modified
551 ··-·PCI-DSSv4-11.5.2546 ··-·PCI-DSSv4-11.5.2
552 ··-·enable_strategy547 ··-·enable_strategy
553 ··-·low_complexity548 ··-·low_complexity
554 ··-·low_disruption549 ··-·low_disruption
555 ··-·medium_severity550 ··-·medium_severity
556 ··-·no_reboot_needed551 ··-·no_reboot_needed
557 ··-·package_aide_installed552 ··-·package_aide_installed
 553 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 554 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 555 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 556 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 557 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 558 package·--add=aide
 559 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 560 [[packages]]
 561 name·=·"aide"
 562 version·=·"*"
558 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
559 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low564 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
560 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low565 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
561 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false566 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
562 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable567 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
563 include·install_aide568 include·install_aide
  
564 class·install_aide·{569 class·install_aide·{
565 ··package·{·'aide':570 ··package·{·'aide':
566 ····ensure·=>·'installed',571 ····ensure·=>·'installed',
567 ··}572 ··}
568 }573 }
569 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
570 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
571 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
572 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
573 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
574 package·--add=aide 
575 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*574 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
576 Run·the·following·command·to·generate·a·new·database:575 Run·the·following·command·to·generate·a·new·database:
577 $·sudo·/usr/sbin/aide·--init576 $·sudo·/usr/sbin/aide·--init
578 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:577 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
579 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz578 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
580 To·initiate·a·manual·check,·run·the·following·command:579 To·initiate·a·manual·check,·run·the·following·command:
581 $·sudo·/usr/sbin/aide·--check580 $·sudo·/usr/sbin/aide·--check
Offset 7354, 19 lines modifiedOffset 7354, 14 lines modified
7354 ············Multifactor·solutions·that·require·devices·separate·from·information·systems·gaining·access·include,·for·example,·hardware·tokens·providing·time-based·or·challenge-response·authenticators·and·smart·cards·such·as·the·U.S.·Government·Personal·Identity·Verification·card·and·the·DoD·Common·Access·Card.7354 ············Multifactor·solutions·that·require·devices·separate·from·information·systems·gaining·access·include,·for·example,·hardware·tokens·providing·time-based·or·challenge-response·authenticators·and·smart·cards·such·as·the·U.S.·Government·Personal·Identity·Verification·card·and·the·DoD·Common·Access·Card.
7355 Severity: ··medium7355 Severity: ··medium
7356 Rule·ID:····xccdf_org.ssgproject.content_rule_package_opensc_installed7356 Rule·ID:····xccdf_org.ssgproject.content_rule_package_opensc_installed
7357 ············_\x8d_\x8i_\x8s_\x8a···CCI-001953,·CCI-0040467357 ············_\x8d_\x8i_\x8s_\x8a···CCI-001953,·CCI-004046
7358 References:·_\x8i_\x8s_\x8m····1382,·1384,·13867358 References:·_\x8i_\x8s_\x8m····1382,·1384,·1386
7359 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)7359 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)
7360 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-001617360 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161
7361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
7362 [[packages]] 
7363 name·=·"opensc" 
7364 version·=·"*" 
7365 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7366 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7362 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7367 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7363 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7368 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7364 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7369 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7365 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7370 #·Remediation·is·applicable·only·in·certain·platforms7366 #·Remediation·is·applicable·only·in·certain·platforms
7371 if·rpm·--quiet·-q·kernel;·then7367 if·rpm·--quiet·-q·kernel;·then
Offset 7404, 48 lines modifiedOffset 7399, 48 lines modified
7404 ··-·NIST-800-53-CM-6(a)7399 ··-·NIST-800-53-CM-6(a)
7405 ··-·enable_strategy7400 ··-·enable_strategy
7406 ··-·low_complexity7401 ··-·low_complexity
7407 ··-·low_disruption7402 ··-·low_disruption
7408 ··-·medium_severity7403 ··-·medium_severity
7409 ··-·no_reboot_needed7404 ··-·no_reboot_needed
7410 ··-·package_opensc_installed7405 ··-·package_opensc_installed
 7406 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 7407 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 7408 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 7409 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 7410 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 7411 package·--add=opensc
 7412 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 7413 [[packages]]
 7414 name·=·"opensc"
 7415 version·=·"*"
7411 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87416 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7412 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7417 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7413 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7418 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7414 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7419 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7415 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7420 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7416 include·install_opensc7421 include·install_opensc
  
7417 class·install_opensc·{7422 class·install_opensc·{
7418 ··package·{·'opensc':7423 ··package·{·'opensc':
7419 ····ensure·=>·'installed',7424 ····ensure·=>·'installed',
7420 ··}7425 ··}
7421 }7426 }
7422 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
7423 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
7424 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
7425 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
7426 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
7427 package·--add=opensc 
7428 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*7427 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
7429 The·pcsc-lite·package·can·be·installed·with·the·following·command:7428 The·pcsc-lite·package·can·be·installed·with·the·following·command:
7430 $·sudo·yum·install·pcsc-lite7429 $·sudo·yum·install·pcsc-lite
Max diff block lines reached; 33195/38933 bytes (85.26%) of diff not shown.
999 KB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-rhvh-stig.html
    
Offset 17321, 213 lines modifiedOffset 17321, 213 lines modified
00043a80:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm100043a80:·7461·2d74·6172·6765·743d·2223·6964·6d31··ta-target="#idm1
00043a90:·3934·3322·2074·6162·696e·6465·783d·2230··943"·tabindex="000043a90:·3934·3322·2074·6162·696e·6465·783d·2230··943"·tabindex="0
00043aa0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·00043aa0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
00043ab0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f00043ab0:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
00043ac0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act00043ac0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
00043ad0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"00043ad0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
00043ae0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed00043ae0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
00043af0:·6961·7469·6f6e·204f·5342·7569·6c64·2042··iation·OSBuild·B00043af0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr
 00043b00:·6970·7420·e287·b23c·2f61·3e3c·6272·3e3c··ipt·...</a><br><
 00043b10:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel
 00043b20:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap
 00043b30:·7365·2220·6964·3d22·6964·6d31·3934·3322··se"·id="idm1943"
 00043b40:·3e3c·7461·626c·6520·636c·6173·733d·2274··><table·class="t
 00043b50:·6162·6c65·2074·6162·6c65·2d73·7472·6970··able·table-strip
00043b00:·6c75·6570·7269·6e74·2073·6e69·7070·6574··lueprint·snippet 
00043b10:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div 
00043b20:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co 
00043b30:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse" 
00043b40:·2069·643d·2269·646d·3139·3433·223e·3c70···id="idm1943"><p 
00043b50:·7265·3e3c·636f·6465·3e0a·5b5b·7061·636b··re><code>.[[pack 
00043b60:·6167·6573·5d5d·0a6e·616d·6520·3d20·2261··ages]].name·=·"a 
00043b70:·6964·6522·0a76·6572·7369·6f6e·203d·2022··ide".version·=·" 
00043b80:·2a22·0a3c·2f63·6f64·653e·3c2f·7072·653e··*".</code></pre> 
00043b90:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class=" 
00043ba0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success" 
00043bb0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co 
00043bc0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar 
00043bd0:·6765·743d·2223·6964·6d31·3934·3422·2074··get="#idm1944"·t 
00043be0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role 
00043bf0:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e 
00043c00:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"· 
00043c10:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate· 
00043c20:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href= 
00043c30:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation 
00043c40:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·.. 
00043c50:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00043c60:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
00043c70:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
00043c80:·3d22·6964·6d31·3934·3422·3e3c·7461·626c··="idm1944"><tabl 
00043c90:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00043ca0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
00043cb0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00043cc0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00043cd0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00043ce0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00043cf0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00043d00:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00043d10:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00043d20:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00043d30:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00043d40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00043d50:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00043d60:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00043d70:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00043d80:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation 
00043d90:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o 
00043da0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p 
00043db0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm· 
00043dc0:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
00043dd0:·6c3b·2074·6865·6e0a·0a69·6620·2120·7270··l;·then..if·!·rp 
00043de0:·6d20·2d71·202d·2d71·7569·6574·2022·6169··m·-q·--quiet·"ai 
00043df0:·6465·2220·3b20·7468·656e·0a20·2020·2079··de"·;·then.····y 
00043e00:·756d·2069·6e73·7461·6c6c·202d·7920·2261··um·install·-y·"a 
00043e10:·6964·6522·0a66·690a·0a65·6c73·650a·2020··ide".fi..else.·· 
00043e20:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech 
00043e30:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i 
00043e40:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable 
00043e50:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do 
00043e60:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></ 
00043e70:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla 
00043e80:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ 
00043e90:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle 
00043ea0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data 
00043eb0:·2d74·6172·6765·743d·2223·6964·6d31·3934··-target="#idm194 
00043ec0:·3522·2074·6162·696e·6465·783d·2230·2220··5"·tabindex="0"· 
00043ed0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar 
00043ee0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal 
00043ef0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ 
00043f00:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h 
00043f10:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia 
00043f20:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni 
00043f30:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
00043f40:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00043f50:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00043f60:·7073·6522·2069·643d·2269·646d·3139·3435··pse"·id="idm1945 
00043f70:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
00043f80:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
00043f90:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
00043fa0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens00043b60:·6564·2074·6162·6c65·2d62·6f72·6465·7265··ed·table-bordere
00043fb0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00043fc0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
00043fd0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00043fe0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00043ff0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00044000:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
00044010:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa00043b70:·6420·7461·626c·652d·636f·6e64·656e·7365··d·table-condense
 00043b80:·6422·3e3c·7472·3e3c·7468·3e43·6f6d·706c··d"><tr><th>Compl
 00043b90:·6578·6974·793a·3c2f·7468·3e3c·7464·3e6c··exity:</th><td>l
 00043ba0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00043bb0:·3c74·683e·4469·7372·7570·7469·6f6e·3a3c··<th>Disruption:<
 00043bc0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 00043bd0:·3c2f·7472·3e3c·7472·3e3c·7468·3e52·6562··</tr><tr><th>Reb
 00043be0:·6f6f·743a·3c2f·7468·3e3c·7464·3e66·616c··oot:</th><td>fal
 00043bf0:·7365·3c2f·7464·3e3c·2f74·723e·3c74·723e··se</td></tr><tr>
 00043c00:·3c74·683e·5374·7261·7465·6779·3a3c·2f74··<th>Strategy:</t
 00043c10:·683e·3c74·643e·656e·6162·6c65·3c2f·7464··h><td>enable</td
 00043c20:·3e3c·2f74·723e·3c2f·7461·626c·653e·3c70··></tr></table><p
 00043c30:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed
 00043c40:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic
 00043c50:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer
 00043c60:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i
 00043c70:·6620·7270·6d20·2d2d·7175·6965·7420·2d71··f·rpm·--quiet·-q
 00043c80:·206b·6572·6e65·6c3b·2074·6865·6e0a·0a69···kernel;·then..i
 00043c90:·6620·2120·7270·6d20·2d71·202d·2d71·7569··f·!·rpm·-q·--qui
 00043ca0:·6574·2022·6169·6465·2220·3b20·7468·656e··et·"aide"·;·then
 00043cb0:·0a20·2020·2079·756d·2069·6e73·7461·6c6c··.····yum·install
 00043cc0:·202d·7920·2261·6964·6522·0a66·690a·0a65···-y·"aide".fi..e
 00043cd0:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp
 00043ce0:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia
 00043cf0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl
 00043d00:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·
 00043d10:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c
 00043d20:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 00043d30:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 00043d40:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
 00043d50:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse
 00043d60:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
Max diff block lines reached; 898086/926128 bytes (96.97%) of diff not shown.
94.5 KB
html2text {}
    
Offset 677, 19 lines modifiedOffset 677, 14 lines modified
677 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3677 ············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.12.1.2,·A.12.2.1,·A.12.4.1,·A.12.5.1,·A.12.6.2,·A.14.1.2,·A.14.1.3,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.14.2.7,·A.15.2.1,·A.8.2.3
678 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)678 ············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
679 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3679 ············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-7,·PR.DS-1,·PR.DS-6,·PR.DS-8,·PR.IP-1,·PR.IP-3
680 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5680 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
681 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199681 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
682 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79682 ············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
683 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2683 ············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
684 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
685 [[packages]] 
686 name·=·"aide" 
687 version·=·"*" 
688 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8684 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
689 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low685 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
690 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low686 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
691 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false687 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
692 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable688 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
693 #·Remediation·is·applicable·only·in·certain·platforms689 #·Remediation·is·applicable·only·in·certain·platforms
694 if·rpm·--quiet·-q·kernel;·then690 if·rpm·--quiet·-q·kernel;·then
Offset 733, 33 lines modifiedOffset 728, 38 lines modified
733 ··-·PCI-DSSv4-11.5.2728 ··-·PCI-DSSv4-11.5.2
734 ··-·enable_strategy729 ··-·enable_strategy
735 ··-·low_complexity730 ··-·low_complexity
736 ··-·low_disruption731 ··-·low_disruption
737 ··-·medium_severity732 ··-·medium_severity
738 ··-·no_reboot_needed733 ··-·no_reboot_needed
739 ··-·package_aide_installed734 ··-·package_aide_installed
 735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 737 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 738 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 739 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 740 package·--add=aide
 741 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 742 [[packages]]
 743 name·=·"aide"
 744 version·=·"*"
740 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8745 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
741 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low746 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
742 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low747 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
743 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false748 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
744 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable749 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
745 include·install_aide750 include·install_aide
  
746 class·install_aide·{751 class·install_aide·{
747 ··package·{·'aide':752 ··package·{·'aide':
748 ····ensure·=>·'installed',753 ····ensure·=>·'installed',
749 ··}754 ··}
750 }755 }
751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
752 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
753 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
754 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
755 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
756 package·--add=aide 
757 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*756 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·B\x8Bu\x8ui\x8il\x8ld\x8d·a\x8an\x8nd\x8d·T\x8Te\x8es\x8st\x8t·A\x8AI\x8ID\x8DE\x8E·D\x8Da\x8at\x8ta\x8ab\x8ba\x8as\x8se\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
758 Run·the·following·command·to·generate·a·new·database:757 Run·the·following·command·to·generate·a·new·database:
759 $·sudo·/usr/sbin/aide·--init758 $·sudo·/usr/sbin/aide·--init
760 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:759 By·default,·the·database·will·be·written·to·the·file·/var/lib/aide/aide.db.new.gz.·Storing·the·database,·the·configuration·file·/etc/aide.conf,·and·the·binary·/usr/sbin/aide·(or·hashes·of·these·files),·in·a·secure·location·(such·as·on·read-only·media)·provides·additional·assurance·about·their·integrity.·The·newly-generated·database·can·be·installed·as·follows:
761 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz760 $·sudo·cp·/var/lib/aide/aide.db.new.gz·/var/lib/aide/aide.db.gz
762 To·initiate·a·manual·check,·run·the·following·command:761 To·initiate·a·manual·check,·run·the·following·command:
763 $·sudo·/usr/sbin/aide·--check762 $·sudo·/usr/sbin/aide·--check
Offset 1583, 31 lines modifiedOffset 1583, 31 lines modified
1583 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode1583 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
1584 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-0008771584 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
1585 ············_\x8i_\x8s_\x8m······14461585 ············_\x8i_\x8s_\x8m······1446
1586 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.11586 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
1587 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-121587 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
1588 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.11588 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
1589 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-001761589 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
1590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1591 [customizations] 
1592 fips·=·true 
1593 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81590 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1594 #·Remediation·is·applicable·only·in·certain·platforms1591 #·Remediation·is·applicable·only·in·certain·platforms
1595 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then1592 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
1596 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then1593 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
1597 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF1594 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
1598 kargs·=·["fips=1"]1595 kargs·=·["fips=1"]
1599 EOF1596 EOF
1600 fi1597 fi
  
1601 else1598 else
1602 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'1599 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
1603 fi1600 fi
 1601 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1602 [customizations]
 1603 fips·=·true
1604 Group  ·System·Cryptographic·Policies·  Group·contains·6·rules1604 Group  ·System·Cryptographic·Policies·  Group·contains·6·rules
1605 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:1605 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
1606 ····*·GnuTLS·library1606 ····*·GnuTLS·library
1607 ····*·OpenSSL·library1607 ····*·OpenSSL·library
1608 ····*·NSS·library1608 ····*·NSS·library
1609 ····*·OpenJDK1609 ····*·OpenJDK
1610 ····*·Libkrb51610 ····*·Libkrb5
Offset 2303, 33 lines modifiedOffset 2303, 33 lines modified
2303 ··-·NIST-800-53-CM-7(b)2303 ··-·NIST-800-53-CM-7(b)
2304 ··-·disable_strategy2304 ··-·disable_strategy
2305 ··-·low_complexity2305 ··-·low_complexity
2306 ··-·low_disruption2306 ··-·low_disruption
2307 ··-·medium_severity2307 ··-·medium_severity
2308 ··-·no_reboot_needed2308 ··-·no_reboot_needed
2309 ··-·package_gdm_removed2309 ··-·package_gdm_removed
 2310 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 2311 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 2312 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 2313 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 2314 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
  
 2315 package·--remove=gdm
2310 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82316 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2311 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2317 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2312 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2318 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2313 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2319 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2314 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable2320 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
2315 include·remove_gdm2321 include·remove_gdm
  
2316 class·remove_gdm·{2322 class·remove_gdm·{
2317 ··package·{·'gdm':2323 ··package·{·'gdm':
2318 ····ensure·=>·'purged',2324 ····ensure·=>·'purged',
2319 ··}2325 ··}
Max diff block lines reached; 90891/96782 bytes (93.91%) of diff not shown.
337 KB
./usr/share/doc/ssg-nondebian/ssg-rhv4-guide-rhvh-vpp.html
    
Offset 17415, 62 lines modifiedOffset 17415, 62 lines modified
00044060:·612d·7461·7267·6574·3d22·2369·646d·3234··a-target="#idm2400044060:·612d·7461·7267·6574·3d22·2369·646d·3234··a-target="#idm24
00044070:·3234·2220·7461·6269·6e64·6578·3d22·3022··24"·tabindex="0"00044070:·3234·2220·7461·6269·6e64·6578·3d22·3022··24"·tabindex="0"
00044080:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a00044080:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a
00044090:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa00044090:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa
000440a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti000440a0:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti
000440b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·000440b0:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·
000440c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi000440c0:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi
000440d0:·6174·696f·6e20·4f53·4275·696c·6420·426c··ation·OSBuild·Bl 
000440e0:·7565·7072·696e·7420·736e·6970·7065·7420··ueprint·snippet· 
000440f0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00044100:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00044110:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00044120:·6964·3d22·6964·6d32·3432·3422·3e3c·7072··id="idm2424"><pr 
00044130:·653e·3c63·6f64·653e·0a5b·6375·7374·6f6d··e><code>.[custom 
00044140:·697a·6174·696f·6e73·5d0a·6669·7073·203d··izations].fips·= 
00044150:·2074·7275·650a·3c2f·636f·6465·3e3c·2f70···true.</code></p 
00044160:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas 
00044170:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe 
00044180:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle= 
00044190:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data- 
000441a0:·7461·7267·6574·3d22·2369·646d·3234·3235··target="#idm2425 
000441b0:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r 
000441c0:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari 
000441d0:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals 
000441e0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa 
000441f0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr 
00044200:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat 
00044210:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script000440d0:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri
00044220:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div000440e0:·7074·20e2·87b2·3c2f·613e·3c62·723e·3c64··pt·...</a><br><d
00044230:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co000440f0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
00044240:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"00044100:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
00044250:·2069·643d·2269·646d·3234·3235·223e·3c70···id="idm2425"><p00044110:·6522·2069·643d·2269·646d·3234·3234·223e··e"·id="idm2424">
00044260:·7265·3e3c·636f·6465·3e23·2052·656d·6564··re><code>#·Remed00044120:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
00044270:·6961·7469·6f6e·2069·7320·6170·706c·6963··iation·is·applic00044130:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
00044280:·6162·6c65·206f·6e6c·7920·696e·2063·6572··able·only·in·cer00044140:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
00044290:·7461·696e·2070·6c61·7466·6f72·6d73·0a69··tain·platforms.i00044150:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
000442a0:·6620·2820·2120·2820·5b20·2224·7b63·6f6e··f·(·!·(·[·"${con00044160:·0a69·6620·2820·2120·2820·5b20·2224·7b63··.if·(·!·(·[·"${c
000442b0:·7461·696e·6572·3a2d·7d22·203d·3d20·2262··tainer:-}"·==·"b00044170:·6f6e·7461·696e·6572·3a2d·7d22·203d·3d20··ontainer:-}"·==·
000442c0:·7772·6170·2d6f·7362·7569·6c64·2220·5d20··wrap-osbuild"·]·00044180:·2262·7772·6170·2d6f·7362·7569·6c64·2220··"bwrap-osbuild"·
000442d0:·2920·2661·6d70·3b26·616d·703b·2072·706d··)·&amp;&amp;·rpm00044190:·5d20·2920·2661·6d70·3b26·616d·703b·2072··]·)·&amp;&amp;·r
000442e0:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern000441a0:·706d·202d·2d71·7569·6574·202d·7120·6b65··pm·--quiet·-q·ke
000442f0:·656c·2029·3b20·7468·656e·0a0a·6966·205b··el·);·then..if·[000441b0:·726e·656c·2029·3b20·7468·656e·0a0a·6966··rnel·);·then..if
00044300:·5b20·2224·4f53·4341·505f·424f·4f54·435f··[·"$OSCAP_BOOTC_000441c0:·205b·5b20·2224·4f53·4341·505f·424f·4f54···[[·"$OSCAP_BOOT
00044310:·4255·494c·4422·203d·3d20·2259·4553·2220··BUILD"·==·"YES"·000441d0:·435f·4255·494c·4422·203d·3d20·2259·4553··C_BUILD"·==·"YES
00044320:·5d5d·3b20·7468·656e·0a09·6361·7420·2667··]];·then..cat·&g000441e0:·2220·5d5d·3b20·7468·656e·0a09·6361·7420··"·]];·then..cat·
00044330:·743b·202f·7573·722f·6c69·622f·626f·6f74··t;·/usr/lib/boot000441f0:·2667·743b·202f·7573·722f·6c69·622f·626f··&gt;·/usr/lib/bo
00044340:·632f·6b61·7267·732e·642f·3031·2d66·6970··c/kargs.d/01-fip00044200:·6f74·632f·6b61·7267·732e·642f·3031·2d66··otc/kargs.d/01-f
00044350:·732e·746f·6d6c·2026·6c74·3b26·6c74·3b20··s.toml·&lt;&lt;·00044210:·6970·732e·746f·6d6c·2026·6c74·3b26·6c74··ips.toml·&lt;&lt
00044360:·454f·460a·6b61·7267·7320·3d20·5b22·6669··EOF.kargs·=·["fi00044220:·3b20·454f·460a·6b61·7267·7320·3d20·5b22··;·EOF.kargs·=·["
00044370:·7073·3d31·225d·0a45·4f46·0a66·690a·0a65··ps=1"].EOF.fi..e00044230:·6669·7073·3d31·225d·0a45·4f46·0a66·690a··fips=1"].EOF.fi.
00044380:·6c73·650a·2020·2020·2667·743b·2661·6d70··lse.····&gt;&amp00044240:·0a65·6c73·650a·2020·2020·2667·743b·2661··.else.····&gt;&a
00044390:·3b32·2065·6368·6f20·2752·656d·6564·6961··;2·echo·'Remedia00044250:·6d70·3b32·2065·6368·6f20·2752·656d·6564··mp;2·echo·'Remed
000443a0:·7469·6f6e·2069·7320·6e6f·7420·6170·706c··tion·is·not·appl00044260:·6961·7469·6f6e·2069·7320·6e6f·7420·6170··iation·is·not·ap
000443b0:·6963·6162·6c65·2c20·6e6f·7468·696e·6720··icable,·nothing·00044270:·706c·6963·6162·6c65·2c20·6e6f·7468·696e··plicable,·nothin
000443c0:·7761·7320·646f·6e65·270a·6669·0a3c·2f63··was·done'.fi.</c00044280:·6720·7761·7320·646f·6e65·270a·6669·0a3c··g·was·done'.fi.<
 00044290:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di
 000442a0:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn·
 000442b0:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat
 000442c0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap
 000442d0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
 000442e0:·2223·6964·6d32·3432·3522·2074·6162·696e··"#idm2425"·tabin
 000442f0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
 00044300:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
 00044310:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
 00044320:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
 00044330:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
 00044340:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB
 00044350:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s
 00044360:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 00044370:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 00044380:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00044390:·6c61·7073·6522·2069·643d·2269·646d·3234··lapse"·id="idm24
 000443a0:·3235·223e·3c70·7265·3e3c·636f·6465·3e0a··25"><pre><code>.
 000443b0:·5b63·7573·746f·6d69·7a61·7469·6f6e·735d··[customizations]
 000443c0:·0a66·6970·7320·3d20·7472·7565·0a3c·2f63··.fips·=·true.</c
000443d0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>000443d0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
000443e0:·3c2f·6469·763e·3c2f·7464·3e3c·2f74·723e··</div></td></tr>000443e0:·3c2f·6469·763e·3c2f·7464·3e3c·2f74·723e··</div></td></tr>
000443f0:·3c2f·7462·6f64·793e·3c2f·7461·626c·653e··</tbody></table>000443f0:·3c2f·7462·6f64·793e·3c2f·7461·626c·653e··</tbody></table>
00044400:·3c2f·7464·3e3c·2f74·723e·3c74·7220·6461··</td></tr><tr·da00044400:·3c2f·7464·3e3c·2f74·723e·3c74·7220·6461··</td></tr><tr·da
00044410:·7461·2d74·742d·6964·3d22·6368·696c·6472··ta-tt-id="childr00044410:·7461·2d74·742d·6964·3d22·6368·696c·6472··ta-tt-id="childr
00044420:·656e·2d78·6363·6466·5f6f·7267·2e73·7367··en-xccdf_org.ssg00044420:·656e·2d78·6363·6466·5f6f·7267·2e73·7367··en-xccdf_org.ssg
00044430:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_00044430:·7072·6f6a·6563·742e·636f·6e74·656e·745f··project.content_
Offset 46530, 207 lines modifiedOffset 46530, 207 lines modified
000b5c10:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe000b5c10:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
000b5c20:·743d·2223·6964·6d37·3738·3122·2074·6162··t="#idm7781"·tab000b5c20:·743d·2223·6964·6d37·3738·3122·2074·6162··t="#idm7781"·tab
000b5c30:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="000b5c30:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
000b5c40:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp000b5c40:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
000b5c50:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti000b5c50:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
000b5c60:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to000b5c60:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
000b5c70:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#000b5c70:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
000b5c80:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O000b5c80:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
000b5c90:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint000b5c90:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 000b5ca0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 000b5cb0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 000b5cc0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 000b5cd0:·6964·6d37·3738·3122·3e3c·7461·626c·6520··idm7781"><table·
 000b5ce0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 000b5cf0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 000b5d00:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 000b5d10:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 000b5d20:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 000b5d30:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 000b5d40:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 000b5d50:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 000b5d60:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 000b5d70:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 000b5d80:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 000b5d90:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 000b5da0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 000b5db0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 000b5dc0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 000b5dd0:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 000b5de0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 000b5df0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 000b5e00:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
 000b5e10:·7175·6965·7420·2d71·206b·6572·6e65·6c3b··quiet·-q·kernel;
 000b5e20:·2074·6865·6e0a·0a69·6620·2120·7270·6d20···then..if·!·rpm·
 000b5e30:·2d71·202d·2d71·7569·6574·2022·6f70·656e··-q·--quiet·"open
 000b5e40:·7363·2220·3b20·7468·656e·0a20·2020·2079··sc"·;·then.····y
 000b5e50:·756d·2069·6e73·7461·6c6c·202d·7920·226f··um·install·-y·"o
 000b5e60:·7065·6e73·6322·0a66·690a·0a65·6c73·650a··pensc".fi..else.
 000b5e70:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 000b5e80:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 000b5e90:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 000b5ea0:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 000b5eb0:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
 000b5ec0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
Max diff block lines reached; 271963/306793 bytes (88.65%) of diff not shown.
36.9 KB
html2text {}
    
Offset 691, 31 lines modifiedOffset 691, 31 lines modified
691 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode691 Rule·ID:····xccdf_org.ssgproject.content_rule_enable_fips_mode
692 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877692 ············_\x8d_\x8i_\x8s_\x8a·····CCI-002450,·CCI-000068,·CCI-002418,·CCI-000877
693 ············_\x8i_\x8s_\x8m······1446693 ············_\x8i_\x8s_\x8m······1446
694 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1694 References:·_\x8n_\x8e_\x8r_\x8c_\x8-_\x8c_\x8i_\x8p·CIP-003-8·R4.2,·CIP-007-3·R5.1
695 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12695 ············_\x8n_\x8i_\x8s_\x8t·····CM-3(6),·SC-12(2),·SC-12(3),·IA-7,·SC-13,·CM-6(a),·SC-12
696 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1696 ············_\x8o_\x8s_\x8p_\x8p·····FCS_COP.1(1),·FCS_COP.1(2),·FCS_COP.1(3),·FCS_COP.1(4),·FCS_CKM.1,·FCS_CKM.2,·FCS_TLSC_EXT.1,·FCS_RBG_EXT.1
697 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176697 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g···SRG-OS-000478-GPOS-00223,·SRG-OS-000396-GPOS-00176
698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
699 [customizations] 
700 fips·=·true 
701 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
702 #·Remediation·is·applicable·only·in·certain·platforms699 #·Remediation·is·applicable·only·in·certain·platforms
703 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then700 if·(·!·(·[·"${container:-}"·==·"bwrap-osbuild"·]·)·&&·rpm·--quiet·-q·kernel·);·then
  
704 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then701 if·[[·"$OSCAP_BOOTC_BUILD"·==·"YES"·]];·then
705 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF702 »       cat·>·/usr/lib/bootc/kargs.d/01-fips.toml·<<·EOF
706 kargs·=·["fips=1"]703 kargs·=·["fips=1"]
707 EOF704 EOF
708 fi705 fi
  
709 else706 else
710 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'707 ····>&2·echo·'Remediation·is·not·applicable,·nothing·was·done'
711 fi708 fi
 709 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 710 [customizations]
 711 fips·=·true
712 Group  ·System·Cryptographic·Policies·  Group·contains·6·rules712 Group  ·System·Cryptographic·Policies·  Group·contains·6·rules
713 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:713 _\x8[_\x8r_\x8e_\x8f_\x8]  ·Linux·has·the·capability·to·centrally·configure·cryptographic·polices.·The·command·update-crypto-policies·is·used·to·set·the·policy·applicable·for·the·various·cryptographic·back-ends,·such·as·SSL/TLS·libraries.·The·configured·cryptographic·policies·will·be·the·default·policy·used·by·these·backends·unless·the·application·user·configures·them·otherwise.·When·the·system·has·been·configured·to·use·the·centralized·cryptographic·policies,·the·administrator·is·assured·that·any·application·that·utilizes·the·supported·backends·will·follow·a·policy·that·adheres·to·the·configured·profile.·Currently·the·supported·backends·are:
714 ····*·GnuTLS·library714 ····*·GnuTLS·library
715 ····*·OpenSSL·library715 ····*·OpenSSL·library
716 ····*·NSS·library716 ····*·NSS·library
717 ····*·OpenJDK717 ····*·OpenJDK
718 ····*·Libkrb5718 ····*·Libkrb5
Offset 8737, 19 lines modifiedOffset 8737, 14 lines modified
8737 ············Multifactor·solutions·that·require·devices·separate·from·information·systems·gaining·access·include,·for·example,·hardware·tokens·providing·time-based·or·challenge-response·authenticators·and·smart·cards·such·as·the·U.S.·Government·Personal·Identity·Verification·card·and·the·DoD·Common·Access·Card.8737 ············Multifactor·solutions·that·require·devices·separate·from·information·systems·gaining·access·include,·for·example,·hardware·tokens·providing·time-based·or·challenge-response·authenticators·and·smart·cards·such·as·the·U.S.·Government·Personal·Identity·Verification·card·and·the·DoD·Common·Access·Card.
8738 Severity: ··medium8738 Severity: ··medium
8739 Rule·ID:····xccdf_org.ssgproject.content_rule_package_opensc_installed8739 Rule·ID:····xccdf_org.ssgproject.content_rule_package_opensc_installed
8740 ············_\x8d_\x8i_\x8s_\x8a···CCI-001953,·CCI-0040468740 ············_\x8d_\x8i_\x8s_\x8a···CCI-001953,·CCI-004046
8741 References:·_\x8i_\x8s_\x8m····1382,·1384,·13868741 References:·_\x8i_\x8s_\x8m····1382,·1384,·1386
8742 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)8742 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)
8743 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-001618743 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-00160,·SRG-OS-000376-GPOS-00161
8744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
8745 [[packages]] 
8746 name·=·"opensc" 
8747 version·=·"*" 
8748 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x88744 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
8749 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8745 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8750 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8746 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8751 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8747 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8752 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8748 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8753 #·Remediation·is·applicable·only·in·certain·platforms8749 #·Remediation·is·applicable·only·in·certain·platforms
8754 if·rpm·--quiet·-q·kernel;·then8750 if·rpm·--quiet·-q·kernel;·then
Offset 8787, 48 lines modifiedOffset 8782, 48 lines modified
8787 ··-·NIST-800-53-CM-6(a)8782 ··-·NIST-800-53-CM-6(a)
8788 ··-·enable_strategy8783 ··-·enable_strategy
8789 ··-·low_complexity8784 ··-·low_complexity
8790 ··-·low_disruption8785 ··-·low_disruption
8791 ··-·medium_severity8786 ··-·medium_severity
8792 ··-·no_reboot_needed8787 ··-·no_reboot_needed
8793 ··-·package_opensc_installed8788 ··-·package_opensc_installed
 8789 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 8790 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 8791 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
 8792 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
 8793 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
  
 8794 package·--add=opensc
 8795 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 8796 [[packages]]
 8797 name·=·"opensc"
 8798 version·=·"*"
8794 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88799 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8795 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8800 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8796 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8801 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8797 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8802 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8798 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8803 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8799 include·install_opensc8804 include·install_opensc
  
8800 class·install_opensc·{8805 class·install_opensc·{
8801 ··package·{·'opensc':8806 ··package·{·'opensc':
8802 ····ensure·=>·'installed',8807 ····ensure·=>·'installed',
8803 ··}8808 ··}
8804 }8809 }
8805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
8806 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low 
8807 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low 
8808 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false 
8809 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable 
  
8810 package·--add=opensc 
8811 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*8810 *\x8**\x8**\x8*·R\x8Ru\x8ul\x8le\x8e?\x8 ?\x8 ·I\x8In\x8ns\x8st\x8ta\x8al\x8ll\x8l·t\x8th\x8he\x8e·p\x8pc\x8cs\x8sc\x8c-\x8-l\x8li\x8it\x8te\x8e·p\x8pa\x8ac\x8ck\x8ka\x8ag\x8ge\x8e·?\x8 ?\x8 _\x8[\x8[_\x8r\x8r_\x8e\x8e_\x8f\x8f_\x8]\x8]·*\x8**\x8**\x8*
8812 The·pcsc-lite·package·can·be·installed·with·the·following·command:8811 The·pcsc-lite·package·can·be·installed·with·the·following·command:
8813 $·sudo·yum·install·pcsc-lite8812 $·sudo·yum·install·pcsc-lite
8814 Rationale:··The·pcsc-lite·package·must·be·installed·if·it·is·to·be·available·for·multifactor·authentication·using·smartcards.8813 Rationale:··The·pcsc-lite·package·must·be·installed·if·it·is·to·be·available·for·multifactor·authentication·using·smartcards.
8815 Severity: ··medium8814 Severity: ··medium
8816 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed8815 Rule·ID:····xccdf_org.ssgproject.content_rule_package_pcsc-lite_installed
8817 ············_\x8d_\x8i_\x8s_\x8a···CCI-0040468816 ············_\x8d_\x8i_\x8s_\x8a···CCI-004046
8818 References:·_\x8i_\x8s_\x8m····1382,·1384,·13868817 References:·_\x8i_\x8s_\x8m····1382,·1384,·1386
8819 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)8818 ············_\x8n_\x8i_\x8s_\x8t···CM-6(a)
8820 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-001608819 ············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-00160
8821 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
8822 [[packages]] 
8823 name·=·"pcsc-lite" 
8824 version·=·"*" 
8825 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x88820 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
8826 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8821 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8827 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8822 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8828 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8823 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8829 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8824 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8830 #·Remediation·is·applicable·only·in·certain·platforms8825 #·Remediation·is·applicable·only·in·certain·platforms
8831 if·rpm·--quiet·-q·kernel;·then8826 if·rpm·--quiet·-q·kernel;·then
Offset 8866, 50 lines modifiedOffset 8861, 51 lines modified
8866 ··-·NIST-800-53-CM-6(a)8861 ··-·NIST-800-53-CM-6(a)
8867 ··-·enable_strategy8862 ··-·enable_strategy
8868 ··-·low_complexity8863 ··-·low_complexity
8869 ··-·low_disruption8864 ··-·low_disruption
8870 ··-·medium_severity8865 ··-·medium_severity
8871 ··-·no_reboot_needed8866 ··-·no_reboot_needed
8872 ··-·package_pcsc-lite_installed8867 ··-·package_pcsc-lite_installed
 8868 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8A_\x8n_\x8a_\x8c_\x8o_\x8n_\x8d_\x8a_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
 8869 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
 8870 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
Max diff block lines reached; 31444/37741 bytes (83.32%) of diff not shown.
582 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-anssi_bp28_enhanced.html
    
Offset 15133, 146 lines modifiedOffset 15133, 146 lines modified
0003b1c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b1c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b1d0:·3533·3937·2220·7461·6269·6e64·6578·3d22··5397"·tabindex="0003b1d0:·3533·3937·2220·7461·6269·6e64·6578·3d22··5397"·tabindex="
0003b1e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b1e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b1f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b1f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b200:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b200:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b210:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b210:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b220:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b220:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b230:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·0003b230:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
0003b240:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0003b250:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b260:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b270:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b280:·2220·6964·3d22·6964·6d35·3339·3722·3e3c··"·id="idm5397"><0003b240:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003b250:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b260:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b270:·7073·6522·2069·643d·2269·646d·3533·3937··pse"·id="idm5397
 0003b280:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b290:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b2a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b2b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b2c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b2d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b2e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b2f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b300:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b310:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b320:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b330:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b340:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b350:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b360:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003b290:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac0003b370:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
0003b2a0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
0003b2b0:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·0003b380:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 0003b390:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 0003b3a0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 0003b3b0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 0003b3c0:·7120·6b65·726e·656c·2d64·6566·6175·6c74··q·kernel-default
 0003b3d0:·3b20·7468·656e·0a0a·7a79·7070·6572·2069··;·then..zypper·i
 0003b3e0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 0003b3f0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003b400:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003b410:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003b420:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003b430:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
0003b2c0:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre0003b440:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003b2d0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003b450:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003b2e0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003b460:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003b2f0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003b470:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003b300:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003b480:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b310:·7267·6574·3d22·2369·646d·3533·3938·2220··rget="#idm5398"·0003b490:·3d22·2369·646d·3533·3938·2220·7461·6269··="#idm5398"·tabi
0003b320:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b4a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b330:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b4b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b340:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b4c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b350:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b4d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b360:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b4e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b370:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b4f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003b380:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.0003b500:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·..
 0003b510:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b520:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b530:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b540:·3d22·6964·6d35·3339·3822·3e3c·7461·626c··="idm5398"><tabl
 0003b550:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b560:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b570:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b580:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b590:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b5a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b5b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b5c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b5d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b5e0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b5f0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b600:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b610:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003b620:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003b630:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b640:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe
 0003b650:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa
 0003b660:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa
 0003b670:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager
 0003b680:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.·
 0003b690:·202d·2043·4345·2d38·3330·3637·2d39·0a20···-·CCE-83067-9.·
 0003b6a0:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3
 0003b6b0:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
 0003b6c0:·4c45·532d·3132·2d30·3130·3439·390a·2020··LES-12-010499.··
 0003b6d0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 0003b6e0:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
 0003b6f0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
 0003b700:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
 0003b710:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
 0003b720:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp
 0003b730:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
 0003b740:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
 0003b750:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
 0003b760:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
 0003b770:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a
 0003b780:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..-
 0003b790:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai
 0003b7a0:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed.
 0003b7b0:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n
 0003b7c0:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st
 0003b7d0:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w
 0003b7e0:·6865·6e3a·2027·226b·6572·6e65·6c2d·6465··hen:·'"kernel-de
 0003b7f0:·6661·756c·7422·2069·6e20·616e·7369·626c··fault"·in·ansibl
 0003b800:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
 0003b810:·270a·2020·7461·6773·3a0a·2020·2d20·4343··'.··tags:.··-·CC
 0003b820:·452d·3833·3036·372d·390a·2020·2d20·434a··E-83067-9.··-·CJ
 0003b830:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-·
 0003b840:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1
 0003b850:·322d·3031·3034·3939·0a20·202d·204e·4953··2-010499.··-·NIS
 0003b860:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
 0003b870:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
 0003b880:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
 0003b890:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e
 0003b8a0:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.·
 0003b8b0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
 0003b8c0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup
 0003b8d0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
 0003b8e0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
 0003b8f0:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
 0003b900:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i
 0003b910:·6e73·7461·6c6c·6564·0a3c·2f63·6f64·653e··nstalled.</code>
 0003b920:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b930:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b940:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003b950:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
Max diff block lines reached; 546410/565206 bytes (96.67%) of diff not shown.
29.7 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 14 lines modified
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
125 ·············_\x8c_\x8i_\x8s············1.4.1125 ·············_\x8c_\x8i_\x8s············1.4.1
126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms134 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel-default;·then135 if·rpm·--quiet·-q·kernel-default;·then
Offset 180, 14 lines modifiedOffset 175, 19 lines modified
180 ··-·PCI-DSSv4-11.5.2175 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy176 ··-·enable_strategy
182 ··-·low_complexity177 ··-·low_complexity
183 ··-·low_disruption178 ··-·low_disruption
184 ··-·medium_severity179 ··-·medium_severity
185 ··-·no_reboot_needed180 ··-·no_reboot_needed
186 ··-·package_aide_installed181 ··-·package_aide_installed
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide191 include·install_aide
  
Offset 607, 19 lines modifiedOffset 607, 14 lines modified
607 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386607 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
608 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)608 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
609 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1609 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
610 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125610 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
611 ·············_\x8c_\x8i_\x8s·····1.3.1611 ·············_\x8c_\x8i_\x8s·····1.3.1
612 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33612 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
613 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2613 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
614 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
615 [[packages]] 
616 name·=·"sudo" 
617 version·=·"*" 
618 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8614 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
619 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low615 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
620 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low616 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
621 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false617 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
622 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable618 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
623 #·Remediation·is·applicable·only·in·certain·platforms619 #·Remediation·is·applicable·only·in·certain·platforms
624 if·rpm·--quiet·-q·kernel-default;·then620 if·rpm·--quiet·-q·kernel-default;·then
Offset 661, 14 lines modifiedOffset 656, 19 lines modified
661 ··-·PCI-DSSv4-2.2.6656 ··-·PCI-DSSv4-2.2.6
662 ··-·enable_strategy657 ··-·enable_strategy
663 ··-·low_complexity658 ··-·low_complexity
664 ··-·low_disruption659 ··-·low_disruption
665 ··-·medium_severity660 ··-·medium_severity
666 ··-·no_reboot_needed661 ··-·no_reboot_needed
667 ··-·package_sudo_installed662 ··-·package_sudo_installed
 663 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 664 [[packages]]
 665 name·=·"sudo"
 666 version·=·"*"
668 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8667 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
669 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low668 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
670 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low669 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
671 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false670 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
672 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable671 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
673 include·install_sudo672 include·install_sudo
  
Offset 1463, 19 lines modifiedOffset 1463, 14 lines modified
1463 ·············automatic,·regular·execution.1463 ·············automatic,·regular·execution.
1464 Severity: ···medium1464 Severity: ···medium
1465 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1465 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1466 Identifiers:·CCE-91476-21466 Identifiers:·CCE-91476-2
1467 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.21467 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
1468 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-000801468 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
1469 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R611469 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
1470 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1471 [[packages]] 
1472 name·=·"dnf-automatic" 
1473 version·=·"*" 
1474 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81470 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1475 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1471 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1476 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1472 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1477 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1473 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1478 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1474 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1479 #·Remediation·is·applicable·only·in·certain·platforms1475 #·Remediation·is·applicable·only·in·certain·platforms
1480 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&·{·!1476 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&·{·!
Offset 1514, 14 lines modifiedOffset 1509, 19 lines modified
1514 ··-·CCE-91476-21509 ··-·CCE-91476-2
1515 ··-·enable_strategy1510 ··-·enable_strategy
1516 ··-·low_complexity1511 ··-·low_complexity
1517 ··-·low_disruption1512 ··-·low_disruption
1518 ··-·medium_severity1513 ··-·medium_severity
1519 ··-·no_reboot_needed1514 ··-·no_reboot_needed
1520 ··-·package_dnf-automatic_installed1515 ··-·package_dnf-automatic_installed
 1516 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1517 [[packages]]
 1518 name·=·"dnf-automatic"
 1519 version·=·"*"
1521 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81520 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1522 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1521 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1523 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1522 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1524 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1523 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1525 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1524 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1526 include·install_dnf-automatic1525 include·install_dnf-automatic
  
Offset 9390, 19 lines modifiedOffset 9390, 14 lines modified
9390 ············Control·system·will·be·available.9390 ············Control·system·will·be·available.
9391 Severity: ··medium9391 Severity: ··medium
9392 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed9392 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed
9393 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022359393 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
9394 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-9394 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-
9395 ···················000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001559395 ···················000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
9396 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R459396 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
Max diff block lines reached; 25241/30405 bytes (83.02%) of diff not shown.
583 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-anssi_bp28_high.html
    
Offset 15138, 146 lines modifiedOffset 15138, 146 lines modified
0003b210:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b210:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b220:·6964·6d35·3339·3722·2074·6162·696e·6465··idm5397"·tabinde0003b220:·6964·6d35·3339·3722·2074·6162·696e·6465··idm5397"·tabinde
0003b230:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b230:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b240:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b240:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b250:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b250:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b260:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b260:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b270:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b270:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b280:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003b280:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0003b290:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003b2a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b2b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b2c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b2d0:·7073·6522·2069·643d·2269·646d·3533·3937··pse"·id="idm53970003b290:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003b2a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b2b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b2c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5
 0003b2d0:·3339·3722·3e3c·7461·626c·6520·636c·6173··397"><table·clas
 0003b2e0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b2f0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b300:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b310:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b320:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b330:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b340:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b350:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b360:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b370:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b380:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b390:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b3a0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b3b0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b2e0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[0003b3c0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
0003b2f0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003b300:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003b310:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></0003b3d0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003b3e0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003b3f0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003b400:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 0003b410:·7420·2d71·206b·6572·6e65·6c2d·6465·6661··t·-q·kernel-defa
 0003b420:·756c·743b·2074·6865·6e0a·0a7a·7970·7065··ult;·then..zyppe
 0003b430:·7220·696e·7374·616c·6c20·2d79·2022·6169··r·install·-y·"ai
 0003b440:·6465·220a·0a65·6c73·650a·2020·2020·2667··de"..else.····&g
 0003b450:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 0003b460:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 0003b470:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 0003b480:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 0003b490:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
0003b320:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003b4a0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003b330:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003b4b0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003b340:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003b4c0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003b350:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003b4d0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003b360:·2d74·6172·6765·743d·2223·6964·6d35·3339··-target="#idm5390003b4e0:·6765·743d·2223·6964·6d35·3339·3822·2074··get="#idm5398"·t
0003b370:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·0003b4f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b380:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b500:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b390:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b510:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b3a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b520:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b3b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b530:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b3c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b540:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b3d0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip0003b550:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
 0003b560:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b570:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b580:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b590:·2069·643d·2269·646d·3533·3938·223e·3c74···id="idm5398"><t
 0003b5a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b5b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b5c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b5d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b5e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b5f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b600:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b610:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003b620:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b630:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b640:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003b650:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b660:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003b670:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003b680:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b690:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4761··<code>-·name:·Ga
 0003b6a0:·7468·6572·2074·6865·2070·6163·6b61·6765··ther·the·package
 0003b6b0:·2066·6163·7473·0a20·2070·6163·6b61·6765···facts.··package
 0003b6c0:·5f66·6163·7473·3a0a·2020·2020·6d61·6e61··_facts:.····mana
 0003b6d0:·6765·723a·2061·7574·6f0a·2020·7461·6773··ger:·auto.··tags
 0003b6e0:·3a0a·2020·2d20·4343·452d·3833·3036·372d··:.··-·CCE-83067-
 0003b6f0:·390a·2020·2d20·434a·4953·2d35·2e31·302e··9.··-·CJIS-5.10.
 0003b700:·312e·330a·2020·2d20·4449·5341·2d53·5449··1.3.··-·DISA-STI
 0003b710:·472d·534c·4553·2d31·322d·3031·3034·3939··G-SLES-12-010499
 0003b720:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b730:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI
 0003b740:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.··
 0003b750:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5
 0003b760:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st
 0003b770:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c
 0003b780:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo
 0003b790:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-
 0003b7a0:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity
 0003b7b0:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n
 0003b7c0:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag
 0003b7d0:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed
 0003b7e0:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure
 0003b7f0:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install
 0003b800:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.··
 0003b810:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.···
 0003b820:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.
 0003b830:·2020·7768·656e·3a20·2722·6b65·726e·656c····when:·'"kernel
 0003b840:·2d64·6566·6175·6c74·2220·696e·2061·6e73··-default"·in·ans
 0003b850:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
 0003b860:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-
 0003b870:·2043·4345·2d38·3330·3637·2d39·0a20·202d···CCE-83067-9.··-
 0003b880:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.·
 0003b890:·202d·2044·4953·412d·5354·4947·2d53·4c45···-·DISA-STIG-SLE
 0003b8a0:·532d·3132·2d30·3130·3439·390a·2020·2d20··S-12-010499.··-·
 0003b8b0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6
 0003b8c0:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS-
 0003b8d0:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI
 0003b8e0:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.··
 0003b8f0:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg
 0003b900:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple
 0003b910:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis
 0003b920:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi
 0003b930:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-·
 0003b940:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed
 0003b950:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid
 0003b960:·655f·696e·7374·616c·6c65·640a·3c2f·636f··e_installed.</co
 0003b970:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003b980:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b990:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
Max diff block lines reached; 546962/565758 bytes (96.68%) of diff not shown.
29.9 KB
html2text {}
    
Offset 123, 19 lines modifiedOffset 123, 14 lines modified
123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499125 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
126 ·············_\x8c_\x8i_\x8s············1.4.1126 ·············_\x8c_\x8i_\x8s············1.4.1
127 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79127 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule129 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
131 [[packages]] 
132 name·=·"aide" 
133 version·=·"*" 
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
139 #·Remediation·is·applicable·only·in·certain·platforms135 #·Remediation·is·applicable·only·in·certain·platforms
140 if·rpm·--quiet·-q·kernel-default;·then136 if·rpm·--quiet·-q·kernel-default;·then
Offset 181, 14 lines modifiedOffset 176, 19 lines modified
181 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
182 ··-·enable_strategy177 ··-·enable_strategy
183 ··-·low_complexity178 ··-·low_complexity
184 ··-·low_disruption179 ··-·low_disruption
185 ··-·medium_severity180 ··-·medium_severity
186 ··-·no_reboot_needed181 ··-·no_reboot_needed
187 ··-·package_aide_installed182 ··-·package_aide_installed
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 184 [[packages]]
 185 name·=·"aide"
 186 version·=·"*"
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
193 include·install_aide192 include·install_aide
  
Offset 1382, 19 lines modifiedOffset 1382, 14 lines modified
1382 ·············_\x8i_\x8s_\x8m·····1382,·1384,·13861382 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1383 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1383 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1384 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11384 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1385 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251385 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1386 ·············_\x8c_\x8i_\x8s·····1.3.11386 ·············_\x8c_\x8i_\x8s·····1.3.1
1387 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R331387 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1388 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21388 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1390 [[packages]] 
1391 name·=·"sudo" 
1392 version·=·"*" 
1393 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81389 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1394 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1390 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1395 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1391 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1396 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1392 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1397 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1393 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1398 #·Remediation·is·applicable·only·in·certain·platforms1394 #·Remediation·is·applicable·only·in·certain·platforms
1399 if·rpm·--quiet·-q·kernel-default;·then1395 if·rpm·--quiet·-q·kernel-default;·then
Offset 1436, 14 lines modifiedOffset 1431, 19 lines modified
1436 ··-·PCI-DSSv4-2.2.61431 ··-·PCI-DSSv4-2.2.6
1437 ··-·enable_strategy1432 ··-·enable_strategy
1438 ··-·low_complexity1433 ··-·low_complexity
1439 ··-·low_disruption1434 ··-·low_disruption
1440 ··-·medium_severity1435 ··-·medium_severity
1441 ··-·no_reboot_needed1436 ··-·no_reboot_needed
1442 ··-·package_sudo_installed1437 ··-·package_sudo_installed
 1438 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1439 [[packages]]
 1440 name·=·"sudo"
 1441 version·=·"*"
1443 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81442 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1444 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1443 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1445 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1444 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1446 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1445 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1447 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1446 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1448 include·install_sudo1447 include·install_sudo
  
Offset 2238, 19 lines modifiedOffset 2238, 14 lines modified
2238 ·············automatic,·regular·execution.2238 ·············automatic,·regular·execution.
2239 Severity: ···medium2239 Severity: ···medium
2240 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed2240 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
2241 Identifiers:·CCE-91476-22241 Identifiers:·CCE-91476-2
2242 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.22242 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
2243 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-000802243 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
2244 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R612244 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
2245 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2246 [[packages]] 
2247 name·=·"dnf-automatic" 
2248 version·=·"*" 
2249 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82245 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2250 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2246 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2251 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2247 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2252 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2248 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2253 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2249 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2254 #·Remediation·is·applicable·only·in·certain·platforms2250 #·Remediation·is·applicable·only·in·certain·platforms
2255 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&·{·!2251 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&·{·!
Offset 2289, 14 lines modifiedOffset 2284, 19 lines modified
2289 ··-·CCE-91476-22284 ··-·CCE-91476-2
2290 ··-·enable_strategy2285 ··-·enable_strategy
2291 ··-·low_complexity2286 ··-·low_complexity
2292 ··-·low_disruption2287 ··-·low_disruption
2293 ··-·medium_severity2288 ··-·medium_severity
2294 ··-·no_reboot_needed2289 ··-·no_reboot_needed
2295 ··-·package_dnf-automatic_installed2290 ··-·package_dnf-automatic_installed
 2291 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2292 [[packages]]
 2293 name·=·"dnf-automatic"
 2294 version·=·"*"
2296 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82295 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2297 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2296 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2298 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2297 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2299 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2298 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2300 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2299 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2301 include·install_dnf-automatic2300 include·install_dnf-automatic
  
Offset 10165, 19 lines modifiedOffset 10165, 14 lines modified
10165 ············Control·system·will·be·available.10165 ············Control·system·will·be·available.
10166 Severity: ··medium10166 Severity: ··medium
10167 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed10167 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed
10168 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-00223510168 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
10169 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-10169 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-
10170 ···················000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-0015510170 ···················000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
10171 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R4510171 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
Max diff block lines reached; 25458/30628 bytes (83.12%) of diff not shown.
422 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-anssi_bp28_intermediary.html
    
Offset 15124, 146 lines modifiedOffset 15124, 146 lines modified
0003b130:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b130:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b140:·6d35·3339·3722·2074·6162·696e·6465·783d··m5397"·tabindex=0003b140:·6d35·3339·3722·2074·6162·696e·6465·783d··m5397"·tabindex=
0003b150:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b150:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b160:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b160:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b170:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b170:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b180:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b180:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b190:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b190:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b1a0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild0003b1a0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
0003b1b0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003b1c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b1d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b1e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b1f0:·6522·2069·643d·2269·646d·3533·3937·223e··e"·id="idm5397">0003b1b0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003b1c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b1d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b1e0:·6170·7365·2220·6964·3d22·6964·6d35·3339··apse"·id="idm539
 0003b1f0:·3722·3e3c·7461·626c·6520·636c·6173·733d··7"><table·class=
 0003b200:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b210:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003b220:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003b230:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003b240:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003b250:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b260:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b270:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b280:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003b290:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003b2a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003b2b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b2c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003b2d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003b200:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa0003b2e0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
0003b210:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003b220:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=0003b2f0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003b300:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003b310:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003b320:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet·
 0003b330:·2d71·206b·6572·6e65·6c2d·6465·6661·756c··-q·kernel-defaul
 0003b340:·743b·2074·6865·6e0a·0a7a·7970·7065·7220··t;·then..zypper·
 0003b350:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003b360:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt;
 0003b370:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003b380:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003b390:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003b3a0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
0003b230:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr0003b3b0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003b240:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003b3c0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003b250:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003b3d0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003b260:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003b3e0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003b270:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003b3f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b280:·6172·6765·743d·2223·6964·6d35·3339·3822··arget="#idm5398"0003b400:·743d·2223·6964·6d35·3339·3822·2074·6162··t="#idm5398"·tab
0003b290:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b410:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b2a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b420:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b2b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b430:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b2c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b440:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b2d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b450:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b2e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b460:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003b2f0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·0003b470:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
 0003b480:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b490:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b4a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b4b0:·643d·2269·646d·3533·3938·223e·3c74·6162··d="idm5398"><tab
 0003b4c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003b4d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003b4e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003b4f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003b500:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003b510:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b520:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003b530:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003b540:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b550:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003b560:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003b570:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003b580:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003b590:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003b5a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b5b0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath
 0003b5c0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f
 0003b5d0:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f
 0003b5e0:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage
 0003b5f0:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:.
 0003b600:·2020·2d20·4343·452d·3833·3036·372d·390a····-·CCE-83067-9.
 0003b610:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1.
 0003b620:·330a·2020·2d20·4449·5341·2d53·5449·472d··3.··-·DISA-STIG-
 0003b630:·534c·4553·2d31·322d·3031·3034·3939·0a20··SLES-12-010499.·
 0003b640:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
 0003b650:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D
 0003b660:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·
 0003b670:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2
 0003b680:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra
 0003b690:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com
 0003b6a0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_
 0003b6b0:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m
 0003b6c0:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.·
 0003b6d0:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee
 0003b6e0:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_
 0003b6f0:·6169·6465·5f69·6e73·7461·6c6c·6564·0a0a··aide_installed..
 0003b700:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a
 0003b710:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed
 0003b720:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.····
 0003b730:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s
 0003b740:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
 0003b750:·7768·656e·3a20·2722·6b65·726e·656c·2d64··when:·'"kernel-d
 0003b760:·6566·6175·6c74·2220·696e·2061·6e73·6962··efault"·in·ansib
 0003b770:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package
 0003b780:·7327·0a20·2074·6167·733a·0a20·202d·2043··s'.··tags:.··-·C
 0003b790:·4345·2d38·3330·3637·2d39·0a20·202d·2043··CE-83067-9.··-·C
 0003b7a0:·4a49·532d·352e·3130·2e31·2e33·0a20·202d··JIS-5.10.1.3.··-
 0003b7b0:·2044·4953·412d·5354·4947·2d53·4c45·532d···DISA-STIG-SLES-
 0003b7c0:·3132·2d30·3130·3439·390a·2020·2d20·4e49··12-010499.··-·NI
 0003b7d0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a
 0003b7e0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re
 0003b7f0:·712d·3131·2e35·0a20·202d·2050·4349·2d44··q-11.5.··-·PCI-D
 0003b800:·5353·7634·2d31·312e·352e·320a·2020·2d20··SSv4-11.5.2.··-·
 0003b810:·656e·6162·6c65·5f73·7472·6174·6567·790a··enable_strategy.
 0003b820:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi
 0003b830:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru
 0003b840:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium
 0003b850:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no
 0003b860:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·
 0003b870:·202d·2070·6163·6b61·6765·5f61·6964·655f···-·package_aide_
 0003b880:·696e·7374·616c·6c65·640a·3c2f·636f·6465··installed.</code
 0003b890:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b8a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b8b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b8c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
Max diff block lines reached; 393722/412518 bytes (95.44%) of diff not shown.
18.9 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 14 lines modified
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
125 ·············_\x8c_\x8i_\x8s············1.4.1125 ·············_\x8c_\x8i_\x8s············1.4.1
126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms134 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel-default;·then135 if·rpm·--quiet·-q·kernel-default;·then
Offset 180, 14 lines modifiedOffset 175, 19 lines modified
180 ··-·PCI-DSSv4-11.5.2175 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy176 ··-·enable_strategy
182 ··-·low_complexity177 ··-·low_complexity
183 ··-·low_disruption178 ··-·low_disruption
184 ··-·medium_severity179 ··-·medium_severity
185 ··-·no_reboot_needed180 ··-·no_reboot_needed
186 ··-·package_aide_installed181 ··-·package_aide_installed
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide191 include·install_aide
  
Offset 588, 19 lines modifiedOffset 588, 14 lines modified
588 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386588 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
589 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)589 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
590 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1590 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
591 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125591 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
592 ·············_\x8c_\x8i_\x8s·····1.3.1592 ·············_\x8c_\x8i_\x8s·····1.3.1
593 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33593 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
594 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2594 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
595 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
596 [[packages]] 
597 name·=·"sudo" 
598 version·=·"*" 
599 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8595 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
600 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low596 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
601 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low597 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
602 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false598 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
603 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable599 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
604 #·Remediation·is·applicable·only·in·certain·platforms600 #·Remediation·is·applicable·only·in·certain·platforms
605 if·rpm·--quiet·-q·kernel-default;·then601 if·rpm·--quiet·-q·kernel-default;·then
Offset 642, 14 lines modifiedOffset 637, 19 lines modified
642 ··-·PCI-DSSv4-2.2.6637 ··-·PCI-DSSv4-2.2.6
643 ··-·enable_strategy638 ··-·enable_strategy
644 ··-·low_complexity639 ··-·low_complexity
645 ··-·low_disruption640 ··-·low_disruption
646 ··-·medium_severity641 ··-·medium_severity
647 ··-·no_reboot_needed642 ··-·no_reboot_needed
648 ··-·package_sudo_installed643 ··-·package_sudo_installed
 644 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 645 [[packages]]
 646 name·=·"sudo"
 647 version·=·"*"
649 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8648 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
650 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low649 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
651 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low650 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
652 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false651 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
653 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable652 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
654 include·install_sudo653 include·install_sudo
  
Offset 1374, 19 lines modifiedOffset 1374, 14 lines modified
1374 ·············automatic,·regular·execution.1374 ·············automatic,·regular·execution.
1375 Severity: ···medium1375 Severity: ···medium
1376 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1376 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1377 Identifiers:·CCE-91476-21377 Identifiers:·CCE-91476-2
1378 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.21378 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
1379 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-000801379 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
1380 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R611380 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
1381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1382 [[packages]] 
1383 name·=·"dnf-automatic" 
1384 version·=·"*" 
1385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1386 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1382 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1387 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1383 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1388 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1384 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1389 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1385 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1390 #·Remediation·is·applicable·only·in·certain·platforms1386 #·Remediation·is·applicable·only·in·certain·platforms
1391 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&1387 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 1425, 14 lines modifiedOffset 1420, 19 lines modified
1425 ··-·CCE-91476-21420 ··-·CCE-91476-2
1426 ··-·enable_strategy1421 ··-·enable_strategy
1427 ··-·low_complexity1422 ··-·low_complexity
1428 ··-·low_disruption1423 ··-·low_disruption
1429 ··-·medium_severity1424 ··-·medium_severity
1430 ··-·no_reboot_needed1425 ··-·no_reboot_needed
1431 ··-·package_dnf-automatic_installed1426 ··-·package_dnf-automatic_installed
 1427 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1428 [[packages]]
 1429 name·=·"dnf-automatic"
 1430 version·=·"*"
1432 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81431 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1433 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1432 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1434 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1433 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1435 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1434 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1436 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1435 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1437 include·install_dnf-automatic1436 include·install_dnf-automatic
  
Offset 9072, 17 lines modifiedOffset 9072, 14 lines modified
9072 Warning: ·Enabling·L1TF·mitigations·may·impact·performance·of·the·system.9072 Warning: ·Enabling·L1TF·mitigations·may·impact·performance·of·the·system.
9073 ············The·L1TF·vulnerability·allows·an·attacker·to·bypass·memory·access·security·controls9073 ············The·L1TF·vulnerability·allows·an·attacker·to·bypass·memory·access·security·controls
9074 Rationale:··imposed·by·the·system·or·hypervisor.·The·L1TF·vulnerability·allows·read·access·to·any9074 Rationale:··imposed·by·the·system·or·hypervisor.·The·L1TF·vulnerability·allows·read·access·to·any
9075 ············physical·memory·location·that·is·cached·in·the·L1·Data·Cache.9075 ············physical·memory·location·that·is·cached·in·the·L1·Data·Cache.
9076 Severity: ··high9076 Severity: ··high
9077 Rule·ID:····xccdf_org.ssgproject.content_rule_grub2_l1tf_argument9077 Rule·ID:····xccdf_org.ssgproject.content_rule_grub2_l1tf_argument
9078 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R89078 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R8
Max diff block lines reached; 14203/19371 bytes (73.32%) of diff not shown.
21.2 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-anssi_bp28_minimal.html
    
Offset 14800, 152 lines modifiedOffset 14800, 152 lines modified
00039cf0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00039cf0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00039d00:·3831·3136·2220·7461·6269·6e64·6578·3d22··8116"·tabindex="00039d00:·3831·3136·2220·7461·6269·6e64·6578·3d22··8116"·tabindex="
00039d10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00039d10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00039d20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00039d20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00039d30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00039d30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00039d40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00039d40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00039d50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00039d50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00039d60:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·00039d60:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
00039d70:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
00039d80:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00039d90:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00039da0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00039db0:·2220·6964·3d22·6964·6d38·3131·3622·3e3c··"·id="idm8116"><00039d70:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 00039d80:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00039d90:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00039da0:·7073·6522·2069·643d·2269·646d·3831·3136··pse"·id="idm8116
 00039db0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00039dc0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 00039dd0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00039de0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00039df0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00039e00:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00039e10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00039e20:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00039e30:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00039e40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00039e50:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00039e60:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00039e70:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00039e80:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00039e90:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
00039dc0:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac00039ea0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
00039dd0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"00039eb0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 00039ec0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 00039ed0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00039ee0:·6966·2021·2028·207b·2072·706d·202d·2d71··if·!·(·{·rpm·--q
 00039ef0:·7569·6574·202d·7120·6b65·726e·656c·203b··uiet·-q·kernel·;
 00039f00:·7d20·2661·6d70·3b26·616d·703b·207b·2072··}·&amp;&amp;·{·r
 00039f10:·706d·202d·2d71·7569·6574·202d·7120·7270··pm·--quiet·-q·rp
 00039f20:·6d2d·6f73·7472·6565·203b·7d20·2661·6d70··m-ostree·;}·&amp
 00039f30:·3b26·616d·703b·207b·2072·706d·202d·2d71··;&amp;·{·rpm·--q
 00039f40:·7569·6574·202d·7120·626f·6f74·6320·3b7d··uiet·-q·bootc·;}
 00039f50:·2026·616d·703b·2661·6d70·3b20·7b20·2120···&amp;&amp;·{·!·
 00039f60:·7270·6d20·2d2d·7175·6965·7420·2d71·206f··rpm·--quiet·-q·o
 00039f70:·7065·6e73·6869·6674·2d6b·7562·656c·6574··penshift-kubelet
 00039f80:·203b·7d20·293b·2074·6865·6e0a·0a7a·7970···;}·);·then..zyp
 00039f90:·7065·7220·696e·7374·616c·6c20·2d79·2022··per·install·-y·"
00039de0:·646e·662d·6175·746f·6d61·7469·6322·0a76··dnf-automatic".v00039fa0:·646e·662d·6175·746f·6d61·7469·6322·0a0a··dnf-automatic"..
00039df0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
00039e00:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00039e10:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00039e20:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00039e30:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00039e40:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00039e50:·6964·6d38·3131·3722·2074·6162·696e·6465··idm8117"·tabinde 
00039e60:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00039e70:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00039e80:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00039e90:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
00039ea0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
00039eb0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
00039ec0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><00039fb0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 00039fc0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 00039fd0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 00039fe0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 00039ff0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 0003a000:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003a010:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003a020:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003a030:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003a040:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003a050:·2369·646d·3831·3137·2220·7461·6269·6e64··#idm8117"·tabind
 0003a060:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003a070:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003a080:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003a090:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003a0a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003a0b0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
 0003a0c0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
00039ed0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003a0d0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00039ee0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003a0e0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00039ef0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003a0f0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00039f00:·3131·3722·3e3c·7461·626c·6520·636c·6173··117"><table·clas0003a100:·6964·6d38·3131·3722·3e3c·7461·626c·6520··idm8117"><table·
00039f10:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003a110:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
00039f20:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003a120:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
00039f30:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003a130:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
00039f40:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003a140:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
00039f50:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003a150:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00039f60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003a160:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00039f70:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003a170:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
00039f80:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003a180:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00039f90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003a190:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00039fa0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003a1a0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003a1b0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003a1c0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003a1d0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
00039fb0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003a1e0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
00039fc0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00039fd0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
00039fe0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00039ff0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R0003a1f0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003a200:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather·
 0003a210:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact
 0003a220:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact
 0003a230:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:·
 0003a240:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··-
 0003a250:·2043·4345·2d39·3134·3736·2d32·0a20·202d···CCE-91476-2.··-
 0003a260:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy
 0003a270:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex
0003a000:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003a010:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003a020:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003a030:·6d73·0a69·6620·2120·2820·7b20·7270·6d20··ms.if·!·(·{·rpm· 
0003a040:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003a050:·6c20·3b7d·2026·616d·703b·2661·6d70·3b20··l·;}·&amp;&amp;· 
0003a060:·7b20·7270·6d20·2d2d·7175·6965·7420·2d71··{·rpm·--quiet·-q 
0003a070:·2072·706d·2d6f·7374·7265·6520·3b7d·2026···rpm-ostree·;}·& 
0003a080:·616d·703b·2661·6d70·3b20·7b20·7270·6d20··amp;&amp;·{·rpm· 
0003a090:·2d2d·7175·6965·7420·2d71·2062·6f6f·7463··--quiet·-q·bootc 
0003a0a0:·203b·7d20·2661·6d70·3b26·616d·703b·207b···;}·&amp;&amp;·{ 
0003a0b0:·2021·2072·706d·202d·2d71·7569·6574·202d···!·rpm·--quiet·- 
0003a0c0:·7120·6f70·656e·7368·6966·742d·6b75·6265··q·openshift-kube 
0003a0d0:·6c65·7420·3b7d·2029·3b20·7468·656e·0a0a··let·;}·);·then.. 
0003a0e0:·7a79·7070·6572·2069·6e73·7461·6c6c·202d··zypper·install·- 
0003a0f0:·7920·2264·6e66·2d61·7574·6f6d·6174·6963··y·"dnf-automatic 
0003a100:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt; 
0003a110:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
Max diff block lines reached; 414/20038 bytes (2.07%) of diff not shown.
1.51 KB
html2text {}
    
Offset 88, 19 lines modifiedOffset 88, 14 lines modified
88 ·············suitable·for·automatic,·regular·execution.88 ·············suitable·for·automatic,·regular·execution.
89 Severity: ···medium89 Severity: ···medium
90 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed90 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
91 Identifiers:·CCE-91476-291 Identifiers:·CCE-91476-2
92 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.292 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
93 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008093 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
94 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R6194 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
95 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
96 [[packages]] 
97 name·=·"dnf-automatic" 
98 version·=·"*" 
99 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x895 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
100 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low96 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
101 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low97 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
102 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false98 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
103 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable99 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
104 #·Remediation·is·applicable·only·in·certain·platforms100 #·Remediation·is·applicable·only·in·certain·platforms
105 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-101 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 141, 14 lines modifiedOffset 136, 19 lines modified
141 ··-·CCE-91476-2136 ··-·CCE-91476-2
142 ··-·enable_strategy137 ··-·enable_strategy
143 ··-·low_complexity138 ··-·low_complexity
144 ··-·low_disruption139 ··-·low_disruption
145 ··-·medium_severity140 ··-·medium_severity
146 ··-·no_reboot_needed141 ··-·no_reboot_needed
147 ··-·package_dnf-automatic_installed142 ··-·package_dnf-automatic_installed
 143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 144 [[packages]]
 145 name·=·"dnf-automatic"
 146 version·=·"*"
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
153 include·install_dnf-automatic152 include·install_dnf-automatic
  
1.02 MB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis.html
    
Offset 15170, 146 lines modifiedOffset 15170, 146 lines modified
0003b410:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b410:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b420:·646d·3533·3937·2220·7461·6269·6e64·6578··dm5397"·tabindex0003b420:·646d·3533·3937·2220·7461·6269·6e64·6578··dm5397"·tabindex
0003b430:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b430:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b440:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b440:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b450:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b450:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b460:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b460:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b470:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b470:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b480:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b480:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003b490:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b4a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b4b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b4c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b4d0:·7365·2220·6964·3d22·6964·6d35·3339·3722··se"·id="idm5397"0003b490:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003b4a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b4b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b4c0:·6c61·7073·6522·2069·643d·2269·646d·3533··lapse"·id="idm53
 0003b4d0:·3937·223e·3c74·6162·6c65·2063·6c61·7373··97"><table·class
 0003b4e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b4f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b500:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b510:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b520:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b530:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b540:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b550:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b560:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b570:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b580:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b590:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b5a0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b5b0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b4e0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p0003b5c0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
0003b4f0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b500:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b510:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p0003b5d0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003b5e0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003b5f0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003b600:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet
 0003b610:·202d·7120·6b65·726e·656c·2d64·6566·6175···-q·kernel-defau
 0003b620:·6c74·3b20·7468·656e·0a0a·7a79·7070·6572··lt;·then..zypper
 0003b630:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003b640:·6522·0a0a·656c·7365·0a20·2020·2026·6774··e"..else.····&gt
 0003b650:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003b660:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003b670:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003b680:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
 0003b690:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
0003b520:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003b6a0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003b530:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003b6b0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003b540:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003b6c0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003b550:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003b6d0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003b560:·7461·7267·6574·3d22·2369·646d·3533·3938··target="#idm53980003b6e0:·6574·3d22·2369·646d·3533·3938·2220·7461··et="#idm5398"·ta
0003b570:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b6f0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b580:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b700:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b590:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b710:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b5a0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b720:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b5b0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b730:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b5c0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b740:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b5d0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script0003b750:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
 0003b760:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b770:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b780:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b790:·6964·3d22·6964·6d35·3339·3822·3e3c·7461··id="idm5398"><ta
 0003b7a0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003b7b0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003b7c0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003b7d0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003b7e0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003b7f0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003b800:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b810:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b820:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b830:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003b840:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003b850:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b860:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003b870:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003b880:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b890:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat
 0003b8a0:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package·
 0003b8b0:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_
 0003b8c0:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag
 0003b8d0:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags:
 0003b8e0:·0a20·202d·2043·4345·2d38·3330·3637·2d39··.··-·CCE-83067-9
 0003b8f0:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1
 0003b900:·2e33·0a20·202d·2044·4953·412d·5354·4947··.3.··-·DISA-STIG
 0003b910:·2d53·4c45·532d·3132·2d30·3130·3439·390a··-SLES-12-010499.
 0003b920:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
 0003b930:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI-
 0003b940:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-
 0003b950:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.
 0003b960:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str
 0003b970:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co
 0003b980:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low
 0003b990:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
 0003b9a0:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.
 0003b9b0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
 0003b9c0:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package
 0003b9d0:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed.
 0003b9e0:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure·
 0003b9f0:·6169·6465·2069·7320·696e·7374·616c·6c65··aide·is·installe
 0003ba00:·640a·2020·7061·636b·6167·653a·0a20·2020··d.··package:.···
 0003ba10:·206e·616d·653a·2061·6964·650a·2020·2020···name:·aide.····
 0003ba20:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
 0003ba30:·2077·6865·6e3a·2027·226b·6572·6e65·6c2d···when:·'"kernel-
 0003ba40:·6465·6661·756c·7422·2069·6e20·616e·7369··default"·in·ansi
 0003ba50:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
 0003ba60:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·
 0003ba70:·4343·452d·3833·3036·372d·390a·2020·2d20··CCE-83067-9.··-·
 0003ba80:·434a·4953·2d35·2e31·302e·312e·330a·2020··CJIS-5.10.1.3.··
 0003ba90:·2d20·4449·5341·2d53·5449·472d·534c·4553··-·DISA-STIG-SLES
 0003baa0:·2d31·322d·3031·3034·3939·0a20·202d·204e··-12-010499.··-·N
 0003bab0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
 0003bac0:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R
 0003bad0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
 0003bae0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
 0003baf0:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy
 0003bb00:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex
 0003bb10:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr
 0003bb20:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu
 0003bb30:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n
 0003bb40:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed.
 0003bb50:·2020·2d20·7061·636b·6167·655f·6169·6465····-·package_aide
 0003bb60:·5f69·6e73·7461·6c6c·6564·0a3c·2f63·6f64··_installed.</cod
 0003bb70:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003bb80:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003bb90:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
Max diff block lines reached; 1005112/1023908 bytes (98.16%) of diff not shown.
48.8 KB
html2text {}
    
Offset 128, 19 lines modifiedOffset 128, 14 lines modified
128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
129 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199129 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
130 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499130 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
131 ·············_\x8c_\x8i_\x8s············1.4.1131 ·············_\x8c_\x8i_\x8s············1.4.1
132 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79132 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
133 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2133 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
134 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule134 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
136 [[packages]] 
137 name·=·"aide" 
138 version·=·"*" 
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
144 #·Remediation·is·applicable·only·in·certain·platforms140 #·Remediation·is·applicable·only·in·certain·platforms
145 if·rpm·--quiet·-q·kernel-default;·then141 if·rpm·--quiet·-q·kernel-default;·then
Offset 186, 14 lines modifiedOffset 181, 19 lines modified
186 ··-·PCI-DSSv4-11.5.2181 ··-·PCI-DSSv4-11.5.2
187 ··-·enable_strategy182 ··-·enable_strategy
188 ··-·low_complexity183 ··-·low_complexity
189 ··-·low_disruption184 ··-·low_disruption
190 ··-·medium_severity185 ··-·medium_severity
191 ··-·no_reboot_needed186 ··-·no_reboot_needed
192 ··-·package_aide_installed187 ··-·package_aide_installed
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 189 [[packages]]
 190 name·=·"aide"
 191 version·=·"*"
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
198 include·install_aide197 include·install_aide
  
Offset 1218, 19 lines modifiedOffset 1218, 14 lines modified
1218 ·············_\x8i_\x8s_\x8m·····1382,·1384,·13861218 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1219 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1219 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1220 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11220 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1221 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251221 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1222 ·············_\x8c_\x8i_\x8s·····1.3.11222 ·············_\x8c_\x8i_\x8s·····1.3.1
1223 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R331223 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1224 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21224 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1226 [[packages]] 
1227 name·=·"sudo" 
1228 version·=·"*" 
1229 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81225 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1230 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1226 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1231 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1227 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1232 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1228 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1233 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1229 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1234 #·Remediation·is·applicable·only·in·certain·platforms1230 #·Remediation·is·applicable·only·in·certain·platforms
1235 if·rpm·--quiet·-q·kernel-default;·then1231 if·rpm·--quiet·-q·kernel-default;·then
Offset 1272, 14 lines modifiedOffset 1267, 19 lines modified
1272 ··-·PCI-DSSv4-2.2.61267 ··-·PCI-DSSv4-2.2.6
1273 ··-·enable_strategy1268 ··-·enable_strategy
1274 ··-·low_complexity1269 ··-·low_complexity
1275 ··-·low_disruption1270 ··-·low_disruption
1276 ··-·medium_severity1271 ··-·medium_severity
1277 ··-·no_reboot_needed1272 ··-·no_reboot_needed
1278 ··-·package_sudo_installed1273 ··-·package_sudo_installed
 1274 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1275 [[packages]]
 1276 name·=·"sudo"
 1277 version·=·"*"
1279 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81278 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1280 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1279 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1281 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1280 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1282 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1281 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1283 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1282 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1284 include·install_sudo1283 include·install_sudo
  
Offset 9798, 19 lines modifiedOffset 9798, 14 lines modified
9798 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9798 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9799 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9799 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9800 ·····················002329800 ·····················00232
9801 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-0106009801 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
9802 ·············_\x8c_\x8i_\x8s·····1.7.1.19802 ·············_\x8c_\x8i_\x8s·····1.7.1.1
9803 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459803 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9804 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule9804 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
9805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9806 [[packages]] 
9807 name·=·"pam_apparmor" 
9808 version·=·"*" 
9809 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89805 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9810 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9806 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9811 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9807 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9812 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9808 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9813 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9809 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9814 #·Remediation·is·applicable·only·in·certain·platforms9810 #·Remediation·is·applicable·only·in·certain·platforms
9815 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9811 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 9842, 14 lines modifiedOffset 9837, 19 lines modified
9842 ··-·NIST-800-53-SC-7(21)9837 ··-·NIST-800-53-SC-7(21)
9843 ··-·enable_strategy9838 ··-·enable_strategy
9844 ··-·low_complexity9839 ··-·low_complexity
9845 ··-·low_disruption9840 ··-·low_disruption
9846 ··-·medium_severity9841 ··-·medium_severity
9847 ··-·no_reboot_needed9842 ··-·no_reboot_needed
9848 ··-·package_pam_apparmor_installed9843 ··-·package_pam_apparmor_installed
 9844 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9845 [[packages]]
 9846 name·=·"pam_apparmor"
 9847 version·=·"*"
9849 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89848 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9850 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9849 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9851 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9850 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9852 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9851 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9853 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9852 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9854 include·install_pam_apparmor9853 include·install_pam_apparmor
  
Offset 10202, 18 lines modifiedOffset 10202, 14 lines modified
10202 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-10202 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
10203 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-10203 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
10204 ·····················0023210204 ·····················00232
10205 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-01060010205 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
10206 ·············_\x8c_\x8i_\x8s·····1.7.1.210206 ·············_\x8c_\x8i_\x8s·····1.7.1.2
10207 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R4510207 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
10208 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule10208 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
Max diff block lines reached; 44760/49981 bytes (89.55%) of diff not shown.
810 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis_server_l1.html
    
Offset 15148, 146 lines modifiedOffset 15148, 146 lines modified
0003b2b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b2b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b2c0:·2223·6964·6d35·3339·3722·2074·6162·696e··"#idm5397"·tabin0003b2c0:·2223·6964·6d35·3339·3722·2074·6162·696e··"#idm5397"·tabin
0003b2d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b2d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b2e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b2e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b2f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b2f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b300:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b300:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b310:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b310:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b320:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003b320:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
0003b330:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003b340:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b350:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b360:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b370:·6c61·7073·6522·2069·643d·2269·646d·3533··lapse"·id="idm530003b330:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003b340:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b350:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b360:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b370:·6d35·3339·3722·3e3c·7461·626c·6520·636c··m5397"><table·cl
 0003b380:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b390:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b3a0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b3b0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b3c0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b3d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b3e0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b3f0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b400:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b410:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b420:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b430:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b440:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003b450:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003b380:·3937·223e·3c70·7265·3e3c·636f·6465·3e0a··97"><pre><code>.0003b460:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
0003b390:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003b3a0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003b3b0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>0003b470:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003b480:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003b490:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003b4a0:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 0003b4b0:·6965·7420·2d71·206b·6572·6e65·6c2d·6465··iet·-q·kernel-de
 0003b4c0:·6661·756c·743b·2074·6865·6e0a·0a7a·7970··fault;·then..zyp
 0003b4d0:·7065·7220·696e·7374·616c·6c20·2d79·2022··per·install·-y·"
 0003b4e0:·6169·6465·220a·0a65·6c73·650a·2020·2020··aide"..else.····
 0003b4f0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003b500:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003b510:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003b520:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 0003b530:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003b3c0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b540:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003b3d0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003b550:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003b3e0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003b560:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003b3f0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003b570:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003b400:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm50003b580:·6172·6765·743d·2223·6964·6d35·3339·3822··arget="#idm5398"
0003b410:·3339·3822·2074·6162·696e·6465·783d·2230··398"·tabindex="00003b590:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b420:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b5a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b430:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b5b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b440:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b5c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b450:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b5d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b460:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b5e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003b470:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr0003b5f0:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 0003b600:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b610:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b620:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b630:·6522·2069·643d·2269·646d·3533·3938·223e··e"·id="idm5398">
 0003b640:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b650:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b660:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b670:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b680:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b690:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b6a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b6b0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b6c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b6d0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b6e0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b6f0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b700:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b710:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b720:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b730:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
 0003b740:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa
 0003b750:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa
 0003b760:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma
 0003b770:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta
 0003b780:·6773·3a0a·2020·2d20·4343·452d·3833·3036··gs:.··-·CCE-8306
 0003b790:·372d·390a·2020·2d20·434a·4953·2d35·2e31··7-9.··-·CJIS-5.1
 0003b7a0:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S
 0003b7b0:·5449·472d·534c·4553·2d31·322d·3031·3034··TIG-SLES-12-0104
 0003b7c0:·3939·0a20·202d·204e·4953·542d·3830·302d··99.··-·NIST-800-
 0003b7d0:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P
 0003b7e0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5.
 0003b7f0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11
 0003b800:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_
 0003b810:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
 0003b820:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
 0003b830:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
 0003b840:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
 0003b850:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
 0003b860:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack
 0003b870:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install
 0003b880:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu
 0003b890:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta
 0003b8a0:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:.
 0003b8b0:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.·
 0003b8c0:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen
 0003b8d0:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern
 0003b8e0:·656c·2d64·6566·6175·6c74·2220·696e·2061··el-default"·in·a
 0003b8f0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
 0003b900:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.·
 0003b910:·202d·2043·4345·2d38·3330·3637·2d39·0a20···-·CCE-83067-9.·
 0003b920:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3
 0003b930:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
 0003b940:·4c45·532d·3132·2d30·3130·3439·390a·2020··LES-12-010499.··
 0003b950:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 0003b960:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
 0003b970:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
 0003b980:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
 0003b990:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
 0003b9a0:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp
 0003b9b0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
 0003b9c0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
 0003b9d0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
 0003b9e0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
 0003b9f0:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a
 0003ba00:·6964·655f·696e·7374·616c·6c65·640a·3c2f··ide_installed.</
 0003ba10:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003ba20:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003ba30:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
Max diff block lines reached; 770746/789542 bytes (97.62%) of diff not shown.
38.9 KB
html2text {}
    
Offset 125, 19 lines modifiedOffset 125, 14 lines modified
125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
127 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499127 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
128 ·············_\x8c_\x8i_\x8s············1.4.1128 ·············_\x8c_\x8i_\x8s············1.4.1
129 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79129 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
131 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule131 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
133 [[packages]] 
134 name·=·"aide" 
135 version·=·"*" 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 #·Remediation·is·applicable·only·in·certain·platforms137 #·Remediation·is·applicable·only·in·certain·platforms
142 if·rpm·--quiet·-q·kernel-default;·then138 if·rpm·--quiet·-q·kernel-default;·then
Offset 183, 14 lines modifiedOffset 178, 19 lines modified
183 ··-·PCI-DSSv4-11.5.2178 ··-·PCI-DSSv4-11.5.2
184 ··-·enable_strategy179 ··-·enable_strategy
185 ··-·low_complexity180 ··-·low_complexity
186 ··-·low_disruption181 ··-·low_disruption
187 ··-·medium_severity182 ··-·medium_severity
188 ··-·no_reboot_needed183 ··-·no_reboot_needed
189 ··-·package_aide_installed184 ··-·package_aide_installed
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 186 [[packages]]
 187 name·=·"aide"
 188 version·=·"*"
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
195 include·install_aide194 include·install_aide
  
Offset 1107, 19 lines modifiedOffset 1107, 14 lines modified
1107 ·············_\x8i_\x8s_\x8m·····1382,·1384,·13861107 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1108 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1108 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1109 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11109 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1110 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251110 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1111 ·············_\x8c_\x8i_\x8s·····1.3.11111 ·············_\x8c_\x8i_\x8s·····1.3.1
1112 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R331112 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1115 [[packages]] 
1116 name·=·"sudo" 
1117 version·=·"*" 
1118 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81114 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1119 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1115 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1120 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1116 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1121 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1117 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1122 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1118 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1123 #·Remediation·is·applicable·only·in·certain·platforms1119 #·Remediation·is·applicable·only·in·certain·platforms
1124 if·rpm·--quiet·-q·kernel-default;·then1120 if·rpm·--quiet·-q·kernel-default;·then
Offset 1161, 14 lines modifiedOffset 1156, 19 lines modified
1161 ··-·PCI-DSSv4-2.2.61156 ··-·PCI-DSSv4-2.2.6
1162 ··-·enable_strategy1157 ··-·enable_strategy
1163 ··-·low_complexity1158 ··-·low_complexity
1164 ··-·low_disruption1159 ··-·low_disruption
1165 ··-·medium_severity1160 ··-·medium_severity
1166 ··-·no_reboot_needed1161 ··-·no_reboot_needed
1167 ··-·package_sudo_installed1162 ··-·package_sudo_installed
 1163 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1164 [[packages]]
 1165 name·=·"sudo"
 1166 version·=·"*"
1168 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81167 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1169 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1168 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1170 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1169 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1171 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1170 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1172 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1171 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1173 include·install_sudo1172 include·install_sudo
  
Offset 9687, 19 lines modifiedOffset 9687, 14 lines modified
9687 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9687 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9688 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9688 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9689 ·····················002329689 ·····················00232
9690 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-0106009690 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
9691 ·············_\x8c_\x8i_\x8s·····1.7.1.19691 ·············_\x8c_\x8i_\x8s·····1.7.1.1
9692 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459692 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9693 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule9693 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
9694 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9695 [[packages]] 
9696 name·=·"pam_apparmor" 
9697 version·=·"*" 
9698 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89694 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9699 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9695 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9700 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9696 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9701 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9697 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9702 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9698 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9703 #·Remediation·is·applicable·only·in·certain·platforms9699 #·Remediation·is·applicable·only·in·certain·platforms
9704 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9700 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 9731, 14 lines modifiedOffset 9726, 19 lines modified
9731 ··-·NIST-800-53-SC-7(21)9726 ··-·NIST-800-53-SC-7(21)
9732 ··-·enable_strategy9727 ··-·enable_strategy
9733 ··-·low_complexity9728 ··-·low_complexity
9734 ··-·low_disruption9729 ··-·low_disruption
9735 ··-·medium_severity9730 ··-·medium_severity
9736 ··-·no_reboot_needed9731 ··-·no_reboot_needed
9737 ··-·package_pam_apparmor_installed9732 ··-·package_pam_apparmor_installed
 9733 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9734 [[packages]]
 9735 name·=·"pam_apparmor"
 9736 version·=·"*"
9738 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89737 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9739 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9738 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9740 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9739 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9741 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9740 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9742 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9741 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9743 include·install_pam_apparmor9742 include·install_pam_apparmor
  
Offset 9959, 18 lines modifiedOffset 9959, 14 lines modified
9959 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9959 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9960 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9960 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9961 ·····················002329961 ·····················00232
9962 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-0106009962 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
9963 ·············_\x8c_\x8i_\x8s·····1.7.1.29963 ·············_\x8c_\x8i_\x8s·····1.7.1.2
9964 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459964 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9965 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule9965 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
Max diff block lines reached; 34594/39813 bytes (86.89%) of diff not shown.
678 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis_workstation_l1.html
    
Offset 15134, 146 lines modifiedOffset 15134, 146 lines modified
0003b1d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b1d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b1e0:·743d·2223·6964·6d35·3339·3722·2074·6162··t="#idm5397"·tab0003b1e0:·743d·2223·6964·6d35·3339·3722·2074·6162··t="#idm5397"·tab
0003b1f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b1f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b200:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b200:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b210:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b210:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b220:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b220:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b230:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b230:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b240:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003b240:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
0003b250:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003b260:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b270:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b280:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b290:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm 
0003b2a0:·3533·3937·223e·3c70·7265·3e3c·636f·6465··5397"><pre><code 
0003b2b0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003b2c0:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003b2d0:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod0003b250:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 0003b260:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b270:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b280:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b290:·6964·6d35·3339·3722·3e3c·7461·626c·6520··idm5397"><table·
 0003b2a0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003b2b0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003b2c0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003b2d0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003b2e0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003b2f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b300:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003b310:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003b320:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b330:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003b340:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003b350:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003b360:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003b370:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
 0003b380:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003b390:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003b3a0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003b3b0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003b3c0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
 0003b3d0:·7175·6965·7420·2d71·206b·6572·6e65·6c2d··quiet·-q·kernel-
 0003b3e0:·6465·6661·756c·743b·2074·6865·6e0a·0a7a··default;·then..z
 0003b3f0:·7970·7065·7220·696e·7374·616c·6c20·2d79··ypper·install·-y
 0003b400:·2022·6169·6465·220a·0a65·6c73·650a·2020···"aide"..else.··
 0003b410:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003b420:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003b430:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003b440:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 0003b450:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
0003b2e0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003b460:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003b2f0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003b470:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003b300:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003b480:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003b310:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003b490:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003b320:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b4a0:·2d74·6172·6765·743d·2223·6964·6d35·3339··-target="#idm539
0003b330:·6d35·3339·3822·2074·6162·696e·6465·783d··m5398"·tabindex=0003b4b0:·3822·2074·6162·696e·6465·783d·2230·2220··8"·tabindex="0"·
0003b340:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b4c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b350:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b4d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b360:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b4e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b370:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b4f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b380:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b500:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b390:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s0003b510:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
 0003b520:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b530:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b540:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b550:·7073·6522·2069·643d·2269·646d·3533·3938··pse"·id="idm5398
 0003b560:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b570:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b580:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b590:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b5a0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b5b0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b5c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b5d0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b5e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b5f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b600:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b610:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b620:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b630:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b640:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b650:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
 0003b660:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac
 0003b670:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac
 0003b680:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.····
 0003b690:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.··
 0003b6a0:·7461·6773·3a0a·2020·2d20·4343·452d·3833··tags:.··-·CCE-83
 0003b6b0:·3036·372d·390a·2020·2d20·434a·4953·2d35··067-9.··-·CJIS-5
 0003b6c0:·2e31·302e·312e·330a·2020·2d20·4449·5341··.10.1.3.··-·DISA
 0003b6d0:·2d53·5449·472d·534c·4553·2d31·322d·3031··-STIG-SLES-12-01
 0003b6e0:·3034·3939·0a20·202d·204e·4953·542d·3830··0499.··-·NIST-80
 0003b6f0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
 0003b700:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11.
 0003b710:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4-
 0003b720:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl
 0003b730:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l
 0003b740:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.··
 0003b750:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption
 0003b760:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve
 0003b770:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo
 0003b780:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa
 0003b790:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta
 0003b7a0:·6c6c·6564·0a0a·2d20·6e61·6d65·3a20·456e··lled..-·name:·En
 0003b7b0:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins
 0003b7c0:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package
 0003b7d0:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide
 0003b7e0:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres
 0003b7f0:·656e·740a·2020·7768·656e·3a20·2722·6b65··ent.··when:·'"ke
 0003b800:·726e·656c·2d64·6566·6175·6c74·2220·696e··rnel-default"·in
 0003b810:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 0003b820:·6163·6b61·6765·7327·0a20·2074·6167·733a··ackages'.··tags:
 0003b830:·0a20·202d·2043·4345·2d38·3330·3637·2d39··.··-·CCE-83067-9
 0003b840:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1
 0003b850:·2e33·0a20·202d·2044·4953·412d·5354·4947··.3.··-·DISA-STIG
 0003b860:·2d53·4c45·532d·3132·2d30·3130·3439·390a··-SLES-12-010499.
 0003b870:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
 0003b880:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI-
 0003b890:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-
 0003b8a0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.
 0003b8b0:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str
 0003b8c0:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co
 0003b8d0:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low
 0003b8e0:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
 0003b8f0:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.
 0003b900:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
 0003b910:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package
 0003b920:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed.
 0003b930:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
Max diff block lines reached; 640800/659596 bytes (97.15%) of diff not shown.
33.9 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 14 lines modified
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
125 ·············_\x8c_\x8i_\x8s············1.4.1125 ·············_\x8c_\x8i_\x8s············1.4.1
126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms134 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel-default;·then135 if·rpm·--quiet·-q·kernel-default;·then
Offset 180, 14 lines modifiedOffset 175, 19 lines modified
180 ··-·PCI-DSSv4-11.5.2175 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy176 ··-·enable_strategy
182 ··-·low_complexity177 ··-·low_complexity
183 ··-·low_disruption178 ··-·low_disruption
184 ··-·medium_severity179 ··-·medium_severity
185 ··-·no_reboot_needed180 ··-·no_reboot_needed
186 ··-·package_aide_installed181 ··-·package_aide_installed
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide191 include·install_aide
  
Offset 1104, 19 lines modifiedOffset 1104, 14 lines modified
1104 ·············_\x8i_\x8s_\x8m·····1382,·1384,·13861104 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1105 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1105 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1106 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11106 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1108 ·············_\x8c_\x8i_\x8s·····1.3.11108 ·············_\x8c_\x8i_\x8s·····1.3.1
1109 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R331109 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21110 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1112 [[packages]] 
1113 name·=·"sudo" 
1114 version·=·"*" 
1115 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81111 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1116 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1112 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1117 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1113 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1118 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1114 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1119 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1115 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1120 #·Remediation·is·applicable·only·in·certain·platforms1116 #·Remediation·is·applicable·only·in·certain·platforms
1121 if·rpm·--quiet·-q·kernel-default;·then1117 if·rpm·--quiet·-q·kernel-default;·then
Offset 1158, 14 lines modifiedOffset 1153, 19 lines modified
1158 ··-·PCI-DSSv4-2.2.61153 ··-·PCI-DSSv4-2.2.6
1159 ··-·enable_strategy1154 ··-·enable_strategy
1160 ··-·low_complexity1155 ··-·low_complexity
1161 ··-·low_disruption1156 ··-·low_disruption
1162 ··-·medium_severity1157 ··-·medium_severity
1163 ··-·no_reboot_needed1158 ··-·no_reboot_needed
1164 ··-·package_sudo_installed1159 ··-·package_sudo_installed
 1160 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1161 [[packages]]
 1162 name·=·"sudo"
 1163 version·=·"*"
1165 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81164 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1166 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1165 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1167 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1166 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1168 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1167 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1169 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1168 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1170 include·install_sudo1169 include·install_sudo
  
Offset 9684, 19 lines modifiedOffset 9684, 14 lines modified
9684 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9684 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9685 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9685 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9686 ·····················002329686 ·····················00232
9687 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-0106009687 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
9688 ·············_\x8c_\x8i_\x8s·····1.7.1.19688 ·············_\x8c_\x8i_\x8s·····1.7.1.1
9689 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459689 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9690 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule9690 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
9691 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9692 [[packages]] 
9693 name·=·"pam_apparmor" 
9694 version·=·"*" 
9695 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89691 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9696 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9692 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9697 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9693 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9698 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9694 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9699 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9695 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9700 #·Remediation·is·applicable·only·in·certain·platforms9696 #·Remediation·is·applicable·only·in·certain·platforms
9701 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9697 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 9728, 14 lines modifiedOffset 9723, 19 lines modified
9728 ··-·NIST-800-53-SC-7(21)9723 ··-·NIST-800-53-SC-7(21)
9729 ··-·enable_strategy9724 ··-·enable_strategy
9730 ··-·low_complexity9725 ··-·low_complexity
9731 ··-·low_disruption9726 ··-·low_disruption
9732 ··-·medium_severity9727 ··-·medium_severity
9733 ··-·no_reboot_needed9728 ··-·no_reboot_needed
9734 ··-·package_pam_apparmor_installed9729 ··-·package_pam_apparmor_installed
 9730 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9731 [[packages]]
 9732 name·=·"pam_apparmor"
 9733 version·=·"*"
9735 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89734 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9736 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9735 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9737 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9736 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9738 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9737 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9739 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9738 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9740 include·install_pam_apparmor9739 include·install_pam_apparmor
  
Offset 9956, 18 lines modifiedOffset 9956, 14 lines modified
9956 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9956 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9957 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9957 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9958 ·····················002329958 ·····················00232
9959 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-0106009959 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
9960 ·············_\x8c_\x8i_\x8s·····1.7.1.29960 ·············_\x8c_\x8i_\x8s·····1.7.1.2
9961 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459961 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9962 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule9962 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
Max diff block lines reached; 29504/34723 bytes (84.97%) of diff not shown.
1010 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-cis_workstation_l2.html
    
Offset 15161, 146 lines modifiedOffset 15161, 146 lines modified
0003b380:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b380:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b390:·2369·646d·3533·3937·2220·7461·6269·6e64··#idm5397"·tabind0003b390:·2369·646d·3533·3937·2220·7461·6269·6e64··#idm5397"·tabind
0003b3a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b3a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b3b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b3b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b3c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b3c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b3d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b3d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b3e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b3e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b3f0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0003b3f0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
0003b400:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003b410:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003b420:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b430:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b440:·6170·7365·2220·6964·3d22·6964·6d35·3339··apse"·id="idm5390003b400:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003b410:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b420:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b430:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b440:·3533·3937·223e·3c74·6162·6c65·2063·6c61··5397"><table·cla
 0003b450:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b460:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b470:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b480:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b490:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b4a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b4b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b4c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b4d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b4e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003b4f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b500:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b510:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003b520:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003b450:·3722·3e3c·7072·653e·3c63·6f64·653e·0a5b··7"><pre><code>.[0003b530:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
0003b460:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0003b470:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio 
0003b480:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><0003b540:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003b550:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003b560:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003b570:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 0003b580:·6574·202d·7120·6b65·726e·656c·2d64·6566··et·-q·kernel-def
 0003b590:·6175·6c74·3b20·7468·656e·0a0a·7a79·7070··ault;·then..zypp
 0003b5a0:·6572·2069·6e73·7461·6c6c·202d·7920·2261··er·install·-y·"a
 0003b5b0:·6964·6522·0a0a·656c·7365·0a20·2020·2026··ide"..else.····&
 0003b5c0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 0003b5d0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 0003b5e0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 0003b5f0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 0003b600:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
0003b490:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003b610:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
0003b4a0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003b620:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
0003b4b0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003b630:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
0003b4c0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003b640:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
0003b4d0:·612d·7461·7267·6574·3d22·2369·646d·3533··a-target="#idm530003b650:·7267·6574·3d22·2369·646d·3533·3938·2220··rget="#idm5398"·
0003b4e0:·3938·2220·7461·6269·6e64·6578·3d22·3022··98"·tabindex="0"0003b660:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b4f0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b670:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b500:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b680:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b510:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b690:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b520:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b6a0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b530:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b6b0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003b540:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri0003b6c0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe
 0003b6d0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b6e0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b6f0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b700:·2220·6964·3d22·6964·6d35·3339·3822·3e3c··"·id="idm5398"><
 0003b710:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b720:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b730:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b740:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b750:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003b760:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003b770:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b780:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003b790:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b7a0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003b7b0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003b7c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b7d0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003b7e0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003b7f0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b800:·3e3c·636f·6465·3e2d·206e·616d·653a·2047··><code>-·name:·G
 0003b810:·6174·6865·7220·7468·6520·7061·636b·6167··ather·the·packag
 0003b820:·6520·6661·6374·730a·2020·7061·636b·6167··e·facts.··packag
 0003b830:·655f·6661·6374·733a·0a20·2020·206d·616e··e_facts:.····man
 0003b840:·6167·6572·3a20·6175·746f·0a20·2074·6167··ager:·auto.··tag
 0003b850:·733a·0a20·202d·2043·4345·2d38·3330·3637··s:.··-·CCE-83067
 0003b860:·2d39·0a20·202d·2043·4a49·532d·352e·3130··-9.··-·CJIS-5.10
 0003b870:·2e31·2e33·0a20·202d·2044·4953·412d·5354··.1.3.··-·DISA-ST
 0003b880:·4947·2d53·4c45·532d·3132·2d30·3130·3439··IG-SLES-12-01049
 0003b890:·390a·2020·2d20·4e49·5354·2d38·3030·2d35··9.··-·NIST-800-5
 0003b8a0:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC
 0003b8b0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
 0003b8c0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
 0003b8d0:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s
 0003b8e0:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_
 0003b8f0:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l
 0003b900:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··
 0003b910:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
 0003b920:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
 0003b930:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa
 0003b940:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe
 0003b950:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur
 0003b960:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal
 0003b970:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.·
 0003b980:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.··
 0003b990:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present
 0003b9a0:·0a20·2077·6865·6e3a·2027·226b·6572·6e65··.··when:·'"kerne
 0003b9b0:·6c2d·6465·6661·756c·7422·2069·6e20·616e··l-default"·in·an
 0003b9c0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
 0003b9d0:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··
 0003b9e0:·2d20·4343·452d·3833·3036·372d·390a·2020··-·CCE-83067-9.··
 0003b9f0:·2d20·434a·4953·2d35·2e31·302e·312e·330a··-·CJIS-5.10.1.3.
 0003ba00:·2020·2d20·4449·5341·2d53·5449·472d·534c····-·DISA-STIG-SL
 0003ba10:·4553·2d31·322d·3031·3034·3939·0a20·202d··ES-12-010499.··-
 0003ba20:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
 0003ba30:·3628·6129·0a20·202d·2050·4349·2d44·5353··6(a).··-·PCI-DSS
 0003ba40:·2d52·6571·2d31·312e·350a·2020·2d20·5043··-Req-11.5.··-·PC
 0003ba50:·492d·4453·5376·342d·3131·2e35·2e32·0a20··I-DSSv4-11.5.2.·
 0003ba60:·202d·2065·6e61·626c·655f·7374·7261·7465···-·enable_strate
 0003ba70:·6779·0a20·202d·206c·6f77·5f63·6f6d·706c··gy.··-·low_compl
 0003ba80:·6578·6974·790a·2020·2d20·6c6f·775f·6469··exity.··-·low_di
 0003ba90:·7372·7570·7469·6f6e·0a20·202d·206d·6564··sruption.··-·med
 0003baa0:·6975·6d5f·7365·7665·7269·7479·0a20·202d··ium_severity.··-
 0003bab0:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede
 0003bac0:·640a·2020·2d20·7061·636b·6167·655f·6169··d.··-·package_ai
 0003bad0:·6465·5f69·6e73·7461·6c6c·6564·0a3c·2f63··de_installed.</c
 0003bae0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003baf0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003bb00:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
Max diff block lines reached; 965062/983858 bytes (98.09%) of diff not shown.
47.2 KB
html2text {}
    
Offset 126, 19 lines modifiedOffset 126, 14 lines modified
126 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5126 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
127 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199127 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499128 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
129 ·············_\x8c_\x8i_\x8s············1.4.1129 ·············_\x8c_\x8i_\x8s············1.4.1
130 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79130 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
132 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule132 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
134 [[packages]] 
135 name·=·"aide" 
136 version·=·"*" 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 #·Remediation·is·applicable·only·in·certain·platforms138 #·Remediation·is·applicable·only·in·certain·platforms
143 if·rpm·--quiet·-q·kernel-default;·then139 if·rpm·--quiet·-q·kernel-default;·then
Offset 184, 14 lines modifiedOffset 179, 19 lines modified
184 ··-·PCI-DSSv4-11.5.2179 ··-·PCI-DSSv4-11.5.2
185 ··-·enable_strategy180 ··-·enable_strategy
186 ··-·low_complexity181 ··-·low_complexity
187 ··-·low_disruption182 ··-·low_disruption
188 ··-·medium_severity183 ··-·medium_severity
189 ··-·no_reboot_needed184 ··-·no_reboot_needed
190 ··-·package_aide_installed185 ··-·package_aide_installed
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 187 [[packages]]
 188 name·=·"aide"
 189 version·=·"*"
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
196 include·install_aide195 include·install_aide
  
Offset 1216, 19 lines modifiedOffset 1216, 14 lines modified
1216 ·············_\x8i_\x8s_\x8m·····1382,·1384,·13861216 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1217 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1217 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1218 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11218 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1219 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251219 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1220 ·············_\x8c_\x8i_\x8s·····1.3.11220 ·············_\x8c_\x8i_\x8s·····1.3.1
1221 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R331221 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1222 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21222 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1224 [[packages]] 
1225 name·=·"sudo" 
1226 version·=·"*" 
1227 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81223 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1228 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1224 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1229 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1225 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1230 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1226 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1231 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1227 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1232 #·Remediation·is·applicable·only·in·certain·platforms1228 #·Remediation·is·applicable·only·in·certain·platforms
1233 if·rpm·--quiet·-q·kernel-default;·then1229 if·rpm·--quiet·-q·kernel-default;·then
Offset 1270, 14 lines modifiedOffset 1265, 19 lines modified
1270 ··-·PCI-DSSv4-2.2.61265 ··-·PCI-DSSv4-2.2.6
1271 ··-·enable_strategy1266 ··-·enable_strategy
1272 ··-·low_complexity1267 ··-·low_complexity
1273 ··-·low_disruption1268 ··-·low_disruption
1274 ··-·medium_severity1269 ··-·medium_severity
1275 ··-·no_reboot_needed1270 ··-·no_reboot_needed
1276 ··-·package_sudo_installed1271 ··-·package_sudo_installed
 1272 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1273 [[packages]]
 1274 name·=·"sudo"
 1275 version·=·"*"
1277 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81276 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1278 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1277 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1279 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1278 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1280 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1279 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1281 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1280 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1282 include·install_sudo1281 include·install_sudo
  
Offset 9796, 19 lines modifiedOffset 9796, 14 lines modified
9796 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9796 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9797 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9797 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9798 ·····················002329798 ·····················00232
9799 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-0106009799 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
9800 ·············_\x8c_\x8i_\x8s·····1.7.1.19800 ·············_\x8c_\x8i_\x8s·····1.7.1.1
9801 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459801 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9802 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule9802 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
9803 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9804 [[packages]] 
9805 name·=·"pam_apparmor" 
9806 version·=·"*" 
9807 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89803 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9808 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9804 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9809 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9805 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9810 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9806 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9811 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9807 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9812 #·Remediation·is·applicable·only·in·certain·platforms9808 #·Remediation·is·applicable·only·in·certain·platforms
9813 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9809 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 9840, 14 lines modifiedOffset 9835, 19 lines modified
9840 ··-·NIST-800-53-SC-7(21)9835 ··-·NIST-800-53-SC-7(21)
9841 ··-·enable_strategy9836 ··-·enable_strategy
9842 ··-·low_complexity9837 ··-·low_complexity
9843 ··-·low_disruption9838 ··-·low_disruption
9844 ··-·medium_severity9839 ··-·medium_severity
9845 ··-·no_reboot_needed9840 ··-·no_reboot_needed
9846 ··-·package_pam_apparmor_installed9841 ··-·package_pam_apparmor_installed
 9842 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9843 [[packages]]
 9844 name·=·"pam_apparmor"
 9845 version·=·"*"
9847 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89846 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9848 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9847 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9849 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9848 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9850 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9849 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9851 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9850 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9852 include·install_pam_apparmor9851 include·install_pam_apparmor
  
Offset 10200, 18 lines modifiedOffset 10200, 14 lines modified
10200 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-10200 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
10201 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-10201 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
10202 ·····················0023210202 ·····················00232
10203 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-01060010203 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
10204 ·············_\x8c_\x8i_\x8s·····1.7.1.210204 ·············_\x8c_\x8i_\x8s·····1.7.1.2
10205 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R4510205 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
10206 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule10206 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
Max diff block lines reached; 43057/48278 bytes (89.19%) of diff not shown.
449 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-pci-dss-4.html
    
Offset 17170, 146 lines modifiedOffset 17170, 146 lines modified
00043110:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00043110:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00043120:·3533·3937·2220·7461·6269·6e64·6578·3d22··5397"·tabindex="00043120:·3533·3937·2220·7461·6269·6e64·6578·3d22··5397"·tabindex="
00043130:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00043130:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00043140:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00043140:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00043150:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00043150:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00043160:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00043160:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00043170:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00043170:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00043180:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·00043180:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
00043190:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
000431a0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
000431b0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
000431c0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
000431d0:·2220·6964·3d22·6964·6d35·3339·3722·3e3c··"·id="idm5397"><00043190:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 000431a0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 000431b0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 000431c0:·7073·6522·2069·643d·2269·646d·3533·3937··pse"·id="idm5397
 000431d0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 000431e0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 000431f0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00043200:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00043210:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00043220:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00043230:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00043240:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00043250:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00043260:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00043270:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00043280:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00043290:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 000432a0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 000432b0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
000431e0:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac000432c0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
000431f0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
00043200:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·000432d0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 000432e0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 000432f0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00043300:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 00043310:·7120·6b65·726e·656c·2d64·6566·6175·6c74··q·kernel-default
 00043320:·3b20·7468·656e·0a0a·7a79·7070·6572·2069··;·then..zypper·i
 00043330:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 00043340:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 00043350:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 00043360:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 00043370:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 00043380:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
00043210:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre00043390:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
00043220:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=000433a0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
00043230:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success000433b0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
00043240:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c000433c0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
00043250:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta000433d0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00043260:·7267·6574·3d22·2369·646d·3533·3938·2220··rget="#idm5398"·000433e0:·3d22·2369·646d·3533·3938·2220·7461·6269··="#idm5398"·tabi
00043270:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol000433f0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00043280:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-00043400:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00043290:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"00043410:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
000432a0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate00043420:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
000432b0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href00043430:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
000432c0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio00043440:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
000432d0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.00043450:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·..
 00043460:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 00043470:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 00043480:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 00043490:·3d22·6964·6d35·3339·3822·3e3c·7461·626c··="idm5398"><tabl
 000434a0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 000434b0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 000434c0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 000434d0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 000434e0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 000434f0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00043500:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 00043510:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 00043520:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 00043530:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 00043540:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 00043550:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 00043560:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 00043570:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 00043580:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 00043590:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe
 000435a0:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa
 000435b0:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa
 000435c0:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager
 000435d0:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.·
 000435e0:·202d·2043·4345·2d38·3330·3637·2d39·0a20···-·CCE-83067-9.·
 000435f0:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3
 00043600:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
 00043610:·4c45·532d·3132·2d30·3130·3439·390a·2020··LES-12-010499.··
 00043620:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 00043630:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
 00043640:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
 00043650:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
 00043660:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
 00043670:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp
 00043680:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
 00043690:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
 000436a0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
 000436b0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
 000436c0:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a
 000436d0:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..-
 000436e0:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai
 000436f0:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed.
 00043700:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n
 00043710:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st
 00043720:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w
 00043730:·6865·6e3a·2027·226b·6572·6e65·6c2d·6465··hen:·'"kernel-de
 00043740:·6661·756c·7422·2069·6e20·616e·7369·626c··fault"·in·ansibl
 00043750:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
 00043760:·270a·2020·7461·6773·3a0a·2020·2d20·4343··'.··tags:.··-·CC
 00043770:·452d·3833·3036·372d·390a·2020·2d20·434a··E-83067-9.··-·CJ
 00043780:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-·
 00043790:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1
 000437a0:·322d·3031·3034·3939·0a20·202d·204e·4953··2-010499.··-·NIS
 000437b0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
 000437c0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
 000437d0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
 000437e0:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e
 000437f0:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.·
 00043800:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
 00043810:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup
 00043820:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
 00043830:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
 00043840:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
 00043850:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i
 00043860:·6e73·7461·6c6c·6564·0a3c·2f63·6f64·653e··nstalled.</code>
 00043870:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 00043880:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 00043890:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 000438a0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
Max diff block lines reached; 419062/437858 bytes (95.71%) of diff not shown.
21.7 KB
html2text {}
    
Offset 619, 19 lines modifiedOffset 619, 14 lines modified
619 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5619 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
620 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199620 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
621 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499621 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
622 ·············_\x8c_\x8i_\x8s············1.4.1622 ·············_\x8c_\x8i_\x8s············1.4.1
623 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79623 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
624 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2624 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
625 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule625 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
626 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
627 [[packages]] 
628 name·=·"aide" 
629 version·=·"*" 
630 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8626 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
631 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low627 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
632 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low628 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
633 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false629 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
634 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable630 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
635 #·Remediation·is·applicable·only·in·certain·platforms631 #·Remediation·is·applicable·only·in·certain·platforms
636 if·rpm·--quiet·-q·kernel-default;·then632 if·rpm·--quiet·-q·kernel-default;·then
Offset 677, 14 lines modifiedOffset 672, 19 lines modified
677 ··-·PCI-DSSv4-11.5.2672 ··-·PCI-DSSv4-11.5.2
678 ··-·enable_strategy673 ··-·enable_strategy
679 ··-·low_complexity674 ··-·low_complexity
680 ··-·low_disruption675 ··-·low_disruption
681 ··-·medium_severity676 ··-·medium_severity
682 ··-·no_reboot_needed677 ··-·no_reboot_needed
683 ··-·package_aide_installed678 ··-·package_aide_installed
 679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 680 [[packages]]
 681 name·=·"aide"
 682 version·=·"*"
684 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8683 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
685 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low684 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
686 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low685 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
687 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false686 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
688 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable687 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
689 include·install_aide688 include·install_aide
  
Offset 7880, 18 lines modifiedOffset 7880, 14 lines modified
7880 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_pcscd_enabled7880 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_pcscd_enabled
7881 Identifiers:·CCE-91646-07881 Identifiers:·CCE-91646-0
7882 ·············_\x8d_\x8i_\x8s_\x8a···CCI-0040467882 ·············_\x8d_\x8i_\x8s_\x8a···CCI-004046
7883 ·············_\x8i_\x8s_\x8m····1382,·1384,·13867883 ·············_\x8i_\x8s_\x8m····1382,·1384,·1386
7884 References:··_\x8n_\x8i_\x8s_\x8t···IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a)7884 References:··_\x8n_\x8i_\x8s_\x8t···IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a)
7885 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·Req-8.37885 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·Req-8.3
7886 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-001607886 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-00160
7887 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
7888 [customizations.services] 
7889 enabled·=·["pcscd"] 
7890 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87887 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7891 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7888 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7892 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7889 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7893 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7890 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7894 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7891 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7895 #·Remediation·is·applicable·only·in·certain·platforms7892 #·Remediation·is·applicable·only·in·certain·platforms
7896 if·rpm·--quiet·-q·kernel-default;·then7893 if·rpm·--quiet·-q·kernel-default;·then
Offset 7966, 14 lines modifiedOffset 7962, 18 lines modified
7966 ··-·PCI-DSS-Req-8.37962 ··-·PCI-DSS-Req-8.3
7967 ··-·enable_strategy7963 ··-·enable_strategy
7968 ··-·low_complexity7964 ··-·low_complexity
7969 ··-·low_disruption7965 ··-·low_disruption
7970 ··-·medium_severity7966 ··-·medium_severity
7971 ··-·no_reboot_needed7967 ··-·no_reboot_needed
7972 ··-·service_pcscd_enabled7968 ··-·service_pcscd_enabled
 7969 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 7970 [customizations.services]
 7971 enabled·=·["pcscd"]
7973 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87972 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7974 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7973 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7975 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7974 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7976 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7975 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7977 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7976 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7978 include·enable_pcscd7977 include·enable_pcscd
  
Offset 10449, 19 lines modifiedOffset 10449, 14 lines modified
10449 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.110449 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
10450 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)10450 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
10451 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-110451 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
10452 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.710452 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.7
10453 ·············_\x8c_\x8i_\x8s············4.2.410453 ·············_\x8c_\x8i_\x8s············4.2.4
10454 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R7110454 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
10455 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.510455 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.5
10456 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
10457 [[packages]] 
10458 name·=·"logrotate" 
10459 version·=·"*" 
10460 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810456 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10461 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10457 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10462 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10458 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10463 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10459 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10464 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable10460 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
10465 #·Remediation·is·applicable·only·in·certain·platforms10461 #·Remediation·is·applicable·only·in·certain·platforms
10466 if·rpm·--quiet·-q·kernel-default;·then10462 if·rpm·--quiet·-q·kernel-default;·then
Offset 10505, 14 lines modifiedOffset 10500, 19 lines modified
10505 ··-·PCI-DSSv4-10.5.110500 ··-·PCI-DSSv4-10.5.1
10506 ··-·enable_strategy10501 ··-·enable_strategy
10507 ··-·low_complexity10502 ··-·low_complexity
10508 ··-·low_disruption10503 ··-·low_disruption
10509 ··-·medium_severity10504 ··-·medium_severity
10510 ··-·no_reboot_needed10505 ··-·no_reboot_needed
10511 ··-·package_logrotate_installed10506 ··-·package_logrotate_installed
 10507 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 10508 [[packages]]
 10509 name·=·"logrotate"
 10510 version·=·"*"
10512 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810511 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10513 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10512 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10514 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10513 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10515 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10514 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10516 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable10515 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
10517 include·install_logrotate10516 include·install_logrotate
  
Offset 10765, 19 lines modifiedOffset 10765, 14 lines modified
10765 References:·················5.3,·SR·7.1,·SR·7.610765 References:·················5.3,·SR·7.1,·SR·7.6
10766 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.15.1.1,·A.15.2.1,·A.6.2.1,10766 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.15.1.1,·A.15.2.1,·A.6.2.1,
10767 ····························A.6.2.210767 ····························A.6.2.2
10768 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)10768 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
10769 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.MA-2,·PR.PT-410769 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.MA-2,·PR.PT-4
10770 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-4.110770 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-4.1
10771 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-0006110771 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-00061
10772 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 16899/22172 bytes (76.22%) of diff not shown.
243 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-pci-dss.html
    
Offset 17115, 146 lines modifiedOffset 17115, 146 lines modified
00042da0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target00042da0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
00042db0:·3d22·2369·646d·3533·3937·2220·7461·6269··="#idm5397"·tabi00042db0:·3d22·2369·646d·3533·3937·2220·7461·6269··="#idm5397"·tabi
00042dc0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b00042dc0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
00042dd0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa00042dd0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
00042de0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit00042de0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
00042df0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·00042df0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
00042e00:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!00042e00:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
00042e10:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS00042e10:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 00042e20:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 00042e30:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 00042e40:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 00042e50:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 00042e60:·646d·3533·3937·223e·3c74·6162·6c65·2063··dm5397"><table·c
 00042e70:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 00042e80:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 00042e90:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 00042ea0:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 00042eb0:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 00042ec0:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 00042ed0:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 00042ee0:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 00042ef0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 00042f00:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 00042f10:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 00042f20:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 00042f30:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
00042e20:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
00042e30:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
00042e40:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
00042e50:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
00042e60:·6c6c·6170·7365·2220·6964·3d22·6964·6d35··llapse"·id="idm5 
00042e70:·3339·3722·3e3c·7072·653e·3c63·6f64·653e··397"><pre><code> 
00042e80:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
00042e90:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
00042ea0:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
00042eb0:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
00042ec0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
00042ed0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
00042ee0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
00042ef0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
00042f00:·3533·3938·2220·7461·6269·6e64·6578·3d22··5398"·tabindex=" 
00042f10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
00042f20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
00042f30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
00042f40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
00042f50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
00042f60:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
00042f70:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
00042f80:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
00042f90:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
00042fa0:·7073·6522·2069·643d·2269·646d·3533·3938··pse"·id="idm5398 
00042fb0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
00042fc0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
00042fd0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
00042fe0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
00042ff0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
00043000:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
00043010:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
00043020:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
00043030:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00043040:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
00043050:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
00043060:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr00042f40:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 00042f50:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
00043070:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
00043080:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
00043090:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
000430a0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
000430b0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
000430c0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
000430d0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
000430e0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
000430f0:·7120·6b65·726e·656c·2d64·6566·6175·6c74··q·kernel-default 
00043100:·3b20·7468·656e·0a0a·7a79·7070·6572·2069··;·then..zypper·i 
00043110:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
00043120:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
00043130:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
00043140:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
00043150:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
00043160:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
00043170:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
00043180:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
00043190:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
000431a0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
000431b0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
000431c0:·3d22·2369·646d·3533·3939·2220·7461·6269··="#idm5399"·tabi 
000431d0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
000431e0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
000431f0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
00043200:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
00043210:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
00043220:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An00042f60:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
00043230:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
00043240:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
00043250:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
00043260:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
00043270:·3d22·6964·6d35·3339·3922·3e3c·7461·626c··="idm5399"><tabl 
00043280:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
00043290:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
000432a0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
000432b0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
000432c0:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
000432d0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
000432e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
000432f0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00043300:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00043310:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00043320:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00043330:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00043340:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
00043350:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
00043360:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
00043370:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
00043380:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
00043390:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
000433a0:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
000433b0:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
000433c0:·202d·2043·4345·2d38·3330·3637·2d39·0a20···-·CCE-83067-9.· 
000433d0:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
000433e0:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S 
000433f0:·4c45·532d·3132·2d30·3130·3439·390a·2020··LES-12-010499.·· 
00043400:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
00043410:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
00043420:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
00043430:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
00043440:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
00043450:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
Max diff block lines reached; 217000/235796 bytes (92.03%) of diff not shown.
12.3 KB
html2text {}
    
Offset 609, 19 lines modifiedOffset 609, 14 lines modified
609 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5609 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
610 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199610 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
611 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499611 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
612 ·············_\x8c_\x8i_\x8s············1.4.1612 ·············_\x8c_\x8i_\x8s············1.4.1
613 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79613 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
614 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2614 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
615 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule615 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
616 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
617 [[packages]] 
618 name·=·"aide" 
619 version·=·"*" 
620 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8616 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
621 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low617 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
622 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low618 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
623 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false619 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
624 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable620 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
625 #·Remediation·is·applicable·only·in·certain·platforms621 #·Remediation·is·applicable·only·in·certain·platforms
626 if·rpm·--quiet·-q·kernel-default;·then622 if·rpm·--quiet·-q·kernel-default;·then
Offset 667, 14 lines modifiedOffset 662, 19 lines modified
667 ··-·PCI-DSSv4-11.5.2662 ··-·PCI-DSSv4-11.5.2
668 ··-·enable_strategy663 ··-·enable_strategy
669 ··-·low_complexity664 ··-·low_complexity
670 ··-·low_disruption665 ··-·low_disruption
671 ··-·medium_severity666 ··-·medium_severity
672 ··-·no_reboot_needed667 ··-·no_reboot_needed
673 ··-·package_aide_installed668 ··-·package_aide_installed
 669 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 670 [[packages]]
 671 name·=·"aide"
 672 version·=·"*"
674 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8673 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
675 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low674 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
676 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low675 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
677 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false676 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
678 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable677 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
679 include·install_aide678 include·install_aide
  
Offset 7870, 18 lines modifiedOffset 7870, 14 lines modified
7870 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_pcscd_enabled7870 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_pcscd_enabled
7871 Identifiers:·CCE-91646-07871 Identifiers:·CCE-91646-0
7872 ·············_\x8d_\x8i_\x8s_\x8a···CCI-0040467872 ·············_\x8d_\x8i_\x8s_\x8a···CCI-004046
7873 ·············_\x8i_\x8s_\x8m····1382,·1384,·13867873 ·············_\x8i_\x8s_\x8m····1382,·1384,·1386
7874 References:··_\x8n_\x8i_\x8s_\x8t···IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a)7874 References:··_\x8n_\x8i_\x8s_\x8t···IA-2(1),·IA-2(2),·IA-2(3),·IA-2(4),·IA-2(6),·IA-2(7),·IA-2(11),·CM-6(a)
7875 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·Req-8.37875 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·Req-8.3
7876 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-001607876 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000375-GPOS-00160
7877 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
7878 [customizations.services] 
7879 enabled·=·["pcscd"] 
7880 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x87877 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
7881 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7878 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7882 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7879 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7883 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7880 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7884 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7881 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7885 #·Remediation·is·applicable·only·in·certain·platforms7882 #·Remediation·is·applicable·only·in·certain·platforms
7886 if·rpm·--quiet·-q·kernel-default;·then7883 if·rpm·--quiet·-q·kernel-default;·then
Offset 7956, 14 lines modifiedOffset 7952, 18 lines modified
7956 ··-·PCI-DSS-Req-8.37952 ··-·PCI-DSS-Req-8.3
7957 ··-·enable_strategy7953 ··-·enable_strategy
7958 ··-·low_complexity7954 ··-·low_complexity
7959 ··-·low_disruption7955 ··-·low_disruption
7960 ··-·medium_severity7956 ··-·medium_severity
7961 ··-·no_reboot_needed7957 ··-·no_reboot_needed
7962 ··-·service_pcscd_enabled7958 ··-·service_pcscd_enabled
 7959 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 7960 [customizations.services]
 7961 enabled·=·["pcscd"]
7963 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x87962 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
7964 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low7963 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
7965 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low7964 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
7966 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false7965 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
7967 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable7966 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
7968 include·enable_pcscd7967 include·enable_pcscd
  
Offset 10211, 19 lines modifiedOffset 10211, 14 lines modified
10211 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.110211 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
10212 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)10212 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
10213 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-110213 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
10214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.710214 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.7
10215 ·············_\x8c_\x8i_\x8s············4.2.410215 ·············_\x8c_\x8i_\x8s············4.2.4
10216 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R7110216 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
10217 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.510217 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.5
10218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
10219 [[packages]] 
10220 name·=·"logrotate" 
10221 version·=·"*" 
10222 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x810218 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
10223 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10219 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10224 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10220 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10225 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10221 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10226 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable10222 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
10227 #·Remediation·is·applicable·only·in·certain·platforms10223 #·Remediation·is·applicable·only·in·certain·platforms
10228 if·rpm·--quiet·-q·kernel-default;·then10224 if·rpm·--quiet·-q·kernel-default;·then
Offset 10267, 14 lines modifiedOffset 10262, 19 lines modified
10267 ··-·PCI-DSSv4-10.5.110262 ··-·PCI-DSSv4-10.5.1
10268 ··-·enable_strategy10263 ··-·enable_strategy
10269 ··-·low_complexity10264 ··-·low_complexity
10270 ··-·low_disruption10265 ··-·low_disruption
10271 ··-·medium_severity10266 ··-·medium_severity
10272 ··-·no_reboot_needed10267 ··-·no_reboot_needed
10273 ··-·package_logrotate_installed10268 ··-·package_logrotate_installed
 10269 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 10270 [[packages]]
 10271 name·=·"logrotate"
 10272 version·=·"*"
10274 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810273 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10275 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10274 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10276 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10275 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10277 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10276 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10278 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable10277 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
10279 include·install_logrotate10278 include·install_logrotate
  
Offset 10527, 19 lines modifiedOffset 10527, 14 lines modified
10527 References:·················5.3,·SR·7.1,·SR·7.610527 References:·················5.3,·SR·7.1,·SR·7.6
10528 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.15.1.1,·A.15.2.1,·A.6.2.1,10528 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.11.2.4,·A.11.2.6,·A.13.1.1,·A.13.2.1,·A.14.1.3,·A.15.1.1,·A.15.2.1,·A.6.2.1,
10529 ····························A.6.2.210529 ····························A.6.2.2
10530 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)10530 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
10531 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.MA-2,·PR.PT-410531 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.MA-2,·PR.PT-4
10532 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-4.110532 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-4.1
10533 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-0006110533 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227,·SRG-OS-000120-GPOS-00061
10534 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 7316/12589 bytes (58.11%) of diff not shown.
323 KB
./usr/share/doc/ssg-nondebian/ssg-sle12-guide-stig.html
    
Offset 15106, 146 lines modifiedOffset 15106, 146 lines modified
0003b010:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b010:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b020:·2223·6964·6d35·3339·3722·2074·6162·696e··"#idm5397"·tabin0003b020:·2223·6964·6d35·3339·3722·2074·6162·696e··"#idm5397"·tabin
0003b030:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b030:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b040:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b040:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b050:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b050:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b060:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b060:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b070:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b070:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b080:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003b080:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
0003b090:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003b0a0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b0b0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b0c0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b0d0:·6c61·7073·6522·2069·643d·2269·646d·3533··lapse"·id="idm530003b090:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003b0a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b0b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b0c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b0d0:·6d35·3339·3722·3e3c·7461·626c·6520·636c··m5397"><table·cl
 0003b0e0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b0f0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b100:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b110:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b120:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b130:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b140:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b150:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b160:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b170:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b180:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b190:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b1a0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003b1b0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003b0e0:·3937·223e·3c70·7265·3e3c·636f·6465·3e0a··97"><pre><code>.0003b1c0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
0003b0f0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003b100:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003b110:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>0003b1d0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003b1e0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003b1f0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003b200:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 0003b210:·6965·7420·2d71·206b·6572·6e65·6c2d·6465··iet·-q·kernel-de
 0003b220:·6661·756c·743b·2074·6865·6e0a·0a7a·7970··fault;·then..zyp
 0003b230:·7065·7220·696e·7374·616c·6c20·2d79·2022··per·install·-y·"
 0003b240:·6169·6465·220a·0a65·6c73·650a·2020·2020··aide"..else.····
 0003b250:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003b260:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003b270:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003b280:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 0003b290:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003b120:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b2a0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003b130:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003b2b0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003b140:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003b2c0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003b150:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003b2d0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003b160:·7461·2d74·6172·6765·743d·2223·6964·6d35··ta-target="#idm50003b2e0:·6172·6765·743d·2223·6964·6d35·3339·3822··arget="#idm5398"
0003b170:·3339·3822·2074·6162·696e·6465·783d·2230··398"·tabindex="00003b2f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b180:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b300:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b190:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b310:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b1a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b320:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b1b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b330:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b1c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b340:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003b1d0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr0003b350:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 0003b360:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b370:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b380:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b390:·6522·2069·643d·2269·646d·3533·3938·223e··e"·id="idm5398">
 0003b3a0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b3b0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b3c0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b3d0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b3e0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b3f0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b400:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b410:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b420:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b430:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b440:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b450:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b460:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b470:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b480:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b490:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
 0003b4a0:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa
 0003b4b0:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa
 0003b4c0:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma
 0003b4d0:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta
 0003b4e0:·6773·3a0a·2020·2d20·4343·452d·3833·3036··gs:.··-·CCE-8306
 0003b4f0:·372d·390a·2020·2d20·434a·4953·2d35·2e31··7-9.··-·CJIS-5.1
 0003b500:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S
 0003b510:·5449·472d·534c·4553·2d31·322d·3031·3034··TIG-SLES-12-0104
 0003b520:·3939·0a20·202d·204e·4953·542d·3830·302d··99.··-·NIST-800-
 0003b530:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P
 0003b540:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5.
 0003b550:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11
 0003b560:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_
 0003b570:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
 0003b580:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
 0003b590:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
 0003b5a0:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
 0003b5b0:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
 0003b5c0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack
 0003b5d0:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install
 0003b5e0:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu
 0003b5f0:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta
 0003b600:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:.
 0003b610:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.·
 0003b620:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen
 0003b630:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern
 0003b640:·656c·2d64·6566·6175·6c74·2220·696e·2061··el-default"·in·a
 0003b650:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
 0003b660:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.·
 0003b670:·202d·2043·4345·2d38·3330·3637·2d39·0a20···-·CCE-83067-9.·
 0003b680:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3
 0003b690:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
 0003b6a0:·4c45·532d·3132·2d30·3130·3439·390a·2020··LES-12-010499.··
 0003b6b0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 0003b6c0:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
 0003b6d0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
 0003b6e0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
 0003b6f0:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
 0003b700:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp
 0003b710:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
 0003b720:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
 0003b730:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
 0003b740:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
 0003b750:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a
 0003b760:·6964·655f·696e·7374·616c·6c65·640a·3c2f··ide_installed.</
 0003b770:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b780:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b790:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
Max diff block lines reached; 291938/310734 bytes (93.95%) of diff not shown.
19.9 KB
html2text {}
    
Offset 114, 19 lines modifiedOffset 114, 14 lines modified
114 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5114 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
115 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199115 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
116 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499116 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-12-010499
117 ·············_\x8c_\x8i_\x8s············1.4.1117 ·············_\x8c_\x8i_\x8s············1.4.1
118 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79118 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
120 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule120 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255916r958794_rule
121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
122 [[packages]] 
123 name·=·"aide" 
124 version·=·"*" 
125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low122 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low123 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false124 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable125 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
130 #·Remediation·is·applicable·only·in·certain·platforms126 #·Remediation·is·applicable·only·in·certain·platforms
131 if·rpm·--quiet·-q·kernel-default;·then127 if·rpm·--quiet·-q·kernel-default;·then
Offset 172, 14 lines modifiedOffset 167, 19 lines modified
172 ··-·PCI-DSSv4-11.5.2167 ··-·PCI-DSSv4-11.5.2
173 ··-·enable_strategy168 ··-·enable_strategy
174 ··-·low_complexity169 ··-·low_complexity
175 ··-·low_disruption170 ··-·low_disruption
176 ··-·medium_severity171 ··-·medium_severity
177 ··-·no_reboot_needed172 ··-·no_reboot_needed
178 ··-·package_aide_installed173 ··-·package_aide_installed
 174 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 175 [[packages]]
 176 name·=·"aide"
 177 version·=·"*"
179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
184 include·install_aide183 include·install_aide
  
Offset 9522, 19 lines modifiedOffset 9522, 14 lines modified
9522 Rule·ID:·····xccdf_org.ssgproject.content_rule_vlock_installed9522 Rule·ID:·····xccdf_org.ssgproject.content_rule_vlock_installed
9523 Identifiers:·CCE-83009-19523 Identifiers:·CCE-83009-1
9524 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-0000609524 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-000060
9525 ·············_\x8n_\x8i_\x8s_\x8t····AC-11(a),·AC-11(b),·AC-11(1)9525 ·············_\x8n_\x8i_\x8s_\x8t····AC-11(a),·AC-11(b),·AC-11(1)
9526 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-000119526 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-00011
9527 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-0100709527 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010070
9528 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217108r1015204_rule9528 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217108r1015204_rule
9529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9530 [[packages]] 
9531 name·=·"kbd" 
9532 version·=·"*" 
9533 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9534 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9535 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9531 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9536 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9532 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9537 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9533 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9538 #·Remediation·is·applicable·only·in·certain·platforms9534 #·Remediation·is·applicable·only·in·certain·platforms
9539 if·rpm·--quiet·-q·kernel-default;·then9535 if·rpm·--quiet·-q·kernel-default;·then
Offset 9578, 14 lines modifiedOffset 9573, 19 lines modified
9578 ··-·NIST-800-53-AC-11(b)9573 ··-·NIST-800-53-AC-11(b)
9579 ··-·enable_strategy9574 ··-·enable_strategy
9580 ··-·low_complexity9575 ··-·low_complexity
9581 ··-·low_disruption9576 ··-·low_disruption
9582 ··-·medium_severity9577 ··-·medium_severity
9583 ··-·no_reboot_needed9578 ··-·no_reboot_needed
9584 ··-·vlock_installed9579 ··-·vlock_installed
 9580 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9581 [[packages]]
 9582 name·=·"kbd"
 9583 version·=·"*"
9585 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89584 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9586 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9585 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9587 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9586 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9588 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9587 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9589 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9588 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9590 include·install_kbd9589 include·install_kbd
  
Offset 12702, 19 lines modifiedOffset 12702, 14 lines modified
12702 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-12702 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
12703 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-12703 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
12704 ·····················0023212704 ·····················00232
12705 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-01060012705 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
12706 ·············_\x8c_\x8i_\x8s·····1.7.1.112706 ·············_\x8c_\x8i_\x8s·····1.7.1.1
12707 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R4512707 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
12708 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule12708 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
12709 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
12710 [[packages]] 
12711 name·=·"pam_apparmor" 
12712 version·=·"*" 
12713 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x812709 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
12714 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12710 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12715 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12711 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12716 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12712 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12717 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable12713 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
12718 #·Remediation·is·applicable·only·in·certain·platforms12714 #·Remediation·is·applicable·only·in·certain·platforms
12719 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then12715 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 12746, 14 lines modifiedOffset 12741, 19 lines modified
12746 ··-·NIST-800-53-SC-7(21)12741 ··-·NIST-800-53-SC-7(21)
12747 ··-·enable_strategy12742 ··-·enable_strategy
12748 ··-·low_complexity12743 ··-·low_complexity
12749 ··-·low_disruption12744 ··-·low_disruption
12750 ··-·medium_severity12745 ··-·medium_severity
12751 ··-·no_reboot_needed12746 ··-·no_reboot_needed
12752 ··-·package_pam_apparmor_installed12747 ··-·package_pam_apparmor_installed
 12748 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 12749 [[packages]]
 12750 name·=·"pam_apparmor"
 12751 version·=·"*"
12753 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x812752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
12754 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12755 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12754 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12756 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12755 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12757 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable12756 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
12758 include·install_pam_apparmor12757 include·install_pam_apparmor
  
Offset 12795, 18 lines modifiedOffset 12795, 14 lines modified
12795 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-12795 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
12796 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-12796 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
12797 ·····················0023212797 ·····················00232
12798 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-01060012798 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-12-010600
12799 ·············_\x8c_\x8i_\x8s·····1.7.1.212799 ·············_\x8c_\x8i_\x8s·····1.7.1.2
12800 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R4512800 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
12801 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule12801 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-217158r958702_rule
Max diff block lines reached; 14969/20305 bytes (73.72%) of diff not shown.
580 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_enhanced.html
    
Offset 15133, 146 lines modifiedOffset 15133, 146 lines modified
0003b1c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b1c0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b1d0:·3633·3631·2220·7461·6269·6e64·6578·3d22··6361"·tabindex="0003b1d0:·3633·3631·2220·7461·6269·6e64·6578·3d22··6361"·tabindex="
0003b1e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b1e0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b1f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b1f0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b200:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b200:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b210:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b210:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b220:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b220:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b230:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·0003b230:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
0003b240:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0003b250:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b260:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b270:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b280:·2220·6964·3d22·6964·6d36·3336·3122·3e3c··"·id="idm6361"><0003b240:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003b250:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b260:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b270:·7073·6522·2069·643d·2269·646d·3633·3631··pse"·id="idm6361
 0003b280:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b290:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b2a0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b2b0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b2c0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b2d0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b2e0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b2f0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b300:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b310:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b320:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b330:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b340:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b350:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b360:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003b290:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac0003b370:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
0003b2a0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
0003b2b0:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·0003b380:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 0003b390:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 0003b3a0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 0003b3b0:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 0003b3c0:·7120·6b65·726e·656c·2d64·6566·6175·6c74··q·kernel-default
 0003b3d0:·3b20·7468·656e·0a0a·7a79·7070·6572·2069··;·then..zypper·i
 0003b3e0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 0003b3f0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003b400:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003b410:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003b420:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003b430:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
0003b2c0:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre0003b440:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003b2d0:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003b450:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003b2e0:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003b460:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003b2f0:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003b470:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003b300:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003b480:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b310:·7267·6574·3d22·2369·646d·3633·3632·2220··rget="#idm6362"·0003b490:·3d22·2369·646d·3633·3632·2220·7461·6269··="#idm6362"·tabi
0003b320:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b4a0:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b330:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b4b0:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b340:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b4c0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b350:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b4d0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b360:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b4e0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b370:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b4f0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003b380:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.0003b500:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·..
 0003b510:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b520:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b530:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b540:·3d22·6964·6d36·3336·3222·3e3c·7461·626c··="idm6362"><tabl
 0003b550:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b560:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b570:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b580:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b590:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b5a0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b5b0:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b5c0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b5d0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b5e0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b5f0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b600:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b610:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003b620:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003b630:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b640:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe
 0003b650:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa
 0003b660:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa
 0003b670:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager
 0003b680:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.·
 0003b690:·202d·2043·4345·2d38·3332·3839·2d39·0a20···-·CCE-83289-9.·
 0003b6a0:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3
 0003b6b0:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
 0003b6c0:·4c45·532d·3135·2d30·3130·3431·390a·2020··LES-15-010419.··
 0003b6d0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 0003b6e0:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
 0003b6f0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
 0003b700:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
 0003b710:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
 0003b720:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp
 0003b730:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
 0003b740:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
 0003b750:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
 0003b760:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
 0003b770:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a
 0003b780:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..-
 0003b790:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai
 0003b7a0:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed.
 0003b7b0:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n
 0003b7c0:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st
 0003b7d0:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w
 0003b7e0:·6865·6e3a·2027·226b·6572·6e65·6c2d·6465··hen:·'"kernel-de
 0003b7f0:·6661·756c·7422·2069·6e20·616e·7369·626c··fault"·in·ansibl
 0003b800:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
 0003b810:·270a·2020·7461·6773·3a0a·2020·2d20·4343··'.··tags:.··-·CC
 0003b820:·452d·3833·3238·392d·390a·2020·2d20·434a··E-83289-9.··-·CJ
 0003b830:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-·
 0003b840:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1
 0003b850:·352d·3031·3034·3139·0a20·202d·204e·4953··5-010419.··-·NIS
 0003b860:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
 0003b870:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
 0003b880:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
 0003b890:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e
 0003b8a0:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.·
 0003b8b0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
 0003b8c0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup
 0003b8d0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
 0003b8e0:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
 0003b8f0:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
 0003b900:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i
 0003b910:·6e73·7461·6c6c·6564·0a3c·2f63·6f64·653e··nstalled.</code>
 0003b920:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003b930:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003b940:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003b950:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
Max diff block lines reached; 544754/563550 bytes (96.66%) of diff not shown.
29.7 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 14 lines modified
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
125 ·············_\x8c_\x8i_\x8s············1.4.1125 ·············_\x8c_\x8i_\x8s············1.4.1
126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms134 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel-default;·then135 if·rpm·--quiet·-q·kernel-default;·then
Offset 180, 14 lines modifiedOffset 175, 19 lines modified
180 ··-·PCI-DSSv4-11.5.2175 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy176 ··-·enable_strategy
182 ··-·low_complexity177 ··-·low_complexity
183 ··-·low_disruption178 ··-·low_disruption
184 ··-·medium_severity179 ··-·medium_severity
185 ··-·no_reboot_needed180 ··-·no_reboot_needed
186 ··-·package_aide_installed181 ··-·package_aide_installed
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide191 include·install_aide
  
Offset 607, 19 lines modifiedOffset 607, 14 lines modified
607 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386607 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
608 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)608 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
609 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1609 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
610 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125610 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
611 ·············_\x8c_\x8i_\x8s·····1.3.1611 ·············_\x8c_\x8i_\x8s·····1.3.1
612 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33612 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
613 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2613 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
614 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
615 [[packages]] 
616 name·=·"sudo" 
617 version·=·"*" 
618 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8614 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
619 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low615 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
620 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low616 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
621 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false617 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
622 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable618 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
623 #·Remediation·is·applicable·only·in·certain·platforms619 #·Remediation·is·applicable·only·in·certain·platforms
624 if·rpm·--quiet·-q·kernel-default;·then620 if·rpm·--quiet·-q·kernel-default;·then
Offset 661, 14 lines modifiedOffset 656, 19 lines modified
661 ··-·PCI-DSSv4-2.2.6656 ··-·PCI-DSSv4-2.2.6
662 ··-·enable_strategy657 ··-·enable_strategy
663 ··-·low_complexity658 ··-·low_complexity
664 ··-·low_disruption659 ··-·low_disruption
665 ··-·medium_severity660 ··-·medium_severity
666 ··-·no_reboot_needed661 ··-·no_reboot_needed
667 ··-·package_sudo_installed662 ··-·package_sudo_installed
 663 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 664 [[packages]]
 665 name·=·"sudo"
 666 version·=·"*"
668 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8667 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
669 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low668 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
670 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low669 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
671 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false670 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
672 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable671 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
673 include·install_sudo672 include·install_sudo
  
Offset 1463, 19 lines modifiedOffset 1463, 14 lines modified
1463 ·············automatic,·regular·execution.1463 ·············automatic,·regular·execution.
1464 Severity: ···medium1464 Severity: ···medium
1465 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1465 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1466 Identifiers:·CCE-91163-61466 Identifiers:·CCE-91163-6
1467 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.21467 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
1468 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-000801468 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
1469 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R611469 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
1470 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1471 [[packages]] 
1472 name·=·"dnf-automatic" 
1473 version·=·"*" 
1474 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81470 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1475 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1471 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1476 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1472 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1477 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1473 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1478 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1474 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1479 #·Remediation·is·applicable·only·in·certain·platforms1475 #·Remediation·is·applicable·only·in·certain·platforms
1480 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&·{·!1476 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&·{·!
Offset 1514, 14 lines modifiedOffset 1509, 19 lines modified
1514 ··-·CCE-91163-61509 ··-·CCE-91163-6
1515 ··-·enable_strategy1510 ··-·enable_strategy
1516 ··-·low_complexity1511 ··-·low_complexity
1517 ··-·low_disruption1512 ··-·low_disruption
1518 ··-·medium_severity1513 ··-·medium_severity
1519 ··-·no_reboot_needed1514 ··-·no_reboot_needed
1520 ··-·package_dnf-automatic_installed1515 ··-·package_dnf-automatic_installed
 1516 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1517 [[packages]]
 1518 name·=·"dnf-automatic"
 1519 version·=·"*"
1521 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81520 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1522 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1521 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1523 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1522 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1524 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1523 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1525 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1524 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1526 include·install_dnf-automatic1525 include·install_dnf-automatic
  
Offset 9330, 19 lines modifiedOffset 9330, 14 lines modified
9330 ············Control·system·will·be·available.9330 ············Control·system·will·be·available.
9331 Severity: ··medium9331 Severity: ··medium
9332 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed9332 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed
9333 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022359333 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
9334 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-9334 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-
9335 ···················000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001559335 ···················000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
9336 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R459336 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
Max diff block lines reached; 25259/30432 bytes (83.00%) of diff not shown.
580 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_high.html
    
Offset 15138, 146 lines modifiedOffset 15138, 146 lines modified
0003b210:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b210:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b220:·6964·6d36·3336·3122·2074·6162·696e·6465··idm6361"·tabinde0003b220:·6964·6d36·3336·3122·2074·6162·696e·6465··idm6361"·tabinde
0003b230:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b230:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b240:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b240:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b250:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b250:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b260:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b260:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b270:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b270:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b280:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003b280:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0003b290:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003b2a0:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b2b0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b2c0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b2d0:·7073·6522·2069·643d·2269·646d·3633·3631··pse"·id="idm63610003b290:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003b2a0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b2b0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b2c0:·6c6c·6170·7365·2220·6964·3d22·6964·6d36··llapse"·id="idm6
 0003b2d0:·3336·3122·3e3c·7461·626c·6520·636c·6173··361"><table·clas
 0003b2e0:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b2f0:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b300:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b310:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b320:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b330:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b340:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b350:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b360:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b370:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b380:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b390:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b3a0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b3b0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b2e0:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[0003b3c0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
0003b2f0:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003b300:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003b310:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></0003b3d0:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003b3e0:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003b3f0:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003b400:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 0003b410:·7420·2d71·206b·6572·6e65·6c2d·6465·6661··t·-q·kernel-defa
 0003b420:·756c·743b·2074·6865·6e0a·0a7a·7970·7065··ult;·then..zyppe
 0003b430:·7220·696e·7374·616c·6c20·2d79·2022·6169··r·install·-y·"ai
 0003b440:·6465·220a·0a65·6c73·650a·2020·2020·2667··de"..else.····&g
 0003b450:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 0003b460:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 0003b470:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 0003b480:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 0003b490:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
0003b320:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003b4a0:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003b330:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003b4b0:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003b340:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003b4c0:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003b350:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003b4d0:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003b360:·2d74·6172·6765·743d·2223·6964·6d36·3336··-target="#idm6360003b4e0:·6765·743d·2223·6964·6d36·3336·3222·2074··get="#idm6362"·t
0003b370:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·0003b4f0:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b380:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b500:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b390:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b510:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b3a0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b520:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b3b0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b530:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b3c0:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b540:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b3d0:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip0003b550:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
 0003b560:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b570:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b580:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b590:·2069·643d·2269·646d·3633·3632·223e·3c74···id="idm6362"><t
 0003b5a0:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b5b0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b5c0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b5d0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b5e0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b5f0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b600:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b610:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003b620:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b630:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b640:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003b650:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b660:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003b670:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003b680:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003b690:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4761··<code>-·name:·Ga
 0003b6a0:·7468·6572·2074·6865·2070·6163·6b61·6765··ther·the·package
 0003b6b0:·2066·6163·7473·0a20·2070·6163·6b61·6765···facts.··package
 0003b6c0:·5f66·6163·7473·3a0a·2020·2020·6d61·6e61··_facts:.····mana
 0003b6d0:·6765·723a·2061·7574·6f0a·2020·7461·6773··ger:·auto.··tags
 0003b6e0:·3a0a·2020·2d20·4343·452d·3833·3238·392d··:.··-·CCE-83289-
 0003b6f0:·390a·2020·2d20·434a·4953·2d35·2e31·302e··9.··-·CJIS-5.10.
 0003b700:·312e·330a·2020·2d20·4449·5341·2d53·5449··1.3.··-·DISA-STI
 0003b710:·472d·534c·4553·2d31·352d·3031·3034·3139··G-SLES-15-010419
 0003b720:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003b730:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI
 0003b740:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.··
 0003b750:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5
 0003b760:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st
 0003b770:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c
 0003b780:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo
 0003b790:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-
 0003b7a0:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity
 0003b7b0:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n
 0003b7c0:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag
 0003b7d0:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed
 0003b7e0:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure
 0003b7f0:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install
 0003b800:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.··
 0003b810:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.···
 0003b820:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.
 0003b830:·2020·7768·656e·3a20·2722·6b65·726e·656c····when:·'"kernel
 0003b840:·2d64·6566·6175·6c74·2220·696e·2061·6e73··-default"·in·ans
 0003b850:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
 0003b860:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-
 0003b870:·2043·4345·2d38·3332·3839·2d39·0a20·202d···CCE-83289-9.··-
 0003b880:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.·
 0003b890:·202d·2044·4953·412d·5354·4947·2d53·4c45···-·DISA-STIG-SLE
 0003b8a0:·532d·3135·2d30·3130·3431·390a·2020·2d20··S-15-010419.··-·
 0003b8b0:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6
 0003b8c0:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS-
 0003b8d0:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI
 0003b8e0:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.··
 0003b8f0:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg
 0003b900:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple
 0003b910:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis
 0003b920:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi
 0003b930:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-·
 0003b940:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed
 0003b950:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid
 0003b960:·655f·696e·7374·616c·6c65·640a·3c2f·636f··e_installed.</co
 0003b970:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003b980:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003b990:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
Max diff block lines reached; 544340/563136 bytes (96.66%) of diff not shown.
30.0 KB
html2text {}
    
Offset 123, 19 lines modifiedOffset 123, 14 lines modified
123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5123 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
124 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199124 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
125 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419125 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
126 ·············_\x8c_\x8i_\x8s············1.4.1126 ·············_\x8c_\x8i_\x8s············1.4.1
127 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79127 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
129 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule129 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
131 [[packages]] 
132 name·=·"aide" 
133 version·=·"*" 
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8130 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low131 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low132 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false133 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable134 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
139 #·Remediation·is·applicable·only·in·certain·platforms135 #·Remediation·is·applicable·only·in·certain·platforms
140 if·rpm·--quiet·-q·kernel-default;·then136 if·rpm·--quiet·-q·kernel-default;·then
Offset 181, 14 lines modifiedOffset 176, 19 lines modified
181 ··-·PCI-DSSv4-11.5.2176 ··-·PCI-DSSv4-11.5.2
182 ··-·enable_strategy177 ··-·enable_strategy
183 ··-·low_complexity178 ··-·low_complexity
184 ··-·low_disruption179 ··-·low_disruption
185 ··-·medium_severity180 ··-·medium_severity
186 ··-·no_reboot_needed181 ··-·no_reboot_needed
187 ··-·package_aide_installed182 ··-·package_aide_installed
 183 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 184 [[packages]]
 185 name·=·"aide"
 186 version·=·"*"
188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
189 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
190 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
191 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
192 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
193 include·install_aide192 include·install_aide
  
Offset 1227, 19 lines modifiedOffset 1227, 14 lines modified
1227 ·············_\x8i_\x8s_\x8m·····1382,·1384,·13861227 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1228 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1228 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1229 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11229 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1230 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251230 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1231 ·············_\x8c_\x8i_\x8s·····1.3.11231 ·············_\x8c_\x8i_\x8s·····1.3.1
1232 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R331232 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1233 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21233 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1235 [[packages]] 
1236 name·=·"sudo" 
1237 version·=·"*" 
1238 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81234 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1239 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1235 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1240 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1236 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1241 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1237 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1242 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1238 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1243 #·Remediation·is·applicable·only·in·certain·platforms1239 #·Remediation·is·applicable·only·in·certain·platforms
1244 if·rpm·--quiet·-q·kernel-default;·then1240 if·rpm·--quiet·-q·kernel-default;·then
Offset 1281, 14 lines modifiedOffset 1276, 19 lines modified
1281 ··-·PCI-DSSv4-2.2.61276 ··-·PCI-DSSv4-2.2.6
1282 ··-·enable_strategy1277 ··-·enable_strategy
1283 ··-·low_complexity1278 ··-·low_complexity
1284 ··-·low_disruption1279 ··-·low_disruption
1285 ··-·medium_severity1280 ··-·medium_severity
1286 ··-·no_reboot_needed1281 ··-·no_reboot_needed
1287 ··-·package_sudo_installed1282 ··-·package_sudo_installed
 1283 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1284 [[packages]]
 1285 name·=·"sudo"
 1286 version·=·"*"
1288 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81287 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1289 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1288 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1290 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1289 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1291 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1290 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1292 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1291 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1293 include·install_sudo1292 include·install_sudo
  
Offset 2083, 19 lines modifiedOffset 2083, 14 lines modified
2083 ·············automatic,·regular·execution.2083 ·············automatic,·regular·execution.
2084 Severity: ···medium2084 Severity: ···medium
2085 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed2085 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
2086 Identifiers:·CCE-91163-62086 Identifiers:·CCE-91163-6
2087 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.22087 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
2088 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-000802088 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
2089 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R612089 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
2090 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2091 [[packages]] 
2092 name·=·"dnf-automatic" 
2093 version·=·"*" 
2094 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82090 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2095 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2091 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2096 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2092 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2097 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2093 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2098 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2094 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2099 #·Remediation·is·applicable·only·in·certain·platforms2095 #·Remediation·is·applicable·only·in·certain·platforms
2100 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&·{·!2096 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&·{·!
Offset 2134, 14 lines modifiedOffset 2129, 19 lines modified
2134 ··-·CCE-91163-62129 ··-·CCE-91163-6
2135 ··-·enable_strategy2130 ··-·enable_strategy
2136 ··-·low_complexity2131 ··-·low_complexity
2137 ··-·low_disruption2132 ··-·low_disruption
2138 ··-·medium_severity2133 ··-·medium_severity
2139 ··-·no_reboot_needed2134 ··-·no_reboot_needed
2140 ··-·package_dnf-automatic_installed2135 ··-·package_dnf-automatic_installed
 2136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2137 [[packages]]
 2138 name·=·"dnf-automatic"
 2139 version·=·"*"
2141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2146 include·install_dnf-automatic2145 include·install_dnf-automatic
  
Offset 9950, 19 lines modifiedOffset 9950, 14 lines modified
9950 ············Control·system·will·be·available.9950 ············Control·system·will·be·available.
9951 Severity: ··medium9951 Severity: ··medium
9952 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed9952 Rule·ID:····xccdf_org.ssgproject.content_rule_package_apparmor_installed
9953 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-0022359953 ············_\x8d_\x8i_\x8s_\x8a···CCI-001764,·CCI-001774,·CCI-002165,·CCI-002235
9954 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-9954 References:·_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000368-GPOS-00154,·SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-
9955 ···················000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-001559955 ···················000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000370-GPOS-00155
9956 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R459956 ············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
Max diff block lines reached; 25474/30651 bytes (83.11%) of diff not shown.
420 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_intermediary.html
    
Offset 15124, 146 lines modifiedOffset 15124, 146 lines modified
0003b130:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b130:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b140:·6d36·3336·3122·2074·6162·696e·6465·783d··m6361"·tabindex=0003b140:·6d36·3336·3122·2074·6162·696e·6465·783d··m6361"·tabindex=
0003b150:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b150:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b160:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b160:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b170:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b170:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b180:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b180:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b190:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b190:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b1a0:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild0003b1a0:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
0003b1b0:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp 
0003b1c0:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d 
0003b1d0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel- 
0003b1e0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps 
0003b1f0:·6522·2069·643d·2269·646d·3633·3631·223e··e"·id="idm6361">0003b1b0:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003b1c0:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b1d0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b1e0:·6170·7365·2220·6964·3d22·6964·6d36·3336··apse"·id="idm636
 0003b1f0:·3122·3e3c·7461·626c·6520·636c·6173·733d··1"><table·class=
 0003b200:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b210:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003b220:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003b230:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003b240:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003b250:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b260:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b270:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b280:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003b290:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003b2a0:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003b2b0:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b2c0:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003b2d0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
0003b200:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa0003b2e0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
0003b210:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003b220:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·=0003b2f0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003b300:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003b310:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003b320:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet·
 0003b330:·2d71·206b·6572·6e65·6c2d·6465·6661·756c··-q·kernel-defaul
 0003b340:·743b·2074·6865·6e0a·0a7a·7970·7065·7220··t;·then..zypper·
 0003b350:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003b360:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt;
 0003b370:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003b380:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003b390:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003b3a0:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
0003b230:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr0003b3b0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
0003b240:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class0003b3c0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
0003b250:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes0003b3d0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
0003b260:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="0003b3e0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
0003b270:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t0003b3f0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b280:·6172·6765·743d·2223·6964·6d36·3336·3222··arget="#idm6362"0003b400:·743d·2223·6964·6d36·3336·3222·2074·6162··t="#idm6362"·tab
0003b290:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003b410:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b2a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003b420:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b2b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003b430:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b2c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003b440:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b2d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003b450:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b2e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003b460:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
0003b2f0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·0003b470:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
 0003b480:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
 0003b490:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
 0003b4a0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
 0003b4b0:·643d·2269·646d·3633·3632·223e·3c74·6162··d="idm6362"><tab
 0003b4c0:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003b4d0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003b4e0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003b4f0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003b500:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003b510:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b520:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003b530:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003b540:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b550:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003b560:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003b570:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003b580:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003b590:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003b5a0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b5b0:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath
 0003b5c0:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f
 0003b5d0:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f
 0003b5e0:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage
 0003b5f0:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:.
 0003b600:·2020·2d20·4343·452d·3833·3238·392d·390a····-·CCE-83289-9.
 0003b610:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1.
 0003b620:·330a·2020·2d20·4449·5341·2d53·5449·472d··3.··-·DISA-STIG-
 0003b630:·534c·4553·2d31·352d·3031·3034·3139·0a20··SLES-15-010419.·
 0003b640:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
 0003b650:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D
 0003b660:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·
 0003b670:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2
 0003b680:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra
 0003b690:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com
 0003b6a0:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_
 0003b6b0:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m
 0003b6c0:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.·
 0003b6d0:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee
 0003b6e0:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_
 0003b6f0:·6169·6465·5f69·6e73·7461·6c6c·6564·0a0a··aide_installed..
 0003b700:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a
 0003b710:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed
 0003b720:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.····
 0003b730:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s
 0003b740:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
 0003b750:·7768·656e·3a20·2722·6b65·726e·656c·2d64··when:·'"kernel-d
 0003b760:·6566·6175·6c74·2220·696e·2061·6e73·6962··efault"·in·ansib
 0003b770:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package
 0003b780:·7327·0a20·2074·6167·733a·0a20·202d·2043··s'.··tags:.··-·C
 0003b790:·4345·2d38·3332·3839·2d39·0a20·202d·2043··CE-83289-9.··-·C
 0003b7a0:·4a49·532d·352e·3130·2e31·2e33·0a20·202d··JIS-5.10.1.3.··-
 0003b7b0:·2044·4953·412d·5354·4947·2d53·4c45·532d···DISA-STIG-SLES-
 0003b7c0:·3135·2d30·3130·3431·390a·2020·2d20·4e49··15-010419.··-·NI
 0003b7d0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a
 0003b7e0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re
 0003b7f0:·712d·3131·2e35·0a20·202d·2050·4349·2d44··q-11.5.··-·PCI-D
 0003b800:·5353·7634·2d31·312e·352e·320a·2020·2d20··SSv4-11.5.2.··-·
 0003b810:·656e·6162·6c65·5f73·7472·6174·6567·790a··enable_strategy.
 0003b820:·2020·2d20·6c6f·775f·636f·6d70·6c65·7869····-·low_complexi
 0003b830:·7479·0a20·202d·206c·6f77·5f64·6973·7275··ty.··-·low_disru
 0003b840:·7074·696f·6e0a·2020·2d20·6d65·6469·756d··ption.··-·medium
 0003b850:·5f73·6576·6572·6974·790a·2020·2d20·6e6f··_severity.··-·no
 0003b860:·5f72·6562·6f6f·745f·6e65·6564·6564·0a20··_reboot_needed.·
 0003b870:·202d·2070·6163·6b61·6765·5f61·6964·655f···-·package_aide_
 0003b880:·696e·7374·616c·6c65·640a·3c2f·636f·6465··installed.</code
 0003b890:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a·
 0003b8a0:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s
 0003b8b0:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog
 0003b8c0:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d
Max diff block lines reached; 391238/410034 bytes (95.42%) of diff not shown.
18.9 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 14 lines modified
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
125 ·············_\x8c_\x8i_\x8s············1.4.1125 ·············_\x8c_\x8i_\x8s············1.4.1
126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms134 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel-default;·then135 if·rpm·--quiet·-q·kernel-default;·then
Offset 180, 14 lines modifiedOffset 175, 19 lines modified
180 ··-·PCI-DSSv4-11.5.2175 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy176 ··-·enable_strategy
182 ··-·low_complexity177 ··-·low_complexity
183 ··-·low_disruption178 ··-·low_disruption
184 ··-·medium_severity179 ··-·medium_severity
185 ··-·no_reboot_needed180 ··-·no_reboot_needed
186 ··-·package_aide_installed181 ··-·package_aide_installed
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide191 include·install_aide
  
Offset 588, 19 lines modifiedOffset 588, 14 lines modified
588 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386588 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
589 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)589 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
590 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1590 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
591 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125591 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
592 ·············_\x8c_\x8i_\x8s·····1.3.1592 ·············_\x8c_\x8i_\x8s·····1.3.1
593 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33593 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
594 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2594 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
595 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
596 [[packages]] 
597 name·=·"sudo" 
598 version·=·"*" 
599 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8595 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
600 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low596 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
601 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low597 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
602 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false598 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
603 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable599 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
604 #·Remediation·is·applicable·only·in·certain·platforms600 #·Remediation·is·applicable·only·in·certain·platforms
605 if·rpm·--quiet·-q·kernel-default;·then601 if·rpm·--quiet·-q·kernel-default;·then
Offset 642, 14 lines modifiedOffset 637, 19 lines modified
642 ··-·PCI-DSSv4-2.2.6637 ··-·PCI-DSSv4-2.2.6
643 ··-·enable_strategy638 ··-·enable_strategy
644 ··-·low_complexity639 ··-·low_complexity
645 ··-·low_disruption640 ··-·low_disruption
646 ··-·medium_severity641 ··-·medium_severity
647 ··-·no_reboot_needed642 ··-·no_reboot_needed
648 ··-·package_sudo_installed643 ··-·package_sudo_installed
 644 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 645 [[packages]]
 646 name·=·"sudo"
 647 version·=·"*"
649 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8648 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
650 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low649 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
651 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low650 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
652 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false651 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
653 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable652 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
654 include·install_sudo653 include·install_sudo
  
Offset 1374, 19 lines modifiedOffset 1374, 14 lines modified
1374 ·············automatic,·regular·execution.1374 ·············automatic,·regular·execution.
1375 Severity: ···medium1375 Severity: ···medium
1376 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed1376 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
1377 Identifiers:·CCE-91163-61377 Identifiers:·CCE-91163-6
1378 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.21378 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
1379 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-000801379 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
1380 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R611380 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
1381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1382 [[packages]] 
1383 name·=·"dnf-automatic" 
1384 version·=·"*" 
1385 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81381 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1386 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1382 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1387 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1383 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1388 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1384 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1389 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1385 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1390 #·Remediation·is·applicable·only·in·certain·platforms1386 #·Remediation·is·applicable·only·in·certain·platforms
1391 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&1387 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-q·bootc·;}·&&
Offset 1425, 14 lines modifiedOffset 1420, 19 lines modified
1425 ··-·CCE-91163-61420 ··-·CCE-91163-6
1426 ··-·enable_strategy1421 ··-·enable_strategy
1427 ··-·low_complexity1422 ··-·low_complexity
1428 ··-·low_disruption1423 ··-·low_disruption
1429 ··-·medium_severity1424 ··-·medium_severity
1430 ··-·no_reboot_needed1425 ··-·no_reboot_needed
1431 ··-·package_dnf-automatic_installed1426 ··-·package_dnf-automatic_installed
 1427 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1428 [[packages]]
 1429 name·=·"dnf-automatic"
 1430 version·=·"*"
1432 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81431 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1433 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1432 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1434 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1433 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1435 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1434 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1436 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1435 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1437 include·install_dnf-automatic1436 include·install_dnf-automatic
  
Offset 9012, 17 lines modifiedOffset 9012, 14 lines modified
9012 Warning: ·Enabling·L1TF·mitigations·may·impact·performance·of·the·system.9012 Warning: ·Enabling·L1TF·mitigations·may·impact·performance·of·the·system.
9013 ············The·L1TF·vulnerability·allows·an·attacker·to·bypass·memory·access·security·controls9013 ············The·L1TF·vulnerability·allows·an·attacker·to·bypass·memory·access·security·controls
9014 Rationale:··imposed·by·the·system·or·hypervisor.·The·L1TF·vulnerability·allows·read·access·to·any9014 Rationale:··imposed·by·the·system·or·hypervisor.·The·L1TF·vulnerability·allows·read·access·to·any
9015 ············physical·memory·location·that·is·cached·in·the·L1·Data·Cache.9015 ············physical·memory·location·that·is·cached·in·the·L1·Data·Cache.
9016 Severity: ··high9016 Severity: ··high
9017 Rule·ID:····xccdf_org.ssgproject.content_rule_grub2_l1tf_argument9017 Rule·ID:····xccdf_org.ssgproject.content_rule_grub2_l1tf_argument
9018 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R89018 References:·_\x8a_\x8n_\x8s_\x8s_\x8i·R8
Max diff block lines reached; 14203/19371 bytes (73.32%) of diff not shown.
21.2 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-anssi_bp28_minimal.html
    
Offset 14800, 152 lines modifiedOffset 14800, 152 lines modified
00039cf0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm00039cf0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
00039d00:·3839·3136·2220·7461·6269·6e64·6578·3d22··8916"·tabindex="00039d00:·3839·3136·2220·7461·6269·6e64·6578·3d22··8916"·tabindex="
00039d10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"00039d10:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
00039d20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="00039d20:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
00039d30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac00039d30:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
00039d40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal00039d40:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
00039d50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme00039d50:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
00039d60:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·00039d60:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
00039d70:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
00039d80:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
00039d90:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
00039da0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
00039db0:·2220·6964·3d22·6964·6d38·3931·3622·3e3c··"·id="idm8916"><00039d70:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 00039d80:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 00039d90:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 00039da0:·7073·6522·2069·643d·2269·646d·3839·3136··pse"·id="idm8916
 00039db0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 00039dc0:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 00039dd0:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 00039de0:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 00039df0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 00039e00:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 00039e10:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 00039e20:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 00039e30:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 00039e40:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 00039e50:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 00039e60:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 00039e70:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 00039e80:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 00039e90:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
00039dc0:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac00039ea0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
00039dd0:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·"00039eb0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 00039ec0:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 00039ed0:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 00039ee0:·6966·2021·2028·207b·2072·706d·202d·2d71··if·!·(·{·rpm·--q
 00039ef0:·7569·6574·202d·7120·6b65·726e·656c·203b··uiet·-q·kernel·;
 00039f00:·7d20·2661·6d70·3b26·616d·703b·207b·2072··}·&amp;&amp;·{·r
 00039f10:·706d·202d·2d71·7569·6574·202d·7120·7270··pm·--quiet·-q·rp
 00039f20:·6d2d·6f73·7472·6565·203b·7d20·2661·6d70··m-ostree·;}·&amp
 00039f30:·3b26·616d·703b·207b·2072·706d·202d·2d71··;&amp;·{·rpm·--q
 00039f40:·7569·6574·202d·7120·626f·6f74·6320·3b7d··uiet·-q·bootc·;}
 00039f50:·2026·616d·703b·2661·6d70·3b20·7b20·2120···&amp;&amp;·{·!·
 00039f60:·7270·6d20·2d2d·7175·6965·7420·2d71·206f··rpm·--quiet·-q·o
 00039f70:·7065·6e73·6869·6674·2d6b·7562·656c·6574··penshift-kubelet
 00039f80:·203b·7d20·293b·2074·6865·6e0a·0a7a·7970···;}·);·then..zyp
 00039f90:·7065·7220·696e·7374·616c·6c20·2d79·2022··per·install·-y·"
00039de0:·646e·662d·6175·746f·6d61·7469·6322·0a76··dnf-automatic".v00039fa0:·646e·662d·6175·746f·6d61·7469·6322·0a0a··dnf-automatic"..
00039df0:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c 
00039e00:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div> 
00039e10:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt 
00039e20:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data- 
00039e30:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse 
00039e40:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="# 
00039e50:·6964·6d38·3931·3722·2074·6162·696e·6465··idm8917"·tabinde 
00039e60:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt 
00039e70:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande 
00039e80:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title= 
00039e90:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev 
00039ea0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R 
00039eb0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell 
00039ec0:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><00039fb0:·656c·7365·0a20·2020·2026·6774·3b26·616d··else.····&gt;&am
 00039fc0:·703b·3220·6563·686f·2027·5265·6d65·6469··p;2·echo·'Remedi
 00039fd0:·6174·696f·6e20·6973·206e·6f74·2061·7070··ation·is·not·app
 00039fe0:·6c69·6361·626c·652c·206e·6f74·6869·6e67··licable,·nothing
 00039ff0:·2077·6173·2064·6f6e·6527·0a66·690a·3c2f···was·done'.fi.</
 0003a000:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003a010:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003a020:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
 0003a030:·2d74·6f67·676c·653d·2263·6f6c·6c61·7073··-toggle="collaps
 0003a040:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
 0003a050:·2369·646d·3839·3137·2220·7461·6269·6e64··#idm8917"·tabind
 0003a060:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
 0003a070:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
 0003a080:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
 0003a090:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
 0003a0a0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
 0003a0b0:·5265·6d65·6469·6174·696f·6e20·416e·7369··Remediation·Ansi
 0003a0c0:·626c·6520·736e·6970·7065·7420·e287·b23c··ble·snippet·...<
00039ed0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p0003a0d0:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
00039ee0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co0003a0e0:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
00039ef0:·6c6c·6170·7365·2220·6964·3d22·6964·6d38··llapse"·id="idm80003a0f0:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
00039f00:·3931·3722·3e3c·7461·626c·6520·636c·6173··917"><table·clas0003a100:·6964·6d38·3931·3722·3e3c·7461·626c·6520··idm8917"><table·
00039f10:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s0003a110:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
00039f20:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor0003a120:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
00039f30:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond0003a130:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
00039f40:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C0003a140:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
00039f50:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><0003a150:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
00039f60:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>0003a160:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
00039f70:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti0003a170:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
00039f80:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<0003a180:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
00039f90:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th0003a190:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
00039fa0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td0003a1a0:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003a1b0:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003a1c0:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003a1d0:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
00039fb0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>0003a1e0:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
00039fc0:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy 
00039fd0:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable 
00039fe0:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl 
00039ff0:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R0003a1f0:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
 0003a200:·3e2d·206e·616d·653a·2047·6174·6865·7220··>-·name:·Gather·
 0003a210:·7468·6520·7061·636b·6167·6520·6661·6374··the·package·fact
 0003a220:·730a·2020·7061·636b·6167·655f·6661·6374··s.··package_fact
 0003a230:·733a·0a20·2020·206d·616e·6167·6572·3a20··s:.····manager:·
 0003a240:·6175·746f·0a20·2074·6167·733a·0a20·202d··auto.··tags:.··-
 0003a250:·2043·4345·2d39·3131·3633·2d36·0a20·202d···CCE-91163-6.··-
 0003a260:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy
 0003a270:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex
0003a000:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap 
0003a010:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in 
0003a020:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor 
0003a030:·6d73·0a69·6620·2120·2820·7b20·7270·6d20··ms.if·!·(·{·rpm· 
0003a040:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne 
0003a050:·6c20·3b7d·2026·616d·703b·2661·6d70·3b20··l·;}·&amp;&amp;· 
0003a060:·7b20·7270·6d20·2d2d·7175·6965·7420·2d71··{·rpm·--quiet·-q 
0003a070:·2072·706d·2d6f·7374·7265·6520·3b7d·2026···rpm-ostree·;}·& 
0003a080:·616d·703b·2661·6d70·3b20·7b20·7270·6d20··amp;&amp;·{·rpm· 
0003a090:·2d2d·7175·6965·7420·2d71·2062·6f6f·7463··--quiet·-q·bootc 
0003a0a0:·203b·7d20·2661·6d70·3b26·616d·703b·207b···;}·&amp;&amp;·{ 
0003a0b0:·2021·2072·706d·202d·2d71·7569·6574·202d···!·rpm·--quiet·- 
0003a0c0:·7120·6f70·656e·7368·6966·742d·6b75·6265··q·openshift-kube 
0003a0d0:·6c65·7420·3b7d·2029·3b20·7468·656e·0a0a··let·;}·);·then.. 
0003a0e0:·7a79·7070·6572·2069·6e73·7461·6c6c·202d··zypper·install·- 
0003a0f0:·7920·2264·6e66·2d61·7574·6f6d·6174·6963··y·"dnf-automatic 
0003a100:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt; 
0003a110:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem 
Max diff block lines reached; 414/20038 bytes (2.07%) of diff not shown.
1.51 KB
html2text {}
    
Offset 88, 19 lines modifiedOffset 88, 14 lines modified
88 ·············suitable·for·automatic,·regular·execution.88 ·············suitable·for·automatic,·regular·execution.
89 Severity: ···medium89 Severity: ···medium
90 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed90 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_dnf-automatic_installed
91 Identifiers:·CCE-91163-691 Identifiers:·CCE-91163-6
92 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.292 ·············_\x8o_\x8s_\x8p_\x8p···FPT_TUD_EXT.1,·FPT_TUD_EXT.2
93 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-0008093 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000191-GPOS-00080
94 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R6194 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R61
95 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
96 [[packages]] 
97 name·=·"dnf-automatic" 
98 version·=·"*" 
99 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x895 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
100 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low96 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
101 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low97 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
102 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false98 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
103 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable99 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
104 #·Remediation·is·applicable·only·in·certain·platforms100 #·Remediation·is·applicable·only·in·certain·platforms
105 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-101 if·!·(·{·rpm·--quiet·-q·kernel·;}·&&·{·rpm·--quiet·-q·rpm-ostree·;}·&&·{·rpm·--quiet·-
Offset 141, 14 lines modifiedOffset 136, 19 lines modified
141 ··-·CCE-91163-6136 ··-·CCE-91163-6
142 ··-·enable_strategy137 ··-·enable_strategy
143 ··-·low_complexity138 ··-·low_complexity
144 ··-·low_disruption139 ··-·low_disruption
145 ··-·medium_severity140 ··-·medium_severity
146 ··-·no_reboot_needed141 ··-·no_reboot_needed
147 ··-·package_dnf-automatic_installed142 ··-·package_dnf-automatic_installed
 143 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 144 [[packages]]
 145 name·=·"dnf-automatic"
 146 version·=·"*"
148 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8147 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
149 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low148 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
150 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low149 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
151 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false150 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
152 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable151 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
153 include·install_dnf-automatic152 include·install_dnf-automatic
  
1.04 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis.html
    
Offset 15170, 146 lines modifiedOffset 15170, 146 lines modified
0003b410:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i0003b410:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i
0003b420:·646d·3633·3631·2220·7461·6269·6e64·6578··dm6361"·tabindex0003b420:·646d·3633·3631·2220·7461·6269·6e64·6578··dm6361"·tabindex
0003b430:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto0003b430:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
0003b440:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded0003b440:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
0003b450:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="0003b450:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
0003b460:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve0003b460:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
0003b470:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re0003b470:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
0003b480:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil0003b480:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
0003b490:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
0003b4a0:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
0003b4b0:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
0003b4c0:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
0003b4d0:·7365·2220·6964·3d22·6964·6d36·3336·3122··se"·id="idm6361"0003b490:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
 0003b4a0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b4b0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b4c0:·6c61·7073·6522·2069·643d·2269·646d·3633··lapse"·id="idm63
 0003b4d0:·3631·223e·3c74·6162·6c65·2063·6c61·7373··61"><table·class
 0003b4e0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b4f0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b500:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b510:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b520:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b530:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b540:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b550:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b560:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b570:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b580:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b590:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b5a0:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b5b0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
0003b4e0:·3e3c·7072·653e·3c63·6f64·653e·0a5b·5b70··><pre><code>.[[p0003b5c0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re
0003b4f0:·6163·6b61·6765·735d·5d0a·6e61·6d65·203d··ackages]].name·= 
0003b500:·2022·6169·6465·220a·7665·7273·696f·6e20···"aide".version· 
0003b510:·3d20·222a·220a·3c2f·636f·6465·3e3c·2f70··=·"*".</code></p0003b5d0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app
 0003b5e0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in·
 0003b5f0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform
 0003b600:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet
 0003b610:·202d·7120·6b65·726e·656c·2d64·6566·6175···-q·kernel-defau
 0003b620:·6c74·3b20·7468·656e·0a0a·7a79·7070·6572··lt;·then..zypper
 0003b630:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid
 0003b640:·6522·0a0a·656c·7365·0a20·2020·2026·6774··e"..else.····&gt
 0003b650:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re
 0003b660:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not
 0003b670:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not
 0003b680:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f
 0003b690:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre><
0003b520:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas0003b6a0:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
0003b530:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe0003b6b0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"·
0003b540:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=0003b6c0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col
0003b550:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-0003b6d0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ
0003b560:·7461·7267·6574·3d22·2369·646d·3633·3632··target="#idm63620003b6e0:·6574·3d22·2369·646d·3633·3632·2220·7461··et="#idm6362"·ta
0003b570:·2220·7461·6269·6e64·6578·3d22·3022·2072··"·tabindex="0"·r0003b6f0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
0003b580:·6f6c·653d·2262·7574·746f·6e22·2061·7269··ole="button"·ari0003b700:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
0003b590:·612d·6578·7061·6e64·6564·3d22·6661·6c73··a-expanded="fals0003b710:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
0003b5a0:·6522·2074·6974·6c65·3d22·4163·7469·7661··e"·title="Activa0003b720:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
0003b5b0:·7465·2074·6f20·7265·7665·616c·2220·6872··te·to·reveal"·hr0003b730:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
0003b5c0:·6566·3d22·2321·223e·5265·6d65·6469·6174··ef="#!">Remediat0003b740:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
0003b5d0:·696f·6e20·5368·656c·6c20·7363·7269·7074··ion·Shell·script0003b750:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
 0003b760:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b770:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b780:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b790:·6964·3d22·6964·6d36·3336·3222·3e3c·7461··id="idm6362"><ta
 0003b7a0:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003b7b0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003b7c0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003b7d0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003b7e0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003b7f0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003b800:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b810:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b820:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b830:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003b840:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003b850:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b860:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003b870:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003b880:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b890:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat
 0003b8a0:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package·
 0003b8b0:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_
 0003b8c0:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag
 0003b8d0:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags:
 0003b8e0:·0a20·202d·2043·4345·2d38·3332·3839·2d39··.··-·CCE-83289-9
 0003b8f0:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1
 0003b900:·2e33·0a20·202d·2044·4953·412d·5354·4947··.3.··-·DISA-STIG
 0003b910:·2d53·4c45·532d·3135·2d30·3130·3431·390a··-SLES-15-010419.
 0003b920:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
 0003b930:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI-
 0003b940:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-
 0003b950:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.
 0003b960:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str
 0003b970:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co
 0003b980:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low
 0003b990:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
 0003b9a0:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.
 0003b9b0:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
 0003b9c0:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package
 0003b9d0:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed.
 0003b9e0:·0a2d·206e·616d·653a·2045·6e73·7572·6520··.-·name:·Ensure·
 0003b9f0:·6169·6465·2069·7320·696e·7374·616c·6c65··aide·is·installe
 0003ba00:·640a·2020·7061·636b·6167·653a·0a20·2020··d.··package:.···
 0003ba10:·206e·616d·653a·2061·6964·650a·2020·2020···name:·aide.····
 0003ba20:·7374·6174·653a·2070·7265·7365·6e74·0a20··state:·present.·
 0003ba30:·2077·6865·6e3a·2027·226b·6572·6e65·6c2d···when:·'"kernel-
 0003ba40:·6465·6661·756c·7422·2069·6e20·616e·7369··default"·in·ansi
 0003ba50:·626c·655f·6661·6374·732e·7061·636b·6167··ble_facts.packag
 0003ba60:·6573·270a·2020·7461·6773·3a0a·2020·2d20··es'.··tags:.··-·
 0003ba70:·4343·452d·3833·3238·392d·390a·2020·2d20··CCE-83289-9.··-·
 0003ba80:·434a·4953·2d35·2e31·302e·312e·330a·2020··CJIS-5.10.1.3.··
 0003ba90:·2d20·4449·5341·2d53·5449·472d·534c·4553··-·DISA-STIG-SLES
 0003baa0:·2d31·352d·3031·3034·3139·0a20·202d·204e··-15-010419.··-·N
 0003bab0:·4953·542d·3830·302d·3533·2d43·4d2d·3628··IST-800-53-CM-6(
 0003bac0:·6129·0a20·202d·2050·4349·2d44·5353·2d52··a).··-·PCI-DSS-R
 0003bad0:·6571·2d31·312e·350a·2020·2d20·5043·492d··eq-11.5.··-·PCI-
 0003bae0:·4453·5376·342d·3131·2e35·2e32·0a20·202d··DSSv4-11.5.2.··-
 0003baf0:·2065·6e61·626c·655f·7374·7261·7465·6779···enable_strategy
 0003bb00:·0a20·202d·206c·6f77·5f63·6f6d·706c·6578··.··-·low_complex
 0003bb10:·6974·790a·2020·2d20·6c6f·775f·6469·7372··ity.··-·low_disr
 0003bb20:·7570·7469·6f6e·0a20·202d·206d·6564·6975··uption.··-·mediu
 0003bb30:·6d5f·7365·7665·7269·7479·0a20·202d·206e··m_severity.··-·n
 0003bb40:·6f5f·7265·626f·6f74·5f6e·6565·6465·640a··o_reboot_needed.
 0003bb50:·2020·2d20·7061·636b·6167·655f·6169·6465····-·package_aide
 0003bb60:·5f69·6e73·7461·6c6c·6564·0a3c·2f63·6f64··_installed.</cod
 0003bb70:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003bb80:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003bb90:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
Max diff block lines reached; 1020320/1039116 bytes (98.19%) of diff not shown.
50.3 KB
html2text {}
    
Offset 128, 19 lines modifiedOffset 128, 14 lines modified
128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5128 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
129 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199129 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
130 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419130 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
131 ·············_\x8c_\x8i_\x8s············1.4.1131 ·············_\x8c_\x8i_\x8s············1.4.1
132 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79132 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
133 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2133 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
134 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule134 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
136 [[packages]] 
137 name·=·"aide" 
138 version·=·"*" 
139 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8135 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
140 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low136 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
141 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low137 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
142 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false138 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
143 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable139 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
144 #·Remediation·is·applicable·only·in·certain·platforms140 #·Remediation·is·applicable·only·in·certain·platforms
145 if·rpm·--quiet·-q·kernel-default;·then141 if·rpm·--quiet·-q·kernel-default;·then
Offset 186, 14 lines modifiedOffset 181, 19 lines modified
186 ··-·PCI-DSSv4-11.5.2181 ··-·PCI-DSSv4-11.5.2
187 ··-·enable_strategy182 ··-·enable_strategy
188 ··-·low_complexity183 ··-·low_complexity
189 ··-·low_disruption184 ··-·low_disruption
190 ··-·medium_severity185 ··-·medium_severity
191 ··-·no_reboot_needed186 ··-·no_reboot_needed
192 ··-·package_aide_installed187 ··-·package_aide_installed
 188 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 189 [[packages]]
 190 name·=·"aide"
 191 version·=·"*"
193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
198 include·install_aide197 include·install_aide
  
Offset 1067, 19 lines modifiedOffset 1067, 14 lines modified
1067 ·············_\x8i_\x8s_\x8m·····1382,·1384,·13861067 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1068 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1068 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1069 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11069 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1070 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251070 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1071 ·············_\x8c_\x8i_\x8s·····1.3.11071 ·············_\x8c_\x8i_\x8s·····1.3.1
1072 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R331072 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1073 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21073 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1074 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1075 [[packages]] 
1076 name·=·"sudo" 
1077 version·=·"*" 
1078 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81074 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1079 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1075 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1080 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1076 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1081 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1077 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1082 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1078 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1083 #·Remediation·is·applicable·only·in·certain·platforms1079 #·Remediation·is·applicable·only·in·certain·platforms
1084 if·rpm·--quiet·-q·kernel-default;·then1080 if·rpm·--quiet·-q·kernel-default;·then
Offset 1121, 14 lines modifiedOffset 1116, 19 lines modified
1121 ··-·PCI-DSSv4-2.2.61116 ··-·PCI-DSSv4-2.2.6
1122 ··-·enable_strategy1117 ··-·enable_strategy
1123 ··-·low_complexity1118 ··-·low_complexity
1124 ··-·low_disruption1119 ··-·low_disruption
1125 ··-·medium_severity1120 ··-·medium_severity
1126 ··-·no_reboot_needed1121 ··-·no_reboot_needed
1127 ··-·package_sudo_installed1122 ··-·package_sudo_installed
 1123 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1124 [[packages]]
 1125 name·=·"sudo"
 1126 version·=·"*"
1128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81127 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1128 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1129 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1130 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1131 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1133 include·install_sudo1132 include·install_sudo
  
Offset 9628, 19 lines modifiedOffset 9628, 14 lines modified
9628 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9628 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9629 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9629 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9630 ·····················002329630 ·····················00232
9631 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-0103909631 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
9632 ·············_\x8c_\x8i_\x8s·····1.7.1.19632 ·············_\x8c_\x8i_\x8s·····1.7.1.1
9633 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459633 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9634 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule9634 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
9635 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9636 [[packages]] 
9637 name·=·"pam_apparmor" 
9638 version·=·"*" 
9639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89635 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9640 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9636 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9641 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9637 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9642 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9638 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9643 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9639 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9644 #·Remediation·is·applicable·only·in·certain·platforms9640 #·Remediation·is·applicable·only·in·certain·platforms
9645 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9641 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 9672, 14 lines modifiedOffset 9667, 19 lines modified
9672 ··-·NIST-800-53-SC-7(21)9667 ··-·NIST-800-53-SC-7(21)
9673 ··-·enable_strategy9668 ··-·enable_strategy
9674 ··-·low_complexity9669 ··-·low_complexity
9675 ··-·low_disruption9670 ··-·low_disruption
9676 ··-·medium_severity9671 ··-·medium_severity
9677 ··-·no_reboot_needed9672 ··-·no_reboot_needed
9678 ··-·package_pam_apparmor_installed9673 ··-·package_pam_apparmor_installed
 9674 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9675 [[packages]]
 9676 name·=·"pam_apparmor"
 9677 version·=·"*"
9679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89678 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9680 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9679 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9681 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9680 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9682 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9681 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9683 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9682 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9684 include·install_pam_apparmor9683 include·install_pam_apparmor
  
Offset 10032, 18 lines modifiedOffset 10032, 14 lines modified
10032 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-10032 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
10033 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-10033 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
10034 ·····················0023210034 ·····················00232
10035 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-01039010035 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
10036 ·············_\x8c_\x8i_\x8s·····1.7.1.210036 ·············_\x8c_\x8i_\x8s·····1.7.1.2
10037 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R4510037 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
10038 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule10038 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
Max diff block lines reached; 46230/51451 bytes (89.85%) of diff not shown.
829 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis_server_l1.html
    
Offset 15148, 146 lines modifiedOffset 15148, 146 lines modified
0003b2b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b2b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b2c0:·2223·6964·6d36·3336·3122·2074·6162·696e··"#idm6361"·tabin0003b2c0:·2223·6964·6d36·3336·3122·2074·6162·696e··"#idm6361"·tabin
0003b2d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b2d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b2e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b2e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b2f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b2f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b300:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b300:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b310:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b310:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b320:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003b320:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
0003b330:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003b340:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b350:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b360:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b370:·6c61·7073·6522·2069·643d·2269·646d·3633··lapse"·id="idm630003b330:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003b340:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b350:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b360:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b370:·6d36·3336·3122·3e3c·7461·626c·6520·636c··m6361"><table·cl
 0003b380:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b390:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b3a0:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b3b0:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b3c0:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b3d0:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b3e0:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b3f0:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b400:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b410:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b420:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b430:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b440:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003b450:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003b380:·3631·223e·3c70·7265·3e3c·636f·6465·3e0a··61"><pre><code>.0003b460:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
0003b390:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003b3a0:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003b3b0:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>0003b470:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003b480:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003b490:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003b4a0:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 0003b4b0:·6965·7420·2d71·206b·6572·6e65·6c2d·6465··iet·-q·kernel-de
 0003b4c0:·6661·756c·743b·2074·6865·6e0a·0a7a·7970··fault;·then..zyp
 0003b4d0:·7065·7220·696e·7374·616c·6c20·2d79·2022··per·install·-y·"
 0003b4e0:·6169·6465·220a·0a65·6c73·650a·2020·2020··aide"..else.····
 0003b4f0:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003b500:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003b510:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003b520:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 0003b530:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003b3c0:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b540:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003b3d0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003b550:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003b3e0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003b560:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003b3f0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003b570:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003b400:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm60003b580:·6172·6765·743d·2223·6964·6d36·3336·3222··arget="#idm6362"
0003b410:·3336·3222·2074·6162·696e·6465·783d·2230··362"·tabindex="00003b590:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b420:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b5a0:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b430:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b5b0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b440:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b5c0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b450:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b5d0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b460:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b5e0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003b470:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr0003b5f0:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 0003b600:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b610:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b620:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b630:·6522·2069·643d·2269·646d·3633·3632·223e··e"·id="idm6362">
 0003b640:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b650:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b660:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b670:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b680:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b690:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b6a0:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b6b0:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b6c0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b6d0:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b6e0:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b6f0:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b700:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b710:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b720:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b730:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
 0003b740:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa
 0003b750:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa
 0003b760:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma
 0003b770:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta
 0003b780:·6773·3a0a·2020·2d20·4343·452d·3833·3238··gs:.··-·CCE-8328
 0003b790:·392d·390a·2020·2d20·434a·4953·2d35·2e31··9-9.··-·CJIS-5.1
 0003b7a0:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S
 0003b7b0:·5449·472d·534c·4553·2d31·352d·3031·3034··TIG-SLES-15-0104
 0003b7c0:·3139·0a20·202d·204e·4953·542d·3830·302d··19.··-·NIST-800-
 0003b7d0:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P
 0003b7e0:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5.
 0003b7f0:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11
 0003b800:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_
 0003b810:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
 0003b820:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
 0003b830:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
 0003b840:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
 0003b850:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
 0003b860:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack
 0003b870:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install
 0003b880:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu
 0003b890:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta
 0003b8a0:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:.
 0003b8b0:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.·
 0003b8c0:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen
 0003b8d0:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern
 0003b8e0:·656c·2d64·6566·6175·6c74·2220·696e·2061··el-default"·in·a
 0003b8f0:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
 0003b900:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.·
 0003b910:·202d·2043·4345·2d38·3332·3839·2d39·0a20···-·CCE-83289-9.·
 0003b920:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3
 0003b930:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
 0003b940:·4c45·532d·3135·2d30·3130·3431·390a·2020··LES-15-010419.··
 0003b950:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 0003b960:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
 0003b970:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
 0003b980:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
 0003b990:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
 0003b9a0:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp
 0003b9b0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
 0003b9c0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
 0003b9d0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
 0003b9e0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
 0003b9f0:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a
 0003ba00:·6964·655f·696e·7374·616c·6c65·640a·3c2f··ide_installed.</
 0003ba10:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003ba20:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003ba30:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
Max diff block lines reached; 788992/807788 bytes (97.67%) of diff not shown.
40.3 KB
html2text {}
    
Offset 125, 19 lines modifiedOffset 125, 14 lines modified
125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5125 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199126 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
127 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419127 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
128 ·············_\x8c_\x8i_\x8s············1.4.1128 ·············_\x8c_\x8i_\x8s············1.4.1
129 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79129 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
131 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule131 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
133 [[packages]] 
134 name·=·"aide" 
135 version·=·"*" 
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8132 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low133 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low134 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false135 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable136 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
141 #·Remediation·is·applicable·only·in·certain·platforms137 #·Remediation·is·applicable·only·in·certain·platforms
142 if·rpm·--quiet·-q·kernel-default;·then138 if·rpm·--quiet·-q·kernel-default;·then
Offset 183, 14 lines modifiedOffset 178, 19 lines modified
183 ··-·PCI-DSSv4-11.5.2178 ··-·PCI-DSSv4-11.5.2
184 ··-·enable_strategy179 ··-·enable_strategy
185 ··-·low_complexity180 ··-·low_complexity
186 ··-·low_disruption181 ··-·low_disruption
187 ··-·medium_severity182 ··-·medium_severity
188 ··-·no_reboot_needed183 ··-·no_reboot_needed
189 ··-·package_aide_installed184 ··-·package_aide_installed
 185 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 186 [[packages]]
 187 name·=·"aide"
 188 version·=·"*"
190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low190 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low191 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false192 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable193 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
195 include·install_aide194 include·install_aide
  
Offset 956, 19 lines modifiedOffset 956, 14 lines modified
956 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386956 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
957 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)957 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
958 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1958 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
959 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125959 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
960 ·············_\x8c_\x8i_\x8s·····1.3.1960 ·············_\x8c_\x8i_\x8s·····1.3.1
961 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33961 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
962 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2962 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
963 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
964 [[packages]] 
965 name·=·"sudo" 
966 version·=·"*" 
967 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8963 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
968 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low964 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
969 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low965 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
970 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false966 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
971 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable967 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
972 #·Remediation·is·applicable·only·in·certain·platforms968 #·Remediation·is·applicable·only·in·certain·platforms
973 if·rpm·--quiet·-q·kernel-default;·then969 if·rpm·--quiet·-q·kernel-default;·then
Offset 1010, 14 lines modifiedOffset 1005, 19 lines modified
1010 ··-·PCI-DSSv4-2.2.61005 ··-·PCI-DSSv4-2.2.6
1011 ··-·enable_strategy1006 ··-·enable_strategy
1012 ··-·low_complexity1007 ··-·low_complexity
1013 ··-·low_disruption1008 ··-·low_disruption
1014 ··-·medium_severity1009 ··-·medium_severity
1015 ··-·no_reboot_needed1010 ··-·no_reboot_needed
1016 ··-·package_sudo_installed1011 ··-·package_sudo_installed
 1012 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1013 [[packages]]
 1014 name·=·"sudo"
 1015 version·=·"*"
1017 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81016 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1018 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1017 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1019 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1018 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1020 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1019 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1021 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1020 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1022 include·install_sudo1021 include·install_sudo
  
Offset 9517, 19 lines modifiedOffset 9517, 14 lines modified
9517 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9517 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9518 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9518 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9519 ·····················002329519 ·····················00232
9520 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-0103909520 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
9521 ·············_\x8c_\x8i_\x8s·····1.7.1.19521 ·············_\x8c_\x8i_\x8s·····1.7.1.1
9522 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459522 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9523 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule9523 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
9524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9525 [[packages]] 
9526 name·=·"pam_apparmor" 
9527 version·=·"*" 
9528 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89524 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9529 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9525 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9530 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9526 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9531 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9527 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9532 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9528 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9533 #·Remediation·is·applicable·only·in·certain·platforms9529 #·Remediation·is·applicable·only·in·certain·platforms
9534 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9530 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 9561, 14 lines modifiedOffset 9556, 19 lines modified
9561 ··-·NIST-800-53-SC-7(21)9556 ··-·NIST-800-53-SC-7(21)
9562 ··-·enable_strategy9557 ··-·enable_strategy
9563 ··-·low_complexity9558 ··-·low_complexity
9564 ··-·low_disruption9559 ··-·low_disruption
9565 ··-·medium_severity9560 ··-·medium_severity
9566 ··-·no_reboot_needed9561 ··-·no_reboot_needed
9567 ··-·package_pam_apparmor_installed9562 ··-·package_pam_apparmor_installed
 9563 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9564 [[packages]]
 9565 name·=·"pam_apparmor"
 9566 version·=·"*"
9568 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89567 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9569 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9568 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9570 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9569 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9571 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9570 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9572 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9571 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9573 include·install_pam_apparmor9572 include·install_pam_apparmor
  
Offset 9789, 18 lines modifiedOffset 9789, 14 lines modified
9789 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9789 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9790 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9790 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9791 ·····················002329791 ·····················00232
9792 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-0103909792 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
9793 ·············_\x8c_\x8i_\x8s·····1.7.1.29793 ·············_\x8c_\x8i_\x8s·····1.7.1.2
9794 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459794 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9795 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule9795 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
Max diff block lines reached; 36066/41283 bytes (87.36%) of diff not shown.
698 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis_workstation_l1.html
    
Offset 15134, 146 lines modifiedOffset 15134, 146 lines modified
0003b1d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe0003b1d0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
0003b1e0:·743d·2223·6964·6d36·3336·3122·2074·6162··t="#idm6361"·tab0003b1e0:·743d·2223·6964·6d36·3336·3122·2074·6162··t="#idm6361"·tab
0003b1f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="0003b1f0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
0003b200:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp0003b200:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
0003b210:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti0003b210:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
0003b220:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to0003b220:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
0003b230:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#0003b230:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
0003b240:·2122·3e52·656d·6564·6961·7469·6f6e·204f··!">Remediation·O0003b240:·2122·3e52·656d·6564·6961·7469·6f6e·2053··!">Remediation·S
0003b250:·5342·7569·6c64·2042·6c75·6570·7269·6e74··SBuild·Blueprint 
0003b260:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a> 
0003b270:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class=" 
0003b280:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c 
0003b290:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm0003b250:·6865·6c6c·2073·6372·6970·7420·e287·b23c··hell·script·...<
 0003b260:·2f61·3e3c·6272·3e3c·6469·7620·636c·6173··/a><br><div·clas
 0003b270:·733d·2270·616e·656c·2d63·6f6c·6c61·7073··s="panel-collaps
 0003b280:·6520·636f·6c6c·6170·7365·2220·6964·3d22··e·collapse"·id="
 0003b290:·6964·6d36·3336·3122·3e3c·7461·626c·6520··idm6361"><table·
 0003b2a0:·636c·6173·733d·2274·6162·6c65·2074·6162··class="table·tab
 0003b2b0:·6c65·2d73·7472·6970·6564·2074·6162·6c65··le-striped·table
 0003b2c0:·2d62·6f72·6465·7265·6420·7461·626c·652d··-bordered·table-
 0003b2d0:·636f·6e64·656e·7365·6422·3e3c·7472·3e3c··condensed"><tr><
 0003b2e0:·7468·3e43·6f6d·706c·6578·6974·793a·3c2f··th>Complexity:</
 0003b2f0:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b300:·2f74·723e·3c74·723e·3c74·683e·4469·7372··/tr><tr><th>Disr
 0003b310:·7570·7469·6f6e·3a3c·2f74·683e·3c74·643e··uption:</th><td>
 0003b320:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b330:·3e3c·7468·3e52·6562·6f6f·743a·3c2f·7468··><th>Reboot:</th
 0003b340:·3e3c·7464·3e66·616c·7365·3c2f·7464·3e3c··><td>false</td><
 0003b350:·2f74·723e·3c74·723e·3c74·683e·5374·7261··/tr><tr><th>Stra
 0003b360:·7465·6779·3a3c·2f74·683e·3c74·643e·656e··tegy:</th><td>en
 0003b370:·6162·6c65·3c2f·7464·3e3c·2f74·723e·3c2f··able</td></tr></
0003b2a0:·3633·3631·223e·3c70·7265·3e3c·636f·6465··6361"><pre><code0003b380:·7461·626c·653e·3c70·7265·3e3c·636f·6465··table><pre><code
0003b2b0:·3e0a·5b5b·7061·636b·6167·6573·5d5d·0a6e··>.[[packages]].n 
0003b2c0:·616d·6520·3d20·2261·6964·6522·0a76·6572··ame·=·"aide".ver 
0003b2d0:·7369·6f6e·203d·2022·2a22·0a3c·2f63·6f64··sion·=·"*".</cod0003b390:·3e23·2052·656d·6564·6961·7469·6f6e·2069··>#·Remediation·i
 0003b3a0:·7320·6170·706c·6963·6162·6c65·206f·6e6c··s·applicable·onl
 0003b3b0:·7920·696e·2063·6572·7461·696e·2070·6c61··y·in·certain·pla
 0003b3c0:·7466·6f72·6d73·0a69·6620·7270·6d20·2d2d··tforms.if·rpm·--
 0003b3d0:·7175·6965·7420·2d71·206b·6572·6e65·6c2d··quiet·-q·kernel-
 0003b3e0:·6465·6661·756c·743b·2074·6865·6e0a·0a7a··default;·then..z
 0003b3f0:·7970·7065·7220·696e·7374·616c·6c20·2d79··ypper·install·-y
 0003b400:·2022·6169·6465·220a·0a65·6c73·650a·2020···"aide"..else.··
 0003b410:·2020·2667·743b·2661·6d70·3b32·2065·6368····&gt;&amp;2·ech
 0003b420:·6f20·2752·656d·6564·6961·7469·6f6e·2069··o·'Remediation·i
 0003b430:·7320·6e6f·7420·6170·706c·6963·6162·6c65··s·not·applicable
 0003b440:·2c20·6e6f·7468·696e·6720·7761·7320·646f··,·nothing·was·do
 0003b450:·6e65·270a·6669·0a3c·2f63·6f64·653e·3c2f··ne'.fi.</code></
0003b2e0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a0003b460:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla
0003b2f0:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-0003b470:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ
0003b300:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to0003b480:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle
0003b310:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·0003b490:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data
0003b320:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b4a0:·2d74·6172·6765·743d·2223·6964·6d36·3336··-target="#idm636
0003b330:·6d36·3336·3222·2074·6162·696e·6465·783d··m6362"·tabindex=0003b4b0:·3222·2074·6162·696e·6465·783d·2230·2220··2"·tabindex="0"·
0003b340:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b4c0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0003b350:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b4d0:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0003b360:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b4e0:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0003b370:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b4f0:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0003b380:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b500:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0003b390:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s0003b510:·7469·6f6e·2041·6e73·6962·6c65·2073·6e69··tion·Ansible·sni
 0003b520:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br>
 0003b530:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b540:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b550:·7073·6522·2069·643d·2269·646d·3633·3632··pse"·id="idm6362
 0003b560:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b570:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b580:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b590:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b5a0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b5b0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b5c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b5d0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b5e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b5f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b600:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b610:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b620:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b630:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b640:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
 0003b650:·7072·653e·3c63·6f64·653e·2d20·6e61·6d65··pre><code>-·name
 0003b660:·3a20·4761·7468·6572·2074·6865·2070·6163··:·Gather·the·pac
 0003b670:·6b61·6765·2066·6163·7473·0a20·2070·6163··kage·facts.··pac
 0003b680:·6b61·6765·5f66·6163·7473·3a0a·2020·2020··kage_facts:.····
 0003b690:·6d61·6e61·6765·723a·2061·7574·6f0a·2020··manager:·auto.··
 0003b6a0:·7461·6773·3a0a·2020·2d20·4343·452d·3833··tags:.··-·CCE-83
 0003b6b0:·3238·392d·390a·2020·2d20·434a·4953·2d35··289-9.··-·CJIS-5
 0003b6c0:·2e31·302e·312e·330a·2020·2d20·4449·5341··.10.1.3.··-·DISA
 0003b6d0:·2d53·5449·472d·534c·4553·2d31·352d·3031··-STIG-SLES-15-01
 0003b6e0:·3034·3139·0a20·202d·204e·4953·542d·3830··0419.··-·NIST-80
 0003b6f0:·302d·3533·2d43·4d2d·3628·6129·0a20·202d··0-53-CM-6(a).··-
 0003b700:·2050·4349·2d44·5353·2d52·6571·2d31·312e···PCI-DSS-Req-11.
 0003b710:·350a·2020·2d20·5043·492d·4453·5376·342d··5.··-·PCI-DSSv4-
 0003b720:·3131·2e35·2e32·0a20·202d·2065·6e61·626c··11.5.2.··-·enabl
 0003b730:·655f·7374·7261·7465·6779·0a20·202d·206c··e_strategy.··-·l
 0003b740:·6f77·5f63·6f6d·706c·6578·6974·790a·2020··ow_complexity.··
 0003b750:·2d20·6c6f·775f·6469·7372·7570·7469·6f6e··-·low_disruption
 0003b760:·0a20·202d·206d·6564·6975·6d5f·7365·7665··.··-·medium_seve
 0003b770:·7269·7479·0a20·202d·206e·6f5f·7265·626f··rity.··-·no_rebo
 0003b780:·6f74·5f6e·6565·6465·640a·2020·2d20·7061··ot_needed.··-·pa
 0003b790:·636b·6167·655f·6169·6465·5f69·6e73·7461··ckage_aide_insta
 0003b7a0:·6c6c·6564·0a0a·2d20·6e61·6d65·3a20·456e··lled..-·name:·En
 0003b7b0:·7375·7265·2061·6964·6520·6973·2069·6e73··sure·aide·is·ins
 0003b7c0:·7461·6c6c·6564·0a20·2070·6163·6b61·6765··talled.··package
 0003b7d0:·3a0a·2020·2020·6e61·6d65·3a20·6169·6465··:.····name:·aide
 0003b7e0:·0a20·2020·2073·7461·7465·3a20·7072·6573··.····state:·pres
 0003b7f0:·656e·740a·2020·7768·656e·3a20·2722·6b65··ent.··when:·'"ke
 0003b800:·726e·656c·2d64·6566·6175·6c74·2220·696e··rnel-default"·in
 0003b810:·2061·6e73·6962·6c65·5f66·6163·7473·2e70···ansible_facts.p
 0003b820:·6163·6b61·6765·7327·0a20·2074·6167·733a··ackages'.··tags:
 0003b830:·0a20·202d·2043·4345·2d38·3332·3839·2d39··.··-·CCE-83289-9
 0003b840:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1
 0003b850:·2e33·0a20·202d·2044·4953·412d·5354·4947··.3.··-·DISA-STIG
 0003b860:·2d53·4c45·532d·3135·2d30·3130·3431·390a··-SLES-15-010419.
 0003b870:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53-
 0003b880:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI-
 0003b890:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··-
 0003b8a0:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5.
 0003b8b0:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str
 0003b8c0:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co
 0003b8d0:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low
 0003b8e0:·5f64·6973·7275·7074·696f·6e0a·2020·2d20··_disruption.··-·
 0003b8f0:·6d65·6469·756d·5f73·6576·6572·6974·790a··medium_severity.
 0003b900:·2020·2d20·6e6f·5f72·6562·6f6f·745f·6e65····-·no_reboot_ne
 0003b910:·6564·6564·0a20·202d·2070·6163·6b61·6765··eded.··-·package
 0003b920:·5f61·6964·655f·696e·7374·616c·6c65·640a··_aide_installed.
 0003b930:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
 0003b940:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
 0003b950:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
Max diff block lines reached; 659182/677978 bytes (97.23%) of diff not shown.
35.4 KB
html2text {}
    
Offset 122, 19 lines modifiedOffset 122, 14 lines modified
122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5122 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199123 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419124 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
125 ·············_\x8c_\x8i_\x8s············1.4.1125 ·············_\x8c_\x8i_\x8s············1.4.1
126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79126 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule128 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
130 [[packages]] 
131 name·=·"aide" 
132 version·=·"*" 
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8129 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low130 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low131 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false132 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable133 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
138 #·Remediation·is·applicable·only·in·certain·platforms134 #·Remediation·is·applicable·only·in·certain·platforms
139 if·rpm·--quiet·-q·kernel-default;·then135 if·rpm·--quiet·-q·kernel-default;·then
Offset 180, 14 lines modifiedOffset 175, 19 lines modified
180 ··-·PCI-DSSv4-11.5.2175 ··-·PCI-DSSv4-11.5.2
181 ··-·enable_strategy176 ··-·enable_strategy
182 ··-·low_complexity177 ··-·low_complexity
183 ··-·low_disruption178 ··-·low_disruption
184 ··-·medium_severity179 ··-·medium_severity
185 ··-·no_reboot_needed180 ··-·no_reboot_needed
186 ··-·package_aide_installed181 ··-·package_aide_installed
 182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 183 [[packages]]
 184 name·=·"aide"
 185 version·=·"*"
187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
188 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low187 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
189 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low188 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
190 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false189 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
191 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable190 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
192 include·install_aide191 include·install_aide
  
Offset 953, 19 lines modifiedOffset 953, 14 lines modified
953 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386953 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
954 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)954 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
955 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1955 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
956 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125956 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
957 ·············_\x8c_\x8i_\x8s·····1.3.1957 ·············_\x8c_\x8i_\x8s·····1.3.1
958 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33958 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
959 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2959 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
960 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
961 [[packages]] 
962 name·=·"sudo" 
963 version·=·"*" 
964 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8960 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
965 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low961 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
966 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low962 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
967 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false963 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
968 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable964 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
969 #·Remediation·is·applicable·only·in·certain·platforms965 #·Remediation·is·applicable·only·in·certain·platforms
970 if·rpm·--quiet·-q·kernel-default;·then966 if·rpm·--quiet·-q·kernel-default;·then
Offset 1007, 14 lines modifiedOffset 1002, 19 lines modified
1007 ··-·PCI-DSSv4-2.2.61002 ··-·PCI-DSSv4-2.2.6
1008 ··-·enable_strategy1003 ··-·enable_strategy
1009 ··-·low_complexity1004 ··-·low_complexity
1010 ··-·low_disruption1005 ··-·low_disruption
1011 ··-·medium_severity1006 ··-·medium_severity
1012 ··-·no_reboot_needed1007 ··-·no_reboot_needed
1013 ··-·package_sudo_installed1008 ··-·package_sudo_installed
 1009 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1010 [[packages]]
 1011 name·=·"sudo"
 1012 version·=·"*"
1014 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81013 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1015 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1014 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1016 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1015 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1017 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1016 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1018 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1017 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1019 include·install_sudo1018 include·install_sudo
  
Offset 9514, 19 lines modifiedOffset 9514, 14 lines modified
9514 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9514 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9515 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9515 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9516 ·····················002329516 ·····················00232
9517 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-0103909517 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
9518 ·············_\x8c_\x8i_\x8s·····1.7.1.19518 ·············_\x8c_\x8i_\x8s·····1.7.1.1
9519 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459519 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9520 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule9520 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
9521 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9522 [[packages]] 
9523 name·=·"pam_apparmor" 
9524 version·=·"*" 
9525 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89521 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9526 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9522 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9527 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9523 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9528 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9524 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9529 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9525 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9530 #·Remediation·is·applicable·only·in·certain·platforms9526 #·Remediation·is·applicable·only·in·certain·platforms
9531 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9527 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 9558, 14 lines modifiedOffset 9553, 19 lines modified
9558 ··-·NIST-800-53-SC-7(21)9553 ··-·NIST-800-53-SC-7(21)
9559 ··-·enable_strategy9554 ··-·enable_strategy
9560 ··-·low_complexity9555 ··-·low_complexity
9561 ··-·low_disruption9556 ··-·low_disruption
9562 ··-·medium_severity9557 ··-·medium_severity
9563 ··-·no_reboot_needed9558 ··-·no_reboot_needed
9564 ··-·package_pam_apparmor_installed9559 ··-·package_pam_apparmor_installed
 9560 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9561 [[packages]]
 9562 name·=·"pam_apparmor"
 9563 version·=·"*"
9565 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89564 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9566 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9565 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9567 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9566 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9568 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9567 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9569 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9568 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9570 include·install_pam_apparmor9569 include·install_pam_apparmor
  
Offset 9786, 18 lines modifiedOffset 9786, 14 lines modified
9786 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9786 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9787 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9787 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9788 ·····················002329788 ·····················00232
9789 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-0103909789 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
9790 ·············_\x8c_\x8i_\x8s·····1.7.1.29790 ·············_\x8c_\x8i_\x8s·····1.7.1.2
9791 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459791 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9792 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule9792 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
Max diff block lines reached; 30977/36194 bytes (85.59%) of diff not shown.
1.0 MB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-cis_workstation_l2.html
    
Offset 15161, 146 lines modifiedOffset 15161, 146 lines modified
0003b380:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="0003b380:·6522·2064·6174·612d·7461·7267·6574·3d22··e"·data-target="
0003b390:·2369·646d·3633·3631·2220·7461·6269·6e64··#idm6361"·tabind0003b390:·2369·646d·3633·3631·2220·7461·6269·6e64··#idm6361"·tabind
0003b3a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but0003b3a0:·6578·3d22·3022·2072·6f6c·653d·2262·7574··ex="0"·role="but
0003b3b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand0003b3b0:·746f·6e22·2061·7269·612d·6578·7061·6e64··ton"·aria-expand
0003b3c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title0003b3c0:·6564·3d22·6661·6c73·6522·2074·6974·6c65··ed="false"·title
0003b3d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re0003b3d0:·3d22·4163·7469·7661·7465·2074·6f20·7265··="Activate·to·re
0003b3e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">0003b3e0:·7665·616c·2220·6872·6566·3d22·2321·223e··veal"·href="#!">
0003b3f0:·5265·6d65·6469·6174·696f·6e20·4f53·4275··Remediation·OSBu0003b3f0:·5265·6d65·6469·6174·696f·6e20·5368·656c··Remediation·Shel
0003b400:·696c·6420·426c·7565·7072·696e·7420·736e··ild·Blueprint·sn 
0003b410:·6970·7065·7420·e287·b23c·2f61·3e3c·6272··ippet·...</a><br 
0003b420:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan 
0003b430:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll 
0003b440:·6170·7365·2220·6964·3d22·6964·6d36·3336··apse"·id="idm6360003b400:·6c20·7363·7269·7074·20e2·87b2·3c2f·613e··l·script·...</a>
 0003b410:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
 0003b420:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
 0003b430:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
 0003b440:·3633·3631·223e·3c74·6162·6c65·2063·6c61··6361"><table·cla
 0003b450:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b460:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b470:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b480:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b490:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b4a0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b4b0:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b4c0:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b4d0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b4e0:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003b4f0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b500:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b510:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003b520:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
0003b450:·3122·3e3c·7072·653e·3c63·6f64·653e·0a5b··1"><pre><code>.[0003b530:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
0003b460:·5b70·6163·6b61·6765·735d·5d0a·6e61·6d65··[packages]].name 
0003b470:·203d·2022·6169·6465·220a·7665·7273·696f···=·"aide".versio 
0003b480:·6e20·3d20·222a·220a·3c2f·636f·6465·3e3c··n·=·"*".</code><0003b540:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 0003b550:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 0003b560:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 0003b570:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 0003b580:·6574·202d·7120·6b65·726e·656c·2d64·6566··et·-q·kernel-def
 0003b590:·6175·6c74·3b20·7468·656e·0a0a·7a79·7070··ault;·then..zypp
 0003b5a0:·6572·2069·6e73·7461·6c6c·202d·7920·2261··er·install·-y·"a
 0003b5b0:·6964·6522·0a0a·656c·7365·0a20·2020·2026··ide"..else.····&
 0003b5c0:·6774·3b26·616d·703b·3220·6563·686f·2027··gt;&amp;2·echo·'
 0003b5d0:·5265·6d65·6469·6174·696f·6e20·6973·206e··Remediation·is·n
 0003b5e0:·6f74·2061·7070·6c69·6361·626c·652c·206e··ot·applicable,·n
 0003b5f0:·6f74·6869·6e67·2077·6173·2064·6f6e·6527··othing·was·done'
 0003b600:·0a66·690a·3c2f·636f·6465·3e3c·2f70·7265··.fi.</code></pre
0003b490:·2f70·7265·3e3c·2f64·6976·3e3c·6120·636c··/pre></div><a·cl0003b610:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=
0003b4a0:·6173·733d·2262·746e·2062·746e·2d73·7563··ass="btn·btn-suc0003b620:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success
0003b4b0:·6365·7373·2220·6461·7461·2d74·6f67·676c··cess"·data-toggl0003b630:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c
0003b4c0:·653d·2263·6f6c·6c61·7073·6522·2064·6174··e="collapse"·dat0003b640:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta
0003b4d0:·612d·7461·7267·6574·3d22·2369·646d·3633··a-target="#idm630003b650:·7267·6574·3d22·2369·646d·3633·3632·2220··rget="#idm6362"·
0003b4e0:·3632·2220·7461·6269·6e64·6578·3d22·3022··62"·tabindex="0"0003b660:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol
0003b4f0:·2072·6f6c·653d·2262·7574·746f·6e22·2061···role="button"·a0003b670:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-
0003b500:·7269·612d·6578·7061·6e64·6564·3d22·6661··ria-expanded="fa0003b680:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"
0003b510:·6c73·6522·2074·6974·6c65·3d22·4163·7469··lse"·title="Acti0003b690:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate
0003b520:·7661·7465·2074·6f20·7265·7665·616c·2220··vate·to·reveal"·0003b6a0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href
0003b530:·6872·6566·3d22·2321·223e·5265·6d65·6469··href="#!">Remedi0003b6b0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio
0003b540:·6174·696f·6e20·5368·656c·6c20·7363·7269··ation·Shell·scri0003b6c0:·6e20·416e·7369·626c·6520·736e·6970·7065··n·Ansible·snippe
 0003b6d0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0003b6e0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0003b6f0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0003b700:·2220·6964·3d22·6964·6d36·3336·3222·3e3c··"·id="idm6362"><
 0003b710:·7461·626c·6520·636c·6173·733d·2274·6162··table·class="tab
 0003b720:·6c65·2074·6162·6c65·2d73·7472·6970·6564··le·table-striped
 0003b730:·2074·6162·6c65·2d62·6f72·6465·7265·6420···table-bordered·
 0003b740:·7461·626c·652d·636f·6e64·656e·7365·6422··table-condensed"
 0003b750:·3e3c·7472·3e3c·7468·3e43·6f6d·706c·6578··><tr><th>Complex
 0003b760:·6974·793a·3c2f·7468·3e3c·7464·3e6c·6f77··ity:</th><td>low
 0003b770:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b780:·683e·4469·7372·7570·7469·6f6e·3a3c·2f74··h>Disruption:</t
 0003b790:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b7a0:·7472·3e3c·7472·3e3c·7468·3e52·6562·6f6f··tr><tr><th>Reboo
 0003b7b0:·743a·3c2f·7468·3e3c·7464·3e66·616c·7365··t:</th><td>false
 0003b7c0:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b7d0:·683e·5374·7261·7465·6779·3a3c·2f74·683e··h>Strategy:</th>
 0003b7e0:·3c74·643e·656e·6162·6c65·3c2f·7464·3e3c··<td>enable</td><
 0003b7f0:·2f74·723e·3c2f·7461·626c·653e·3c70·7265··/tr></table><pre
 0003b800:·3e3c·636f·6465·3e2d·206e·616d·653a·2047··><code>-·name:·G
 0003b810:·6174·6865·7220·7468·6520·7061·636b·6167··ather·the·packag
 0003b820:·6520·6661·6374·730a·2020·7061·636b·6167··e·facts.··packag
 0003b830:·655f·6661·6374·733a·0a20·2020·206d·616e··e_facts:.····man
 0003b840:·6167·6572·3a20·6175·746f·0a20·2074·6167··ager:·auto.··tag
 0003b850:·733a·0a20·202d·2043·4345·2d38·3332·3839··s:.··-·CCE-83289
 0003b860:·2d39·0a20·202d·2043·4a49·532d·352e·3130··-9.··-·CJIS-5.10
 0003b870:·2e31·2e33·0a20·202d·2044·4953·412d·5354··.1.3.··-·DISA-ST
 0003b880:·4947·2d53·4c45·532d·3135·2d30·3130·3431··IG-SLES-15-01041
 0003b890:·390a·2020·2d20·4e49·5354·2d38·3030·2d35··9.··-·NIST-800-5
 0003b8a0:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC
 0003b8b0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
 0003b8c0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
 0003b8d0:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s
 0003b8e0:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_
 0003b8f0:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l
 0003b900:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··
 0003b910:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
 0003b920:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
 0003b930:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa
 0003b940:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe
 0003b950:·640a·0a2d·206e·616d·653a·2045·6e73·7572··d..-·name:·Ensur
 0003b960:·6520·6169·6465·2069·7320·696e·7374·616c··e·aide·is·instal
 0003b970:·6c65·640a·2020·7061·636b·6167·653a·0a20··led.··package:.·
 0003b980:·2020·206e·616d·653a·2061·6964·650a·2020·····name:·aide.··
 0003b990:·2020·7374·6174·653a·2070·7265·7365·6e74····state:·present
 0003b9a0:·0a20·2077·6865·6e3a·2027·226b·6572·6e65··.··when:·'"kerne
 0003b9b0:·6c2d·6465·6661·756c·7422·2069·6e20·616e··l-default"·in·an
 0003b9c0:·7369·626c·655f·6661·6374·732e·7061·636b··sible_facts.pack
 0003b9d0:·6167·6573·270a·2020·7461·6773·3a0a·2020··ages'.··tags:.··
 0003b9e0:·2d20·4343·452d·3833·3238·392d·390a·2020··-·CCE-83289-9.··
 0003b9f0:·2d20·434a·4953·2d35·2e31·302e·312e·330a··-·CJIS-5.10.1.3.
 0003ba00:·2020·2d20·4449·5341·2d53·5449·472d·534c····-·DISA-STIG-SL
 0003ba10:·4553·2d31·352d·3031·3034·3139·0a20·202d··ES-15-010419.··-
 0003ba20:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
 0003ba30:·3628·6129·0a20·202d·2050·4349·2d44·5353··6(a).··-·PCI-DSS
 0003ba40:·2d52·6571·2d31·312e·350a·2020·2d20·5043··-Req-11.5.··-·PC
 0003ba50:·492d·4453·5376·342d·3131·2e35·2e32·0a20··I-DSSv4-11.5.2.·
 0003ba60:·202d·2065·6e61·626c·655f·7374·7261·7465···-·enable_strate
 0003ba70:·6779·0a20·202d·206c·6f77·5f63·6f6d·706c··gy.··-·low_compl
 0003ba80:·6578·6974·790a·2020·2d20·6c6f·775f·6469··exity.··-·low_di
 0003ba90:·7372·7570·7469·6f6e·0a20·202d·206d·6564··sruption.··-·med
 0003baa0:·6975·6d5f·7365·7665·7269·7479·0a20·202d··ium_severity.··-
 0003bab0:·206e·6f5f·7265·626f·6f74·5f6e·6565·6465···no_reboot_neede
 0003bac0:·640a·2020·2d20·7061·636b·6167·655f·6169··d.··-·package_ai
 0003bad0:·6465·5f69·6e73·7461·6c6c·6564·0a3c·2f63··de_installed.</c
 0003bae0:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>
 0003baf0:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt
 0003bb00:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-
Max diff block lines reached; 980546/999342 bytes (98.12%) of diff not shown.
48.6 KB
html2text {}
    
Offset 126, 19 lines modifiedOffset 126, 14 lines modified
126 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5126 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
127 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199127 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
128 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419128 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
129 ·············_\x8c_\x8i_\x8s············1.4.1129 ·············_\x8c_\x8i_\x8s············1.4.1
130 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79130 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
132 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule132 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
134 [[packages]] 
135 name·=·"aide" 
136 version·=·"*" 
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8133 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low134 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low135 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false136 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable137 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
142 #·Remediation·is·applicable·only·in·certain·platforms138 #·Remediation·is·applicable·only·in·certain·platforms
143 if·rpm·--quiet·-q·kernel-default;·then139 if·rpm·--quiet·-q·kernel-default;·then
Offset 184, 14 lines modifiedOffset 179, 19 lines modified
184 ··-·PCI-DSSv4-11.5.2179 ··-·PCI-DSSv4-11.5.2
185 ··-·enable_strategy180 ··-·enable_strategy
186 ··-·low_complexity181 ··-·low_complexity
187 ··-·low_disruption182 ··-·low_disruption
188 ··-·medium_severity183 ··-·medium_severity
189 ··-·no_reboot_needed184 ··-·no_reboot_needed
190 ··-·package_aide_installed185 ··-·package_aide_installed
 186 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 187 [[packages]]
 188 name·=·"aide"
 189 version·=·"*"
191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low191 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low192 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false193 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable194 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
196 include·install_aide195 include·install_aide
  
Offset 1065, 19 lines modifiedOffset 1065, 14 lines modified
1065 ·············_\x8i_\x8s_\x8m·····1382,·1384,·13861065 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
1066 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)1066 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
1067 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.11067 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
1068 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001251068 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
1069 ·············_\x8c_\x8i_\x8s·····1.3.11069 ·············_\x8c_\x8i_\x8s·····1.3.1
1070 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R331070 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
1071 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.21071 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
1072 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1073 [[packages]] 
1074 name·=·"sudo" 
1075 version·=·"*" 
1076 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81072 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1077 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1073 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1078 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1074 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1079 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1075 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1080 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1076 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1081 #·Remediation·is·applicable·only·in·certain·platforms1077 #·Remediation·is·applicable·only·in·certain·platforms
1082 if·rpm·--quiet·-q·kernel-default;·then1078 if·rpm·--quiet·-q·kernel-default;·then
Offset 1119, 14 lines modifiedOffset 1114, 19 lines modified
1119 ··-·PCI-DSSv4-2.2.61114 ··-·PCI-DSSv4-2.2.6
1120 ··-·enable_strategy1115 ··-·enable_strategy
1121 ··-·low_complexity1116 ··-·low_complexity
1122 ··-·low_disruption1117 ··-·low_disruption
1123 ··-·medium_severity1118 ··-·medium_severity
1124 ··-·no_reboot_needed1119 ··-·no_reboot_needed
1125 ··-·package_sudo_installed1120 ··-·package_sudo_installed
 1121 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1122 [[packages]]
 1123 name·=·"sudo"
 1124 version·=·"*"
1126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81125 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1126 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1127 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1128 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1129 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1131 include·install_sudo1130 include·install_sudo
  
Offset 9626, 19 lines modifiedOffset 9626, 14 lines modified
9626 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-9626 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
9627 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-9627 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
9628 ·····················002329628 ·····················00232
9629 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-0103909629 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
9630 ·············_\x8c_\x8i_\x8s·····1.7.1.19630 ·············_\x8c_\x8i_\x8s·····1.7.1.1
9631 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R459631 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
9632 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule9632 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
9633 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9634 [[packages]] 
9635 name·=·"pam_apparmor" 
9636 version·=·"*" 
9637 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89633 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9638 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9634 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9639 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9635 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9640 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9636 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9641 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9637 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9642 #·Remediation·is·applicable·only·in·certain·platforms9638 #·Remediation·is·applicable·only·in·certain·platforms
9643 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then9639 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 9670, 14 lines modifiedOffset 9665, 19 lines modified
9670 ··-·NIST-800-53-SC-7(21)9665 ··-·NIST-800-53-SC-7(21)
9671 ··-·enable_strategy9666 ··-·enable_strategy
9672 ··-·low_complexity9667 ··-·low_complexity
9673 ··-·low_disruption9668 ··-·low_disruption
9674 ··-·medium_severity9669 ··-·medium_severity
9675 ··-·no_reboot_needed9670 ··-·no_reboot_needed
9676 ··-·package_pam_apparmor_installed9671 ··-·package_pam_apparmor_installed
 9672 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9673 [[packages]]
 9674 name·=·"pam_apparmor"
 9675 version·=·"*"
9677 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89676 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9678 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9677 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9679 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9678 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9680 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9679 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9681 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9680 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9682 include·install_pam_apparmor9681 include·install_pam_apparmor
  
Offset 10030, 18 lines modifiedOffset 10030, 14 lines modified
10030 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-10030 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
10031 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-10031 References:··········GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
10032 ·····················0023210032 ·····················00232
10033 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-01039010033 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
10034 ·············_\x8c_\x8i_\x8s·····1.7.1.210034 ·············_\x8c_\x8i_\x8s·····1.7.1.2
10035 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R4510035 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
10036 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule10036 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
Max diff block lines reached; 44527/49748 bytes (89.51%) of diff not shown.
520 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-hipaa.html
    
Offset 22092, 298 lines modifiedOffset 22092, 298 lines modified
000564b0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id000564b0:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
000564c0:·6d31·3134·3434·2220·7461·6269·6e64·6578··m11444"·tabindex000564c0:·6d31·3134·3434·2220·7461·6269·6e64·6578··m11444"·tabindex
000564d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto000564d0:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto
000564e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded000564e0:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded
000564f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="000564f0:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title="
00056500:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve00056500:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve
00056510:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re00056510:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re
00056520:·6d65·6469·6174·696f·6e20·4f53·4275·696c··mediation·OSBuil00056520:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell·
 00056530:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b
00056530:·6420·426c·7565·7072·696e·7420·736e·6970··d·Blueprint·snip 
00056540:·7065·7420·e287·b23c·2f61·3e3c·6272·3e3c··pet·...</a><br>< 
00056550:·6469·7620·636c·6173·733d·2270·616e·656c··div·class="panel 
00056560:·2d63·6f6c·6c61·7073·6520·636f·6c6c·6170··-collapse·collap 
00056570:·7365·2220·6964·3d22·6964·6d31·3134·3434··se"·id="idm11444 
00056580:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b63··"><pre><code>.[c 
00056590:·7573·746f·6d69·7a61·7469·6f6e·732e·7365··ustomizations.se 
000565a0:·7276·6963·6573·5d0a·6d61·736b·6564·203d··rvices].masked·= 
000565b0:·205b·2264·6562·7567·2d73·6865·6c6c·225d···["debug-shell"] 
000565c0:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></ 
000565d0:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt00056540:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
000565e0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d 
000565f0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll 
00056600:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe 
00056610:·743d·2223·6964·6d31·3134·3435·2220·7461··t="#idm11445"·ta 
00056620:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
00056630:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00056640:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00056650:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00056660:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00056550:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 00056560:·6c61·7073·6522·2069·643d·2269·646d·3131··lapse"·id="idm11
 00056570:·3434·3422·3e3c·7461·626c·6520·636c·6173··444"><table·clas
 00056580:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 00056590:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 000565a0:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 000565b0:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 000565c0:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 000565d0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 000565e0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 000565f0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 00056600:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 00056610:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 00056620:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 00056630:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 00056640:·3a3c·2f74·683e·3c74·643e·6469·7361·626c··:</th><td>disabl
 00056650:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 00056660:·6c65·3e3c·7072·653e·3c63·6f64·653e·2320··le><pre><code>#·
00056670:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00056670:·5265·6d65·6469·6174·696f·6e20·6973·2061··Remediation·is·a
 00056680:·7070·6c69·6361·626c·6520·6f6e·6c79·2069··pplicable·only·i
 00056690:·6e20·6365·7274·6169·6e20·706c·6174·666f··n·certain·platfo
 000566a0:·726d·730a·6966·2072·706d·202d·2d71·7569··rms.if·rpm·--qui
 000566b0:·6574·202d·7120·6b65·726e·656c·2d64·6566··et·-q·kernel-def
 000566c0:·6175·6c74·3b20·7468·656e·0a0a·5359·5354··ault;·then..SYST
 000566d0:·454d·4354·4c5f·4558·4543·3d27·2f75·7372··EMCTL_EXEC='/usr
 000566e0:·2f62·696e·2f73·7973·7465·6d63·746c·270a··/bin/systemctl'.
 000566f0:·6966·205b·5b20·2428·2224·5359·5354·454d··if·[[·$("$SYSTEM
 00056700:·4354·4c5f·4558·4543·2220·6973·2d73·7973··CTL_EXEC"·is-sys
 00056710:·7465·6d2d·7275·6e6e·696e·6729·2021·3d20··tem-running)·!=·
 00056720:·226f·6666·6c69·6e65·2220·5d5d·3b20·7468··"offline"·]];·th
 00056730:·656e·0a20·2022·2453·5953·5445·4d43·544c··en.··"$SYSTEMCTL
 00056740:·5f45·5845·4322·2073·746f·7020·2764·6562··_EXEC"·stop·'deb
 00056750:·7567·2d73·6865·6c6c·2e73·6572·7669·6365··ug-shell.service
00056680:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·... 
00056690:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla 
000566a0:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap 
000566b0:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id= 
000566c0:·2269·646d·3131·3434·3522·3e3c·7461·626c··"idm11445"><tabl 
000566d0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
000566e0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
000566f0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
00056700:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
00056710:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
00056720:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
00056730:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
00056740:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
00056750:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00056760:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
00056770:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
00056780:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
00056790:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
000567a0:·6469·7361·626c·653c·2f74·643e·3c2f·7472··disable</td></tr 
000567b0:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c 
000567c0:·6f64·653e·2320·5265·6d65·6469·6174·696f··ode>#·Remediatio 
000567d0:·6e20·6973·2061·7070·6c69·6361·626c·6520··n·is·applicable· 
000567e0:·6f6e·6c79·2069·6e20·6365·7274·6169·6e20··only·in·certain· 
000567f0:·706c·6174·666f·726d·730a·6966·2072·706d··platforms.if·rpm 
00056800:·202d·2d71·7569·6574·202d·7120·6b65·726e···--quiet·-q·kern 
00056810:·656c·2d64·6566·6175·6c74·3b20·7468·656e··el-default;·then 
00056820:·0a0a·5359·5354·454d·4354·4c5f·4558·4543··..SYSTEMCTL_EXEC 
00056830:·3d27·2f75·7372·2f62·696e·2f73·7973·7465··='/usr/bin/syste 
00056840:·6d63·746c·270a·6966·205b·5b20·2428·2224··mctl'.if·[[·$("$ 
00056850:·5359·5354·454d·4354·4c5f·4558·4543·2220··SYSTEMCTL_EXEC"· 
00056860:·6973·2d73·7973·7465·6d2d·7275·6e6e·696e··is-system-runnin 
00056870:·6729·2021·3d20·226f·6666·6c69·6e65·2220··g)·!=·"offline"· 
00056880:·5d5d·3b20·7468·656e·0a20·2022·2453·5953··]];·then.··"$SYS 
00056890:·5445·4d43·544c·5f45·5845·4322·2073·746f··TEMCTL_EXEC"·sto 
000568a0:·7020·2764·6562·7567·2d73·6865·6c6c·2e73··p·'debug-shell.s 
000568b0:·6572·7669·6365·270a·6669·0a22·2453·5953··ervice'.fi."$SYS 
000568c0:·5445·4d43·544c·5f45·5845·4322·2064·6973··TEMCTL_EXEC"·dis 
000568d0:·6162·6c65·2027·6465·6275·672d·7368·656c··able·'debug-shel 
000568e0:·6c2e·7365·7276·6963·6527·0a22·2453·5953··l.service'."$SYS 
000568f0:·5445·4d43·544c·5f45·5845·4322·206d·6173··TEMCTL_EXEC"·mas 
00056900:·6b20·2764·6562·7567·2d73·6865·6c6c·2e73··k·'debug-shell.s 
00056910:·6572·7669·6365·270a·2320·4469·7361·626c··ervice'.#·Disabl 
00056920:·6520·736f·636b·6574·2061·6374·6976·6174··e·socket·activat 
00056930:·696f·6e20·6966·2077·6520·6861·7665·2061··ion·if·we·have·a 
00056940:·2075·6e69·7420·6669·6c65·2066·6f72·2069···unit·file·for·i 
00056950:·740a·6966·2022·2453·5953·5445·4d43·544c··t.if·"$SYSTEMCTL00056760:·270a·6669·0a22·2453·5953·5445·4d43·544c··'.fi."$SYSTEMCTL
00056960:·5f45·5845·4322·202d·7120·6c69·7374·2d75··_EXEC"·-q·list-u 
00056970:·6e69·742d·6669·6c65·7320·6465·6275·672d··nit-files·debug- 
00056980:·7368·656c·6c2e·736f·636b·6574·3b20·7468··shell.socket;·th 
00056990:·656e·0a20·2020·2069·6620·5b5b·2024·2822··en.····if·[[·$("00056770:·5f45·5845·4322·2064·6973·6162·6c65·2027··_EXEC"·disable·'
 00056780:·6465·6275·672d·7368·656c·6c2e·7365·7276··debug-shell.serv
 00056790:·6963·6527·0a22·2453·5953·5445·4d43·544c··ice'."$SYSTEMCTL
 000567a0:·5f45·5845·4322·206d·6173·6b20·2764·6562··_EXEC"·mask·'deb
 000567b0:·7567·2d73·6865·6c6c·2e73·6572·7669·6365··ug-shell.service
 000567c0:·270a·2320·4469·7361·626c·6520·736f·636b··'.#·Disable·sock
 000567d0:·6574·2061·6374·6976·6174·696f·6e20·6966··et·activation·if
 000567e0:·2077·6520·6861·7665·2061·2075·6e69·7420···we·have·a·unit·
 000567f0:·6669·6c65·2066·6f72·2069·740a·6966·2022··file·for·it.if·"
000569a0:·2453·5953·5445·4d43·544c·5f45·5845·4322··$SYSTEMCTL_EXEC"00056800:·2453·5953·5445·4d43·544c·5f45·5845·4322··$SYSTEMCTL_EXEC"
 00056810:·202d·7120·6c69·7374·2d75·6e69·742d·6669···-q·list-unit-fi
 00056820:·6c65·7320·6465·6275·672d·7368·656c·6c2e··les·debug-shell.
 00056830:·736f·636b·6574·3b20·7468·656e·0a20·2020··socket;·then.···
 00056840:·2069·6620·5b5b·2024·2822·2453·5953·5445···if·[[·$("$SYSTE
 00056850:·4d43·544c·5f45·5845·4322·2069·732d·7379··MCTL_EXEC"·is-sy
 00056860:·7374·656d·2d72·756e·6e69·6e67·2920·213d··stem-running)·!=
 00056870:·2022·6f66·666c·696e·6522·205d·5d3b·2074···"offline"·]];·t
Max diff block lines reached; 469296/509068 bytes (92.19%) of diff not shown.
22.6 KB
html2text {}
    
Offset 1742, 18 lines modifiedOffset 1742, 14 lines modified
1742 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-0022351742 ·············_\x8d_\x8i_\x8s_\x8a···CCI-000366,·CCI-002235
1743 ····················164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)1743 ····················164.308(a)(1)(ii)(B),·164.308(a)(7)(i),·164.308(a)(7)(ii)(A),·164.310(a)(1),·164.310(a)
1744 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),1744 References:··_\x8h_\x8i_\x8p_\x8a_\x8a··(2)(i),·164.310(a)(2)(ii),·164.310(a)(2)(iii),·164.310(b),·164.310(c),·164.310(d)(1),
1745 ····················164.310(d)(2)(iii)1745 ····················164.310(d)(2)(iii)
1746 ·············_\x8n_\x8i_\x8s_\x8t···CM-61746 ·············_\x8n_\x8i_\x8s_\x8t···CM-6
1747 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.11747 ·············_\x8o_\x8s_\x8p_\x8p···FIA_UAU.1
1748 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-002271748 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·SRG-OS-000324-GPOS-00125,·SRG-OS-000480-GPOS-00227
1749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
1750 [customizations.services] 
1751 masked·=·["debug-shell"] 
1752 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x81749 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
1753 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1750 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1754 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1751 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1755 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1752 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1756 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable1753 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
1757 #·Remediation·is·applicable·only·in·certain·platforms1754 #·Remediation·is·applicable·only·in·certain·platforms
1758 if·rpm·--quiet·-q·kernel-default;·then1755 if·rpm·--quiet·-q·kernel-default;·then
Offset 1870, 14 lines modifiedOffset 1866, 18 lines modified
1870 ··-·NIST-800-53-CM-61866 ··-·NIST-800-53-CM-6
1871 ··-·disable_strategy1867 ··-·disable_strategy
1872 ··-·low_complexity1868 ··-·low_complexity
1873 ··-·low_disruption1869 ··-·low_disruption
1874 ··-·medium_severity1870 ··-·medium_severity
1875 ··-·no_reboot_needed1871 ··-·no_reboot_needed
1876 ··-·service_debug-shell_disabled1872 ··-·service_debug-shell_disabled
 1873 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 1874 [customizations.services]
 1875 masked·=·["debug-shell"]
1877 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x81876 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
1878 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low1877 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
1879 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low1878 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
1880 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false1879 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
1881 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable1880 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
1882 include·disable_debug-shell1881 include·disable_debug-shell
  
Offset 3485, 18 lines modifiedOffset 3485, 14 lines modified
3485 ····························A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.33485 ····························A.9.2.2,·A.9.2.3,·A.9.2.4,·A.9.2.6,·A.9.3.1,·A.9.4.2,·A.9.4.3
3486 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-73486 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a),·MP-7
3487 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-73487 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-1,·PR.AC-3,·PR.AC-6,·PR.AC-7
3488 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-002273488 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000114-GPOS-00059,·SRG-OS-000378-GPOS-00163,·SRG-OS-000480-GPOS-00227
3489 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-0102403489 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010240
3490 ·············_\x8c_\x8i_\x8s············1.1.233490 ·············_\x8c_\x8i_\x8s············1.1.23
3491 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-234823r958498_rule3491 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-234823r958498_rule
3492 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3493 [customizations.services] 
3494 masked·=·["autofs"] 
3495 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83492 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3496 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3493 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3497 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3494 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3498 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3495 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3499 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable3496 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
3500 #·Remediation·is·applicable·only·in·certain·platforms3497 #·Remediation·is·applicable·only·in·certain·platforms
3501 if·(·rpm·--quiet·-q·autofs·&&·rpm·--quiet·-q·kernel-default·);·then3498 if·(·rpm·--quiet·-q·autofs·&&·rpm·--quiet·-q·kernel-default·);·then
Offset 3636, 14 lines modifiedOffset 3632, 18 lines modified
3636 ··-·NIST-800-53-MP-73632 ··-·NIST-800-53-MP-7
3637 ··-·disable_strategy3633 ··-·disable_strategy
3638 ··-·low_complexity3634 ··-·low_complexity
3639 ··-·low_disruption3635 ··-·low_disruption
3640 ··-·medium_severity3636 ··-·medium_severity
3641 ··-·no_reboot_needed3637 ··-·no_reboot_needed
3642 ··-·service_autofs_disabled3638 ··-·service_autofs_disabled
 3639 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3640 [customizations.services]
 3641 masked·=·["autofs"]
3643 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83642 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3644 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3643 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3645 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3644 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3646 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3645 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3647 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3646 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3648 include·disable_autofs3647 include·disable_autofs
  
Offset 5610, 18 lines modifiedOffset 5610, 14 lines modified
5610 ····························A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.25610 ····························A.14.2.3,·A.14.2.4,·A.6.2.1,·A.6.2.2,·A.9.1.2
5611 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)5611 ·············_\x8n_\x8i_\x8s_\x8t···········CM-7(a),·CM-7(b),·CM-6(a)
5612 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-45612 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.AC-3,·PR.IP-1,·PR.PT-3,·PR.PT-4
5613 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1.15613 ·············_\x8o_\x8s_\x8p_\x8p···········FMT_SMF_EXT.1.1
5614 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000269-GPOS-00103,·SRG-OS-000480-GPOS-002275614 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000269-GPOS-00103,·SRG-OS-000480-GPOS-00227
5615 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-0401905615 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-040190
5616 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-235003r991589_rule5616 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-235003r991589_rule
5617 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5618 [customizations.services] 
5619 masked·=·["kdump"] 
5620 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85617 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
5621 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5618 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5622 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5619 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5623 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5620 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5624 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable5621 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···disable
5625 #·Remediation·is·applicable·only·in·certain·platforms5622 #·Remediation·is·applicable·only·in·certain·platforms
5626 if·rpm·--quiet·-q·kernel-default;·then5623 if·rpm·--quiet·-q·kernel-default;·then
Offset 5748, 14 lines modifiedOffset 5744, 18 lines modified
5748 ··-·NIST-800-53-CM-7(b)5744 ··-·NIST-800-53-CM-7(b)
5749 ··-·disable_strategy5745 ··-·disable_strategy
5750 ··-·low_complexity5746 ··-·low_complexity
5751 ··-·low_disruption5747 ··-·low_disruption
5752 ··-·medium_severity5748 ··-·medium_severity
5753 ··-·no_reboot_needed5749 ··-·no_reboot_needed
5754 ··-·service_kdump_disabled5750 ··-·service_kdump_disabled
 5751 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 5752 [customizations.services]
 5753 masked·=·["kdump"]
5755 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x85754 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
5756 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low5755 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
5757 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low5756 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
5758 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false5757 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
5759 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable5758 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
5760 include·disable_kdump5759 include·disable_kdump
  
Offset 5791, 19 lines modifiedOffset 5791, 14 lines modified
5791 ····························2.7,·SR·7.65791 ····························2.7,·SR·7.6
5792 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.25792 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2
5793 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)5793 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
5794 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-35794 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
5795 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002275795 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
5796 ·············_\x8c_\x8i_\x8s············5.1.15796 ·············_\x8c_\x8i_\x8s············5.1.1
5797 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.25797 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
5798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
5799 [[packages]] 
5800 name·=·"cronie" 
5801 version·=·"*" 
5802 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x85798 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
Max diff block lines reached; 17506/23160 bytes (75.59%) of diff not shown.
448 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-pci-dss-4.html
    
Offset 17149, 145 lines modifiedOffset 17149, 145 lines modified
00042fc0:·6574·3d22·2369·646d·3633·3631·2220·7461··et="#idm6361"·ta00042fc0:·6574·3d22·2369·646d·3633·3631·2220·7461··et="#idm6361"·ta
00042fd0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=00042fd0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
00042fe0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex00042fe0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
00042ff0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t00042ff0:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
00043000:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t00043000:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
00043010:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="00043010:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
00043020:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00043020:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 00043030:·5368·656c·6c20·7363·7269·7074·20e2·87b2··Shell·script·...
 00043040:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla
 00043050:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap
 00043060:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=
 00043070:·2269·646d·3633·3631·223e·3c74·6162·6c65··"idm6361"><table
 00043080:·2063·6c61·7373·3d22·7461·626c·6520·7461···class="table·ta
 00043090:·626c·652d·7374·7269·7065·6420·7461·626c··ble-striped·tabl
 000430a0:·652d·626f·7264·6572·6564·2074·6162·6c65··e-bordered·table
 000430b0:·2d63·6f6e·6465·6e73·6564·223e·3c74·723e··-condensed"><tr>
 000430c0:·3c74·683e·436f·6d70·6c65·7869·7479·3a3c··<th>Complexity:<
 000430d0:·2f74·683e·3c74·643e·6c6f·773c·2f74·643e··/th><td>low</td>
 000430e0:·3c2f·7472·3e3c·7472·3e3c·7468·3e44·6973··</tr><tr><th>Dis
 000430f0:·7275·7074·696f·6e3a·3c2f·7468·3e3c·7464··ruption:</th><td
 00043100:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 00043110:·723e·3c74·683e·5265·626f·6f74·3a3c·2f74··r><th>Reboot:</t
 00043120:·683e·3c74·643e·6661·6c73·653c·2f74·643e··h><td>false</td>
 00043130:·3c2f·7472·3e3c·7472·3e3c·7468·3e53·7472··</tr><tr><th>Str
 00043140:·6174·6567·793a·3c2f·7468·3e3c·7464·3e65··ategy:</th><td>e
00043030:·4f53·4275·696c·6420·426c·7565·7072·696e··OSBuild·Blueprin 
00043040:·7420·736e·6970·7065·7420·e287·b23c·2f61··t·snippet·...</a 
00043050:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class= 
00043060:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse· 
00043070:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id 
00043080:·6d36·3336·3122·3e3c·7072·653e·3c63·6f64··m6361"><pre><cod 
00043090:·653e·0a5b·5b70·6163·6b61·6765·735d·5d0a··e>.[[packages]]. 
000430a0:·6e61·6d65·203d·2022·6169·6465·220a·7665··name·=·"aide".ve 
000430b0:·7273·696f·6e20·3d20·222a·220a·3c2f·636f··rsion·=·"*".</co 
000430c0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div>< 
000430d0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn 
000430e0:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t 
000430f0:·6f67·676c·653d·2263·6f6c·6c61·7073·6522··oggle="collapse" 
00043100:·2064·6174·612d·7461·7267·6574·3d22·2369···data-target="#i 
00043110:·646d·3633·3632·2220·7461·6269·6e64·6578··dm6362"·tabindex 
00043120:·3d22·3022·2072·6f6c·653d·2262·7574·746f··="0"·role="butto 
00043130:·6e22·2061·7269·612d·6578·7061·6e64·6564··n"·aria-expanded 
00043140:·3d22·6661·6c73·6522·2074·6974·6c65·3d22··="false"·title=" 
00043150:·4163·7469·7661·7465·2074·6f20·7265·7665··Activate·to·reve 
00043160:·616c·2220·6872·6566·3d22·2321·223e·5265··al"·href="#!">Re 
00043170:·6d65·6469·6174·696f·6e20·5368·656c·6c20··mediation·Shell· 
00043180:·7363·7269·7074·20e2·87b2·3c2f·613e·3c62··script·...</a><b 
00043190:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
000431a0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
000431b0:·6c61·7073·6522·2069·643d·2269·646d·3633··lapse"·id="idm63 
000431c0:·3632·223e·3c74·6162·6c65·2063·6c61·7373··62"><table·class 
000431d0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st 
000431e0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord 
000431f0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde 
00043200:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co 
00043210:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t 
00043220:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
00043230:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio 
00043240:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</ 
00043250:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00043260:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td> 
00043270:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><00043150:·6e61·626c·653c·2f74·643e·3c2f·7472·3e3c··nable</td></tr><
 00043160:·2f74·6162·6c65·3e3c·7072·653e·3c63·6f64··/table><pre><cod
00043280:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy: 
00043290:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable< 
000432a0:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table 
000432b0:·3e3c·7072·653e·3c63·6f64·653e·2320·5265··><pre><code>#·Re 
000432c0:·6d65·6469·6174·696f·6e20·6973·2061·7070··mediation·is·app 
000432d0:·6c69·6361·626c·6520·6f6e·6c79·2069·6e20··licable·only·in· 
000432e0:·6365·7274·6169·6e20·706c·6174·666f·726d··certain·platform 
000432f0:·730a·6966·2072·706d·202d·2d71·7569·6574··s.if·rpm·--quiet 
00043300:·202d·7120·6b65·726e·656c·2d64·6566·6175···-q·kernel-defau 
00043310:·6c74·3b20·7468·656e·0a0a·7a79·7070·6572··lt;·then..zypper 
00043320:·2069·6e73·7461·6c6c·202d·7920·2261·6964···install·-y·"aid 
00043330:·6522·0a0a·656c·7365·0a20·2020·2026·6774··e"..else.····&gt 
00043340:·3b26·616d·703b·3220·6563·686f·2027·5265··;&amp;2·echo·'Re 
00043350:·6d65·6469·6174·696f·6e20·6973·206e·6f74··mediation·is·not 
00043360:·2061·7070·6c69·6361·626c·652c·206e·6f74···applicable,·not 
00043370:·6869·6e67·2077·6173·2064·6f6e·6527·0a66··hing·was·done'.f 
00043380:·690a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··i.</code></pre>< 
00043390:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b 
000433a0:·746e·2062·746e·2d73·7563·6365·7373·2220··tn·btn-success"· 
000433b0:·6461·7461·2d74·6f67·676c·653d·2263·6f6c··data-toggle="col 
000433c0:·6c61·7073·6522·2064·6174·612d·7461·7267··lapse"·data-targ 
000433d0:·6574·3d22·2369·646d·3633·3633·2220·7461··et="#idm6363"·ta 
000433e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role= 
000433f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex 
00043400:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t 
00043410:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t 
00043420:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href=" 
00043430:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·00043170:·653e·2320·5265·6d65·6469·6174·696f·6e20··e>#·Remediation·
00043440:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet· 
00043450:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div· 
00043460:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col 
00043470:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"· 
00043480:·6964·3d22·6964·6d36·3336·3322·3e3c·7461··id="idm6363"><ta 
00043490:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table 
000434a0:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t 
000434b0:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta 
000434c0:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed">< 
000434d0:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit 
000434e0:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</ 
000434f0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00043500:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th> 
00043510:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr 
00043520:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot: 
00043530:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</ 
00043540:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th> 
00043550:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t 
00043560:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t 
00043570:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre>< 
00043580:·636f·6465·3e2d·206e·616d·653a·2047·6174··code>-·name:·Gat 
00043590:·6865·7220·7468·6520·7061·636b·6167·6520··her·the·package· 
000435a0:·6661·6374·730a·2020·7061·636b·6167·655f··facts.··package_ 
000435b0:·6661·6374·733a·0a20·2020·206d·616e·6167··facts:.····manag 
000435c0:·6572·3a20·6175·746f·0a20·2074·6167·733a··er:·auto.··tags: 
000435d0:·0a20·202d·2043·4345·2d38·3332·3839·2d39··.··-·CCE-83289-9 
000435e0:·0a20·202d·2043·4a49·532d·352e·3130·2e31··.··-·CJIS-5.10.1 
000435f0:·2e33·0a20·202d·2044·4953·412d·5354·4947··.3.··-·DISA-STIG 
00043600:·2d53·4c45·532d·3135·2d30·3130·3431·390a··-SLES-15-010419. 
00043610:·2020·2d20·4e49·5354·2d38·3030·2d35·332d····-·NIST-800-53- 
00043620:·434d·2d36·2861·290a·2020·2d20·5043·492d··CM-6(a).··-·PCI- 
00043630:·4453·532d·5265·712d·3131·2e35·0a20·202d··DSS-Req-11.5.··- 
00043640:·2050·4349·2d44·5353·7634·2d31·312e·352e···PCI-DSSv4-11.5. 
00043650:·320a·2020·2d20·656e·6162·6c65·5f73·7472··2.··-·enable_str 
00043660:·6174·6567·790a·2020·2d20·6c6f·775f·636f··ategy.··-·low_co 
00043670:·6d70·6c65·7869·7479·0a20·202d·206c·6f77··mplexity.··-·low 
Max diff block lines reached; 416478/435136 bytes (95.71%) of diff not shown.
22.9 KB
html2text {}
    
Offset 615, 19 lines modifiedOffset 615, 14 lines modified
615 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5615 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
616 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199616 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
617 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419617 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
618 ·············_\x8c_\x8i_\x8s············1.4.1618 ·············_\x8c_\x8i_\x8s············1.4.1
619 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79619 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
620 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2620 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
621 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule621 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
622 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
623 [[packages]] 
624 name·=·"aide" 
625 version·=·"*" 
626 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8622 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
627 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low623 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
628 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low624 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
629 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false625 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
630 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable626 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
631 #·Remediation·is·applicable·only·in·certain·platforms627 #·Remediation·is·applicable·only·in·certain·platforms
632 if·rpm·--quiet·-q·kernel-default;·then628 if·rpm·--quiet·-q·kernel-default;·then
Offset 673, 14 lines modifiedOffset 668, 19 lines modified
673 ··-·PCI-DSSv4-11.5.2668 ··-·PCI-DSSv4-11.5.2
674 ··-·enable_strategy669 ··-·enable_strategy
675 ··-·low_complexity670 ··-·low_complexity
676 ··-·low_disruption671 ··-·low_disruption
677 ··-·medium_severity672 ··-·medium_severity
678 ··-·no_reboot_needed673 ··-·no_reboot_needed
679 ··-·package_aide_installed674 ··-·package_aide_installed
 675 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 676 [[packages]]
 677 name·=·"aide"
 678 version·=·"*"
680 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8679 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
681 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low680 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
682 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low681 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
683 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false682 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
684 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable683 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
685 include·install_aide684 include·install_aide
  
Offset 2456, 19 lines modifiedOffset 2456, 14 lines modified
2456 ·············_\x8i_\x8s_\x8m·····1382,·1384,·13862456 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
2457 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)2457 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
2458 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.12458 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
2459 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-001252459 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
2460 ·············_\x8c_\x8i_\x8s·····1.3.12460 ·············_\x8c_\x8i_\x8s·····1.3.1
2461 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R332461 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
2462 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.22462 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
2463 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
2464 [[packages]] 
2465 name·=·"sudo" 
2466 version·=·"*" 
2467 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x82463 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
2468 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2464 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2469 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2465 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2470 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2466 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2471 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2467 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2472 #·Remediation·is·applicable·only·in·certain·platforms2468 #·Remediation·is·applicable·only·in·certain·platforms
2473 if·rpm·--quiet·-q·kernel-default;·then2469 if·rpm·--quiet·-q·kernel-default;·then
Offset 2510, 14 lines modifiedOffset 2505, 19 lines modified
2510 ··-·PCI-DSSv4-2.2.62505 ··-·PCI-DSSv4-2.2.6
2511 ··-·enable_strategy2506 ··-·enable_strategy
2512 ··-·low_complexity2507 ··-·low_complexity
2513 ··-·low_disruption2508 ··-·low_disruption
2514 ··-·medium_severity2509 ··-·medium_severity
2515 ··-·no_reboot_needed2510 ··-·no_reboot_needed
2516 ··-·package_sudo_installed2511 ··-·package_sudo_installed
 2512 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 2513 [[packages]]
 2514 name·=·"sudo"
 2515 version·=·"*"
2517 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x82516 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
2518 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low2517 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
2519 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low2518 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
2520 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false2519 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
2521 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable2520 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
2522 include·install_sudo2521 include·install_sudo
  
Offset 12480, 19 lines modifiedOffset 12480, 14 lines modified
12480 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.112480 References:··_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
12481 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)12481 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
12482 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-112482 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
12483 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.712483 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-10.7
12484 ·············_\x8c_\x8i_\x8s············4.2.412484 ·············_\x8c_\x8i_\x8s············4.2.4
12485 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R7112485 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R71
12486 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.512486 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········10.5.1,·10.5
12487 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
12488 [[packages]] 
12489 name·=·"logrotate" 
12490 version·=·"*" 
12491 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x812487 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
12492 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12488 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12493 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12489 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12494 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12490 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12495 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable12491 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
12496 #·Remediation·is·applicable·only·in·certain·platforms12492 #·Remediation·is·applicable·only·in·certain·platforms
12497 if·rpm·--quiet·-q·kernel-default;·then12493 if·rpm·--quiet·-q·kernel-default;·then
Offset 12536, 14 lines modifiedOffset 12531, 19 lines modified
12536 ··-·PCI-DSSv4-10.5.112531 ··-·PCI-DSSv4-10.5.1
12537 ··-·enable_strategy12532 ··-·enable_strategy
12538 ··-·low_complexity12533 ··-·low_complexity
12539 ··-·low_disruption12534 ··-·low_disruption
12540 ··-·medium_severity12535 ··-·medium_severity
12541 ··-·no_reboot_needed12536 ··-·no_reboot_needed
12542 ··-·package_logrotate_installed12537 ··-·package_logrotate_installed
 12538 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 12539 [[packages]]
 12540 name·=·"logrotate"
 12541 version·=·"*"
12543 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x812542 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
12544 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12543 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12545 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12544 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12546 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12545 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12547 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable12546 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
12548 include·install_logrotate12547 include·install_logrotate
  
Offset 15804, 19 lines modifiedOffset 15804, 14 lines modified
15804 Rationale:···within·a·corporate·network·to·include·malicious·mobile·code·and·poorly·configured·software·on15804 Rationale:···within·a·corporate·network·to·include·malicious·mobile·code·and·poorly·configured·software·on
15805 ·············a·host.15805 ·············a·host.
15806 Severity: ···medium15806 Severity: ···medium
15807 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_nftables_installed15807 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_nftables_installed
15808 Identifiers:·CCE-92469-615808 Identifiers:·CCE-92469-6
15809 References:··_\x8c_\x8i_\x8s·····3.5.2.115809 References:··_\x8c_\x8i_\x8s·····3.5.2.1
15810 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.215810 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·1.2.1,·1.2
Max diff block lines reached; 18378/23423 bytes (78.46%) of diff not shown.
102 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-pcs-hardening-sap.html
    
Offset 15096, 145 lines modifiedOffset 15096, 145 lines modified
0003af70:·6172·6765·743d·2223·6964·6d36·3336·3122··arget="#idm6361"0003af70:·6172·6765·743d·2223·6964·6d36·3336·3122··arget="#idm6361"
0003af80:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro0003af80:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003af90:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria0003af90:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003afa0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false0003afa0:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003afb0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat0003afb0:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003afc0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre0003afc0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003afd0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati0003afd0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003afe0:·6f6e·204f·5342·7569·6c64·2042·6c75·6570··on·OSBuild·Bluep 
0003aff0:·7269·6e74·2073·6e69·7070·6574·20e2·87b2··rint·snippet·...0003afe0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·
 0003aff0:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0003b000:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0003b010:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0003b020:·6964·3d22·6964·6d36·3336·3122·3e3c·7461··id="idm6361"><ta
 0003b030:·626c·6520·636c·6173·733d·2274·6162·6c65··ble·class="table
 0003b040:·2074·6162·6c65·2d73·7472·6970·6564·2074···table-striped·t
 0003b050:·6162·6c65·2d62·6f72·6465·7265·6420·7461··able-bordered·ta
 0003b060:·626c·652d·636f·6e64·656e·7365·6422·3e3c··ble-condensed"><
 0003b070:·7472·3e3c·7468·3e43·6f6d·706c·6578·6974··tr><th>Complexit
 0003b080:·793a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··y:</th><td>low</
 0003b090:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b0a0:·4469·7372·7570·7469·6f6e·3a3c·2f74·683e··Disruption:</th>
 0003b0b0:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b0c0:·3e3c·7472·3e3c·7468·3e52·6562·6f6f·743a··><tr><th>Reboot:
 0003b0d0:·3c2f·7468·3e3c·7464·3e66·616c·7365·3c2f··</th><td>false</
 0003b0e0:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b0f0:·5374·7261·7465·6779·3a3c·2f74·683e·3c74··Strategy:</th><t
 0003b100:·643e·656e·6162·6c65·3c2f·7464·3e3c·2f74··d>enable</td></t
 0003b110:·723e·3c2f·7461·626c·653e·3c70·7265·3e3c··r></table><pre><
 0003b120:·636f·6465·3e23·2052·656d·6564·6961·7469··code>#·Remediati
 0003b130:·6f6e·2069·7320·6170·706c·6963·6162·6c65··on·is·applicable
 0003b140:·206f·6e6c·7920·696e·2063·6572·7461·696e···only·in·certain
 0003b150:·2070·6c61·7466·6f72·6d73·0a69·6620·7270···platforms.if·rp
 0003b160:·6d20·2d2d·7175·6965·7420·2d71·206b·6572··m·--quiet·-q·ker
 0003b170:·6e65·6c2d·6465·6661·756c·743b·2074·6865··nel-default;·the
 0003b180:·6e0a·0a7a·7970·7065·7220·696e·7374·616c··n..zypper·instal
 0003b190:·6c20·2d79·2022·6169·6465·220a·0a65·6c73··l·-y·"aide"..els
 0003b1a0:·650a·2020·2020·2667·743b·2661·6d70·3b32··e.····&gt;&amp;2
 0003b1b0:·2065·6368·6f20·2752·656d·6564·6961·7469···echo·'Remediati
 0003b1c0:·6f6e·2069·7320·6e6f·7420·6170·706c·6963··on·is·not·applic
 0003b1d0:·6162·6c65·2c20·6e6f·7468·696e·6720·7761··able,·nothing·wa
 0003b1e0:·7320·646f·6e65·270a·6669·0a3c·2f63·6f64··s·done'.fi.</cod
 0003b1f0:·653e·3c2f·7072·653e·3c2f·6469·763e·3c61··e></pre></div><a
 0003b200:·2063·6c61·7373·3d22·6274·6e20·6274·6e2d···class="btn·btn-
 0003b210:·7375·6363·6573·7322·2064·6174·612d·746f··success"·data-to
 0003b220:·6767·6c65·3d22·636f·6c6c·6170·7365·2220··ggle="collapse"·
 0003b230:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
 0003b240:·6d36·3336·3222·2074·6162·696e·6465·783d··m6362"·tabindex=
 0003b250:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
 0003b260:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
 0003b270:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
 0003b280:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
 0003b290:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
 0003b2a0:·6564·6961·7469·6f6e·2041·6e73·6962·6c65··ediation·Ansible
 0003b2b0:·2073·6e69·7070·6574·20e2·87b2·3c2f·613e···snippet·...</a>
0003b000:·3c2f·613e·3c62·723e·3c64·6976·2063·6c61··</a><br><div·cla0003b2c0:·3c62·723e·3c64·6976·2063·6c61·7373·3d22··<br><div·class="
0003b010:·7373·3d22·7061·6e65·6c2d·636f·6c6c·6170··ss="panel-collap0003b2d0:·7061·6e65·6c2d·636f·6c6c·6170·7365·2063··panel-collapse·c
0003b020:·7365·2063·6f6c·6c61·7073·6522·2069·643d··se·collapse"·id=0003b2e0:·6f6c·6c61·7073·6522·2069·643d·2269·646d··ollapse"·id="idm
0003b030:·2269·646d·3633·3631·223e·3c70·7265·3e3c··"idm6361"><pre>< 
0003b040:·636f·6465·3e0a·5b5b·7061·636b·6167·6573··code>.[[packages 
0003b050:·5d5d·0a6e·616d·6520·3d20·2261·6964·6522··]].name·=·"aide" 
0003b060:·0a76·6572·7369·6f6e·203d·2022·2a22·0a3c··.version·=·"*".< 
0003b070:·2f63·6f64·653e·3c2f·7072·653e·3c2f·6469··/code></pre></di 
0003b080:·763e·3c61·2063·6c61·7373·3d22·6274·6e20··v><a·class="btn· 
0003b090:·6274·6e2d·7375·6363·6573·7322·2064·6174··btn-success"·dat 
0003b0a0:·612d·746f·6767·6c65·3d22·636f·6c6c·6170··a-toggle="collap 
0003b0b0:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target= 
0003b0c0:·2223·6964·6d36·3336·3222·2074·6162·696e··"#idm6362"·tabin 
0003b0d0:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu 
0003b0e0:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan 
0003b0f0:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl 
0003b100:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r 
0003b110:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!" 
0003b120:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She 
0003b130:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a0003b2f0:·3633·3632·223e·3c74·6162·6c65·2063·6c61··6362"><table·cla
 0003b300:·7373·3d22·7461·626c·6520·7461·626c·652d··ss="table·table-
 0003b310:·7374·7269·7065·6420·7461·626c·652d·626f··striped·table-bo
 0003b320:·7264·6572·6564·2074·6162·6c65·2d63·6f6e··rdered·table-con
 0003b330:·6465·6e73·6564·223e·3c74·723e·3c74·683e··densed"><tr><th>
 0003b340:·436f·6d70·6c65·7869·7479·3a3c·2f74·683e··Complexity:</th>
 0003b350:·3c74·643e·6c6f·773c·2f74·643e·3c2f·7472··<td>low</td></tr
 0003b360:·3e3c·7472·3e3c·7468·3e44·6973·7275·7074··><tr><th>Disrupt
 0003b370:·696f·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77··ion:</th><td>low
 0003b380:·3c2f·7464·3e3c·2f74·723e·3c74·723e·3c74··</td></tr><tr><t
 0003b390:·683e·5265·626f·6f74·3a3c·2f74·683e·3c74··h>Reboot:</th><t
 0003b3a0:·643e·6661·6c73·653c·2f74·643e·3c2f·7472··d>false</td></tr
 0003b3b0:·3e3c·7472·3e3c·7468·3e53·7472·6174·6567··><tr><th>Strateg
 0003b3c0:·793a·3c2f·7468·3e3c·7464·3e65·6e61·626c··y:</th><td>enabl
 0003b3d0:·653c·2f74·643e·3c2f·7472·3e3c·2f74·6162··e</td></tr></tab
 0003b3e0:·6c65·3e3c·7072·653e·3c63·6f64·653e·2d20··le><pre><code>-·
 0003b3f0:·6e61·6d65·3a20·4761·7468·6572·2074·6865··name:·Gather·the
 0003b400:·2070·6163·6b61·6765·2066·6163·7473·0a20···package·facts.·
 0003b410:·2070·6163·6b61·6765·5f66·6163·7473·3a0a···package_facts:.
 0003b420:·2020·2020·6d61·6e61·6765·723a·2061·7574······manager:·aut
 0003b430:·6f0a·2020·7461·6773·3a0a·2020·2d20·4343··o.··tags:.··-·CC
 0003b440:·452d·3833·3238·392d·390a·2020·2d20·434a··E-83289-9.··-·CJ
 0003b450:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-·
 0003b460:·4449·5341·2d53·5449·472d·534c·4553·2d31··DISA-STIG-SLES-1
 0003b470:·352d·3031·3034·3139·0a20·202d·204e·4953··5-010419.··-·NIS
 0003b480:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
 0003b490:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
 0003b4a0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
 0003b4b0:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e
 0003b4c0:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.·
 0003b4d0:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
 0003b4e0:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup
 0003b4f0:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
 0003b500:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
 0003b510:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
 0003b520:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i
 0003b530:·6e73·7461·6c6c·6564·0a0a·2d20·6e61·6d65··nstalled..-·name
 0003b540:·3a20·456e·7375·7265·2061·6964·6520·6973··:·Ensure·aide·is
 0003b550:·2069·6e73·7461·6c6c·6564·0a20·2070·6163···installed.··pac
 0003b560:·6b61·6765·3a0a·2020·2020·6e61·6d65·3a20··kage:.····name:·
 0003b570:·6169·6465·0a20·2020·2073·7461·7465·3a20··aide.····state:·
 0003b580:·7072·6573·656e·740a·2020·7768·656e·3a20··present.··when:·
 0003b590:·2722·6b65·726e·656c·2d64·6566·6175·6c74··'"kernel-default
 0003b5a0:·2220·696e·2061·6e73·6962·6c65·5f66·6163··"·in·ansible_fac
 0003b5b0:·7473·2e70·6163·6b61·6765·7327·0a20·2074··ts.packages'.··t
 0003b5c0:·6167·733a·0a20·202d·2043·4345·2d38·3332··ags:.··-·CCE-832
 0003b5d0:·3839·2d39·0a20·202d·2043·4a49·532d·352e··89-9.··-·CJIS-5.
 0003b5e0:·3130·2e31·2e33·0a20·202d·2044·4953·412d··10.1.3.··-·DISA-
 0003b5f0:·5354·4947·2d53·4c45·532d·3135·2d30·3130··STIG-SLES-15-010
 0003b600:·3431·390a·2020·2d20·4e49·5354·2d38·3030··419.··-·NIST-800
 0003b610:·2d35·332d·434d·2d36·2861·290a·2020·2d20··-53-CM-6(a).··-·
 0003b620:·5043·492d·4453·532d·5265·712d·3131·2e35··PCI-DSS-Req-11.5
 0003b630:·0a20·202d·2050·4349·2d44·5353·7634·2d31··.··-·PCI-DSSv4-1
 0003b640:·312e·352e·320a·2020·2d20·656e·6162·6c65··1.5.2.··-·enable
Max diff block lines reached; 77948/96606 bytes (80.69%) of diff not shown.
7.59 KB
html2text {}
    
Offset 113, 19 lines modifiedOffset 113, 14 lines modified
113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5113 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
114 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199114 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
115 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419115 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
116 ·············_\x8c_\x8i_\x8s············1.4.1116 ·············_\x8c_\x8i_\x8s············1.4.1
117 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79117 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
118 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2118 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
119 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule119 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
121 [[packages]] 
122 name·=·"aide" 
123 version·=·"*" 
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8120 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low121 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low122 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false123 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable124 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
129 #·Remediation·is·applicable·only·in·certain·platforms125 #·Remediation·is·applicable·only·in·certain·platforms
130 if·rpm·--quiet·-q·kernel-default;·then126 if·rpm·--quiet·-q·kernel-default;·then
Offset 171, 14 lines modifiedOffset 166, 19 lines modified
171 ··-·PCI-DSSv4-11.5.2166 ··-·PCI-DSSv4-11.5.2
172 ··-·enable_strategy167 ··-·enable_strategy
173 ··-·low_complexity168 ··-·low_complexity
174 ··-·low_disruption169 ··-·low_disruption
175 ··-·medium_severity170 ··-·medium_severity
176 ··-·no_reboot_needed171 ··-·no_reboot_needed
177 ··-·package_aide_installed172 ··-·package_aide_installed
 173 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 174 [[packages]]
 175 name·=·"aide"
 176 version·=·"*"
178 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
179 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low178 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
180 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low179 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
181 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false180 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
182 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable181 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
183 include·install_aide182 include·install_aide
  
Offset 9147, 19 lines modifiedOffset 9147, 14 lines modified
9147 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.49147 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x80_\x89·4.3.3.3.9,·4.3.3.5.8,·4.3.4.4.7,·4.4.2.1,·4.4.2.2,·4.4.2.4
9148 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.99148 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
9149 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.19149 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
9150 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)9150 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
9151 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-19151 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
9152 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-002279152 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-00227
9153 ·············_\x8c_\x8i_\x8s············4.2.1.19153 ·············_\x8c_\x8i_\x8s············4.2.1.1
9154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9155 [[packages]] 
9156 name·=·"rsyslog" 
9157 version·=·"*" 
9158 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89154 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9159 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9155 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9160 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9156 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9161 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9157 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9162 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9158 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9163 #·Remediation·is·applicable·only·in·certain·platforms9159 #·Remediation·is·applicable·only·in·certain·platforms
9164 if·rpm·--quiet·-q·kernel-default;·then9160 if·rpm·--quiet·-q·kernel-default;·then
Offset 9197, 14 lines modifiedOffset 9192, 19 lines modified
9197 ··-·NIST-800-53-CM-6(a)9192 ··-·NIST-800-53-CM-6(a)
9198 ··-·enable_strategy9193 ··-·enable_strategy
9199 ··-·low_complexity9194 ··-·low_complexity
9200 ··-·low_disruption9195 ··-·low_disruption
9201 ··-·medium_severity9196 ··-·medium_severity
9202 ··-·no_reboot_needed9197 ··-·no_reboot_needed
9203 ··-·package_rsyslog_installed9198 ··-·package_rsyslog_installed
 9199 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9200 [[packages]]
 9201 name·=·"rsyslog"
 9202 version·=·"*"
9204 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89203 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9205 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9204 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9206 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9205 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9207 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9206 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9208 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9207 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9209 include·install_rsyslog9208 include·install_rsyslog
  
Offset 15657, 19 lines modifiedOffset 15657, 14 lines modified
15657 ·············_\x8i_\x8s_\x8m·····0988,·140515657 ·············_\x8i_\x8s_\x8m·····0988,·1405
15658 ·············_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.115658 ·············_\x8o_\x8s_\x8p_\x8p····FMT_SMF_EXT.1
15659 References:··_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.415659 References:··_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.4
15660 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000355-GPOS-0014315660 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000355-GPOS-00143
15661 ·············_\x8c_\x8i_\x8s·····2.2.1.115661 ·············_\x8c_\x8i_\x8s·····2.2.1.1
15662 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R7115662 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R71
15663 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·10.6.1,·10.615663 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·10.6.1,·10.6
15664 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
15665 [[packages]] 
15666 name·=·"chrony" 
15667 version·=·"*" 
15668 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x815664 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
15669 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low15665 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
15670 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low15666 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
15671 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false15667 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
15672 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable15668 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
15673 #·Remediation·is·applicable·only·in·certain·platforms15669 #·Remediation·is·applicable·only·in·certain·platforms
15674 if·rpm·--quiet·-q·kernel-default;·then15670 if·rpm·--quiet·-q·kernel-default;·then
Offset 15711, 14 lines modifiedOffset 15706, 19 lines modified
15711 ··-·PCI-DSSv4-10.6.115706 ··-·PCI-DSSv4-10.6.1
15712 ··-·enable_strategy15707 ··-·enable_strategy
15713 ··-·low_complexity15708 ··-·low_complexity
15714 ··-·low_disruption15709 ··-·low_disruption
15715 ··-·medium_severity15710 ··-·medium_severity
15716 ··-·no_reboot_needed15711 ··-·no_reboot_needed
15717 ··-·package_chrony_installed15712 ··-·package_chrony_installed
 15713 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 15714 [[packages]]
 15715 name·=·"chrony"
 15716 version·=·"*"
15718 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x815717 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
15719 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low15718 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
15720 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low15719 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
15721 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false15720 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
15722 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable15721 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
15723 include·install_chrony15722 include·install_chrony
  
Offset 78006, 19 lines modifiedOffset 78006, 14 lines modified
78006 ·············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(D),·164.308(a)(5)(ii)(C),·164.310(a)(2)(iv),·164.310(d)(2)(iii),78006 ·············_\x8h_\x8i_\x8p_\x8a_\x8a···164.308(a)(1)(ii)(D),·164.308(a)(5)(ii)(C),·164.310(a)(2)(iv),·164.310(d)(2)(iii),
78007 ·····················164.312(b)78007 ·····················164.312(b)
78008 References:··_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.5.378008 References:··_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s··Req-10.5.3
78009 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000342-GPOS-0013378009 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000342-GPOS-00133
78010 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-03067078010 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-030670
78011 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·10.3.3,·10.378011 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·10.3.3,·10.3
78012 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234966r1009564_rule78012 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234966r1009564_rule
Max diff block lines reached; 2423/7748 bytes (31.27%) of diff not shown.
267 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-standard.html
    
Offset 27505, 136 lines modifiedOffset 27505, 136 lines modified
0006b700:·7461·7267·6574·3d22·2369·646d·3137·3432··target="#idm17420006b700:·7461·7267·6574·3d22·2369·646d·3137·3432··target="#idm1742
0006b710:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·0006b710:·3922·2074·6162·696e·6465·783d·2230·2220··9"·tabindex="0"·
0006b720:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0006b720:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
0006b730:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0006b730:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
0006b740:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0006b740:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
0006b750:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0006b750:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
0006b760:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0006b760:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
 0006b770:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip
 0006b780:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di
 0006b790:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c
 0006b7a0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse
 0006b7b0:·2220·6964·3d22·6964·6d31·3734·3239·223e··"·id="idm17429">
 0006b7c0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0006b7d0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0006b7e0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0006b7f0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0006b800:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0006b810:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0006b820:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0006b830:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0006b840:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0006b850:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0006b860:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0006b870:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0006b880:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0006b890:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0006b8a0:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0006b8b0:·653e·3c63·6f64·653e·2320·5265·6d65·6469··e><code>#·Remedi
 0006b8c0:·6174·696f·6e20·6973·2061·7070·6c69·6361··ation·is·applica
 0006b8d0:·626c·6520·6f6e·6c79·2069·6e20·6365·7274··ble·only·in·cert
 0006b8e0:·6169·6e20·706c·6174·666f·726d·730a·6966··ain·platforms.if
 0006b8f0:·2072·706d·202d·2d71·7569·6574·202d·7120···rpm·--quiet·-q·
 0006b900:·6b65·726e·656c·2d64·6566·6175·6c74·3b20··kernel-default;·
 0006b910:·7468·656e·0a0a·7a79·7070·6572·2069·6e73··then..zypper·ins
 0006b920:·7461·6c6c·202d·7920·2272·7379·736c·6f67··tall·-y·"rsyslog
 0006b930:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt;
 0006b940:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0006b950:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0006b960:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0006b970:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
 0006b980:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0006b990:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0006b9a0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0006b9b0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0006b9c0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0006b9d0:·743d·2223·6964·6d31·3734·3330·2220·7461··t="#idm17430"·ta
 0006b9e0:·6269·6e64·6578·3d22·3022·2072·6f6c·653d··bindex="0"·role=
 0006b9f0:·2262·7574·746f·6e22·2061·7269·612d·6578··"button"·aria-ex
 0006ba00:·7061·6e64·6564·3d22·6661·6c73·6522·2074··panded="false"·t
 0006ba10:·6974·6c65·3d22·4163·7469·7661·7465·2074··itle="Activate·t
 0006ba20:·6f20·7265·7665·616c·2220·6872·6566·3d22··o·reveal"·href="
 0006ba30:·2321·223e·5265·6d65·6469·6174·696f·6e20··#!">Remediation·
 0006ba40:·416e·7369·626c·6520·736e·6970·7065·7420··Ansible·snippet·
 0006ba50:·e287·b23c·2f61·3e3c·6272·3e3c·6469·7620··...</a><br><div·
 0006ba60:·636c·6173·733d·2270·616e·656c·2d63·6f6c··class="panel-col
 0006ba70:·6c61·7073·6520·636f·6c6c·6170·7365·2220··lapse·collapse"·
 0006ba80:·6964·3d22·6964·6d31·3734·3330·223e·3c74··id="idm17430"><t
 0006ba90:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0006baa0:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0006bab0:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0006bac0:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0006bad0:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0006bae0:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0006baf0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0006bb00:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0006bb10:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0006bb20:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0006bb30:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0006bb40:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0006bb50:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0006bb60:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0006bb70:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0006bb80:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4761··<code>-·name:·Ga
 0006bb90:·7468·6572·2074·6865·2070·6163·6b61·6765··ther·the·package
 0006bba0:·2066·6163·7473·0a20·2070·6163·6b61·6765···facts.··package
 0006bbb0:·5f66·6163·7473·3a0a·2020·2020·6d61·6e61··_facts:.····mana
 0006bbc0:·6765·723a·2061·7574·6f0a·2020·7461·6773··ger:·auto.··tags
 0006bbd0:·3a0a·2020·2d20·4343·452d·3931·3136·312d··:.··-·CCE-91161-
 0006bbe0:·300a·2020·2d20·4e49·5354·2d38·3030·2d35··0.··-·NIST-800-5
 0006bbf0:·332d·434d·2d36·2861·290a·2020·2d20·656e··3-CM-6(a).··-·en
 0006bc00:·6162·6c65·5f73·7472·6174·6567·790a·2020··able_strategy.··
 0006bc10:·2d20·6c6f·775f·636f·6d70·6c65·7869·7479··-·low_complexity
 0006bc20:·0a20·202d·206c·6f77·5f64·6973·7275·7074··.··-·low_disrupt
 0006bc30:·696f·6e0a·2020·2d20·6d65·6469·756d·5f73··ion.··-·medium_s
 0006bc40:·6576·6572·6974·790a·2020·2d20·6e6f·5f72··everity.··-·no_r
 0006bc50:·6562·6f6f·745f·6e65·6564·6564·0a20·202d··eboot_needed.··-
 0006bc60:·2070·6163·6b61·6765·5f72·7379·736c·6f67···package_rsyslog
 0006bc70:·5f69·6e73·7461·6c6c·6564·0a0a·2d20·6e61··_installed..-·na
 0006bc80:·6d65·3a20·456e·7375·7265·2072·7379·736c··me:·Ensure·rsysl
 0006bc90:·6f67·2069·7320·696e·7374·616c·6c65·640a··og·is·installed.
 0006bca0:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n
 0006bcb0:·616d·653a·2072·7379·736c·6f67·0a20·2020··ame:·rsyslog.···
 0006bcc0:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.
 0006bcd0:·2020·7768·656e·3a20·2722·6b65·726e·656c····when:·'"kernel
 0006bce0:·2d64·6566·6175·6c74·2220·696e·2061·6e73··-default"·in·ans
 0006bcf0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
 0006bd00:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-
 0006bd10:·2043·4345·2d39·3131·3631·2d30·0a20·202d···CCE-91161-0.··-
 0006bd20:·204e·4953·542d·3830·302d·3533·2d43·4d2d···NIST-800-53-CM-
 0006bd30:·3628·6129·0a20·202d·2065·6e61·626c·655f··6(a).··-·enable_
 0006bd40:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
 0006bd50:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
 0006bd60:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
 0006bd70:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
 0006bd80:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
 0006bd90:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack
 0006bda0:·6167·655f·7273·7973·6c6f·675f·696e·7374··age_rsyslog_inst
 0006bdb0:·616c·6c65·640a·3c2f·636f·6465·3e3c·2f70··alled.</code></p
 0006bdc0:·7265·3e3c·2f64·6976·3e3c·6120·636c·6173··re></div><a·clas
 0006bdd0:·733d·2262·746e·2062·746e·2d73·7563·6365··s="btn·btn-succe
 0006bde0:·7373·2220·6461·7461·2d74·6f67·676c·653d··ss"·data-toggle=
 0006bdf0:·2263·6f6c·6c61·7073·6522·2064·6174·612d··"collapse"·data-
 0006be00:·7461·7267·6574·3d22·2369·646d·3137·3433··target="#idm1743
 0006be10:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·
 0006be20:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar
 0006be30:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal
 0006be40:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ
 0006be50:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h
 0006be60:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia
0006b770:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu0006be70:·7469·6f6e·204f·5342·7569·6c64·2042·6c75··tion·OSBuild·Blu
0006b780:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.0006be80:·6570·7269·6e74·2073·6e69·7070·6574·20e2··eprint·snippet·.
0006b790:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c0006be90:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0006b7a0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll0006bea0:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0006b7b0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i0006beb0:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0006b7c0:·643d·2269·646d·3137·3432·3922·3e3c·7072··d="idm17429"><pr0006bec0:·643d·2269·646d·3137·3433·3122·3e3c·7072··d="idm17431"><pr
0006b7d0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa0006bed0:·653e·3c63·6f64·653e·0a5b·5b70·6163·6b61··e><code>.[[packa
0006b7e0:·6765·735d·5d0a·6e61·6d65·203d·2022·7273··ges]].name·=·"rs0006bee0:·6765·735d·5d0a·6e61·6d65·203d·2022·7273··ges]].name·=·"rs
Max diff block lines reached; 238334/255750 bytes (93.19%) of diff not shown.
17.5 KB
html2text {}
    
Offset 3371, 19 lines modifiedOffset 3371, 14 lines modified
3371 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.93371 References:··_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9
3372 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.13372 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1
3373 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)3373 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
3374 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-13374 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.PT-1
3375 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-3375 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000479-GPOS-00224,·SRG-OS-000051-GPOS-00024,·SRG-OS-000480-GPOS-
3376 ····························002273376 ····························00227
3377 ·············_\x8c_\x8i_\x8s············4.2.1.13377 ·············_\x8c_\x8i_\x8s············4.2.1.1
3378 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3379 [[packages]] 
3380 name·=·"rsyslog" 
3381 version·=·"*" 
3382 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83378 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3383 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3379 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3384 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3380 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3385 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3381 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3386 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3382 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3387 #·Remediation·is·applicable·only·in·certain·platforms3383 #·Remediation·is·applicable·only·in·certain·platforms
3388 if·rpm·--quiet·-q·kernel-default;·then3384 if·rpm·--quiet·-q·kernel-default;·then
Offset 3421, 14 lines modifiedOffset 3416, 19 lines modified
3421 ··-·NIST-800-53-CM-6(a)3416 ··-·NIST-800-53-CM-6(a)
3422 ··-·enable_strategy3417 ··-·enable_strategy
3423 ··-·low_complexity3418 ··-·low_complexity
3424 ··-·low_disruption3419 ··-·low_disruption
3425 ··-·medium_severity3420 ··-·medium_severity
3426 ··-·no_reboot_needed3421 ··-·no_reboot_needed
3427 ··-·package_rsyslog_installed3422 ··-·package_rsyslog_installed
 3423 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3424 [[packages]]
 3425 name·=·"rsyslog"
 3426 version·=·"*"
3428 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83427 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3429 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3428 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3430 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3429 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3431 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3430 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3432 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3431 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3433 include·install_rsyslog3432 include·install_rsyslog
  
Offset 3456, 18 lines modifiedOffset 3456, 14 lines modified
3456 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,·SR·7.23456 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·SR·2.10,·SR·2.11,·SR·2.12,·SR·2.8,·SR·2.9,·SR·6.1,·SR·6.2,·SR·7.1,·SR·7.2
3457 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,3457 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.3,·A.12.4.1,·A.12.4.2,·A.12.4.3,·A.12.4.4,·A.12.7.1,·A.14.2.7,
3458 ····························A.15.2.1,·A.15.2.2,·A.17.2.13458 ····························A.15.2.1,·A.15.2.2,·A.17.2.1
3459 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)3459 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a),·AU-4(1)
3460 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-13460 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······DE.CM-1,·DE.CM-3,·DE.CM-7,·ID.SC-4,·PR.DS-4,·PR.PT-1
3461 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002273461 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
3462 ·············_\x8c_\x8i_\x8s············4.2.1.23462 ·············_\x8c_\x8i_\x8s············4.2.1.2
3463 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
3464 [customizations.services] 
3465 enabled·=·["rsyslog"] 
3466 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x83463 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
3467 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3464 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3468 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3465 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3469 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3466 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3470 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3467 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3471 #·Remediation·is·applicable·only·in·certain·platforms3468 #·Remediation·is·applicable·only·in·certain·platforms
3472 if·rpm·--quiet·-q·kernel-default;·then3469 if·rpm·--quiet·-q·kernel-default;·then
Offset 3523, 14 lines modifiedOffset 3519, 18 lines modified
3523 ··-·NIST-800-53-CM-6(a)3519 ··-·NIST-800-53-CM-6(a)
3524 ··-·enable_strategy3520 ··-·enable_strategy
3525 ··-·low_complexity3521 ··-·low_complexity
3526 ··-·low_disruption3522 ··-·low_disruption
3527 ··-·medium_severity3523 ··-·medium_severity
3528 ··-·no_reboot_needed3524 ··-·no_reboot_needed
3529 ··-·service_rsyslog_enabled3525 ··-·service_rsyslog_enabled
 3526 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 3527 [customizations.services]
 3528 enabled·=·["rsyslog"]
3530 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x83529 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
3531 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low3530 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
3532 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low3531 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
3533 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false3532 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
3534 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable3533 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
3535 include·enable_rsyslog3534 include·enable_rsyslog
  
Offset 9941, 19 lines modifiedOffset 9941, 14 lines modified
9941 ····························2.5,·SR·2.6,·SR·2.7,·SR·7.69941 ····························2.5,·SR·2.6,·SR·2.7,·SR·7.6
9942 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.29942 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2
9943 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)9943 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
9944 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-39944 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
9945 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-002279945 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000480-GPOS-00227
9946 ·············_\x8c_\x8i_\x8s············5.1.19946 ·············_\x8c_\x8i_\x8s············5.1.1
9947 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.29947 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········2.2.6,·2.2
9948 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9949 [[packages]] 
9950 name·=·"cronie" 
9951 version·=·"*" 
9952 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89948 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9953 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9949 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9954 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9950 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9955 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9951 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9956 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9952 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9957 #·Remediation·is·applicable·only·in·certain·platforms9953 #·Remediation·is·applicable·only·in·certain·platforms
9958 if·rpm·--quiet·-q·kernel-default;·then9954 if·rpm·--quiet·-q·kernel-default;·then
Offset 9995, 14 lines modifiedOffset 9990, 19 lines modified
9995 ··-·PCI-DSSv4-2.2.69990 ··-·PCI-DSSv4-2.2.6
9996 ··-·enable_strategy9991 ··-·enable_strategy
9997 ··-·low_complexity9992 ··-·low_complexity
9998 ··-·low_disruption9993 ··-·low_disruption
9999 ··-·medium_severity9994 ··-·medium_severity
10000 ··-·no_reboot_needed9995 ··-·no_reboot_needed
10001 ··-·package_cron_installed9996 ··-·package_cron_installed
 9997 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9998 [[packages]]
 9999 name·=·"cronie"
 10000 version·=·"*"
10002 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x810001 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
10003 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low10002 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
10004 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low10003 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
10005 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false10004 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
10006 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable10005 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
10007 include·install_cronie10006 include·install_cronie
  
Offset 10032, 18 lines modifiedOffset 10032, 14 lines modified
10032 ····························SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR10032 ····························SR·1.1,·SR·1.10,·SR·1.11,·SR·1.12,·SR·1.13,·SR·1.2,·SR·1.3,·SR·1.4,·SR
10033 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR10033 ·············_\x8i_\x8s_\x8a_\x8-_\x86_\x82_\x84_\x84_\x83_\x8-_\x82_\x80_\x81_\x83·1.5,·SR·1.6,·SR·1.7,·SR·1.8,·SR·1.9,·SR·2.1,·SR·2.2,·SR·2.3,·SR·2.4,·SR
10034 ····························2.5,·SR·2.6,·SR·2.7,·SR·7.610034 ····························2.5,·SR·2.6,·SR·2.7,·SR·7.6
10035 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.210035 ·············_\x8i_\x8s_\x8o_\x82_\x87_\x80_\x80_\x81_\x8-_\x82_\x80_\x81_\x83··A.12.1.2,·A.12.5.1,·A.12.6.2,·A.14.2.2,·A.14.2.3,·A.14.2.4,·A.9.1.2
10036 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)10036 ·············_\x8n_\x8i_\x8s_\x8t···········CM-6(a)
10037 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-310037 ·············_\x8n_\x8i_\x8s_\x8t_\x8-_\x8c_\x8s_\x8f·······PR.IP-1,·PR.PT-3
10038 ·············_\x8c_\x8i_\x8s············5.1.110038 ·············_\x8c_\x8i_\x8s············5.1.1
10039 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
Max diff block lines reached; 12164/17893 bytes (67.98%) of diff not shown.
284 KB
./usr/share/doc/ssg-nondebian/ssg-sle15-guide-stig.html
    
Offset 15106, 146 lines modifiedOffset 15106, 146 lines modified
0003b010:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=0003b010:·7365·2220·6461·7461·2d74·6172·6765·743d··se"·data-target=
0003b020:·2223·6964·6d36·3336·3122·2074·6162·696e··"#idm6361"·tabin0003b020:·2223·6964·6d36·3336·3122·2074·6162·696e··"#idm6361"·tabin
0003b030:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu0003b030:·6465·783d·2230·2220·726f·6c65·3d22·6275··dex="0"·role="bu
0003b040:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan0003b040:·7474·6f6e·2220·6172·6961·2d65·7870·616e··tton"·aria-expan
0003b050:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl0003b050:·6465·643d·2266·616c·7365·2220·7469·746c··ded="false"·titl
0003b060:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r0003b060:·653d·2241·6374·6976·6174·6520·746f·2072··e="Activate·to·r
0003b070:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"0003b070:·6576·6561·6c22·2068·7265·663d·2223·2122··eveal"·href="#!"
0003b080:·3e52·656d·6564·6961·7469·6f6e·204f·5342··>Remediation·OSB0003b080:·3e52·656d·6564·6961·7469·6f6e·2053·6865··>Remediation·She
0003b090:·7569·6c64·2042·6c75·6570·7269·6e74·2073··uild·Blueprint·s 
0003b0a0:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b 
0003b0b0:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa 
0003b0c0:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col 
0003b0d0:·6c61·7073·6522·2069·643d·2269·646d·3633··lapse"·id="idm630003b090:·6c6c·2073·6372·6970·7420·e287·b23c·2f61··ll·script·...</a
 0003b0a0:·3e3c·6272·3e3c·6469·7620·636c·6173·733d··><br><div·class=
 0003b0b0:·2270·616e·656c·2d63·6f6c·6c61·7073·6520··"panel-collapse·
 0003b0c0:·636f·6c6c·6170·7365·2220·6964·3d22·6964··collapse"·id="id
 0003b0d0:·6d36·3336·3122·3e3c·7461·626c·6520·636c··m6361"><table·cl
 0003b0e0:·6173·733d·2274·6162·6c65·2074·6162·6c65··ass="table·table
 0003b0f0:·2d73·7472·6970·6564·2074·6162·6c65·2d62··-striped·table-b
 0003b100:·6f72·6465·7265·6420·7461·626c·652d·636f··ordered·table-co
 0003b110:·6e64·656e·7365·6422·3e3c·7472·3e3c·7468··ndensed"><tr><th
 0003b120:·3e43·6f6d·706c·6578·6974·793a·3c2f·7468··>Complexity:</th
 0003b130:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b140:·723e·3c74·723e·3c74·683e·4469·7372·7570··r><tr><th>Disrup
 0003b150:·7469·6f6e·3a3c·2f74·683e·3c74·643e·6c6f··tion:</th><td>lo
 0003b160:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b170:·7468·3e52·6562·6f6f·743a·3c2f·7468·3e3c··th>Reboot:</th><
 0003b180:·7464·3e66·616c·7365·3c2f·7464·3e3c·2f74··td>false</td></t
 0003b190:·723e·3c74·723e·3c74·683e·5374·7261·7465··r><tr><th>Strate
 0003b1a0:·6779·3a3c·2f74·683e·3c74·643e·656e·6162··gy:</th><td>enab
 0003b1b0:·6c65·3c2f·7464·3e3c·2f74·723e·3c2f·7461··le</td></tr></ta
0003b0e0:·3631·223e·3c70·7265·3e3c·636f·6465·3e0a··61"><pre><code>.0003b1c0:·626c·653e·3c70·7265·3e3c·636f·6465·3e23··ble><pre><code>#
0003b0f0:·5b5b·7061·636b·6167·6573·5d5d·0a6e·616d··[[packages]].nam 
0003b100:·6520·3d20·2261·6964·6522·0a76·6572·7369··e·=·"aide".versi 
0003b110:·6f6e·203d·2022·2a22·0a3c·2f63·6f64·653e··on·=·"*".</code>0003b1d0:·2052·656d·6564·6961·7469·6f6e·2069·7320···Remediation·is·
 0003b1e0:·6170·706c·6963·6162·6c65·206f·6e6c·7920··applicable·only·
 0003b1f0:·696e·2063·6572·7461·696e·2070·6c61·7466··in·certain·platf
 0003b200:·6f72·6d73·0a69·6620·7270·6d20·2d2d·7175··orms.if·rpm·--qu
 0003b210:·6965·7420·2d71·206b·6572·6e65·6c2d·6465··iet·-q·kernel-de
 0003b220:·6661·756c·743b·2074·6865·6e0a·0a7a·7970··fault;·then..zyp
 0003b230:·7065·7220·696e·7374·616c·6c20·2d79·2022··per·install·-y·"
 0003b240:·6169·6465·220a·0a65·6c73·650a·2020·2020··aide"..else.····
 0003b250:·2667·743b·2661·6d70·3b32·2065·6368·6f20··&gt;&amp;2·echo·
 0003b260:·2752·656d·6564·6961·7469·6f6e·2069·7320··'Remediation·is·
 0003b270:·6e6f·7420·6170·706c·6963·6162·6c65·2c20··not·applicable,·
 0003b280:·6e6f·7468·696e·6720·7761·7320·646f·6e65··nothing·was·done
 0003b290:·270a·6669·0a3c·2f63·6f64·653e·3c2f·7072··'.fi.</code></pr
0003b120:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c0003b2a0:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class
0003b130:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su0003b2b0:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes
0003b140:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg0003b2c0:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle="
0003b150:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da0003b2d0:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t
0003b160:·7461·2d74·6172·6765·743d·2223·6964·6d36··ta-target="#idm60003b2e0:·6172·6765·743d·2223·6964·6d36·3336·3222··arget="#idm6362"
0003b170:·3336·3222·2074·6162·696e·6465·783d·2230··362"·tabindex="00003b2f0:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro
0003b180:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·0003b300:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria
0003b190:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f0003b310:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false
0003b1a0:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act0003b320:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat
0003b1b0:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"0003b330:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre
0003b1c0:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed0003b340:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati
0003b1d0:·6961·7469·6f6e·2053·6865·6c6c·2073·6372··iation·Shell·scr0003b350:·6f6e·2041·6e73·6962·6c65·2073·6e69·7070··on·Ansible·snipp
 0003b360:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d
 0003b370:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-
 0003b380:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps
 0003b390:·6522·2069·643d·2269·646d·3633·3632·223e··e"·id="idm6362">
 0003b3a0:·3c74·6162·6c65·2063·6c61·7373·3d22·7461··<table·class="ta
 0003b3b0:·626c·6520·7461·626c·652d·7374·7269·7065··ble·table-stripe
 0003b3c0:·6420·7461·626c·652d·626f·7264·6572·6564··d·table-bordered
 0003b3d0:·2074·6162·6c65·2d63·6f6e·6465·6e73·6564···table-condensed
 0003b3e0:·223e·3c74·723e·3c74·683e·436f·6d70·6c65··"><tr><th>Comple
 0003b3f0:·7869·7479·3a3c·2f74·683e·3c74·643e·6c6f··xity:</th><td>lo
 0003b400:·773c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··w</td></tr><tr><
 0003b410:·7468·3e44·6973·7275·7074·696f·6e3a·3c2f··th>Disruption:</
 0003b420:·7468·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c··th><td>low</td><
 0003b430:·2f74·723e·3c74·723e·3c74·683e·5265·626f··/tr><tr><th>Rebo
 0003b440:·6f74·3a3c·2f74·683e·3c74·643e·6661·6c73··ot:</th><td>fals
 0003b450:·653c·2f74·643e·3c2f·7472·3e3c·7472·3e3c··e</td></tr><tr><
 0003b460:·7468·3e53·7472·6174·6567·793a·3c2f·7468··th>Strategy:</th
 0003b470:·3e3c·7464·3e65·6e61·626c·653c·2f74·643e··><td>enable</td>
 0003b480:·3c2f·7472·3e3c·2f74·6162·6c65·3e3c·7072··</tr></table><pr
 0003b490:·653e·3c63·6f64·653e·2d20·6e61·6d65·3a20··e><code>-·name:·
 0003b4a0:·4761·7468·6572·2074·6865·2070·6163·6b61··Gather·the·packa
 0003b4b0:·6765·2066·6163·7473·0a20·2070·6163·6b61··ge·facts.··packa
 0003b4c0:·6765·5f66·6163·7473·3a0a·2020·2020·6d61··ge_facts:.····ma
 0003b4d0:·6e61·6765·723a·2061·7574·6f0a·2020·7461··nager:·auto.··ta
 0003b4e0:·6773·3a0a·2020·2d20·4343·452d·3833·3238··gs:.··-·CCE-8328
 0003b4f0:·392d·390a·2020·2d20·434a·4953·2d35·2e31··9-9.··-·CJIS-5.1
 0003b500:·302e·312e·330a·2020·2d20·4449·5341·2d53··0.1.3.··-·DISA-S
 0003b510:·5449·472d·534c·4553·2d31·352d·3031·3034··TIG-SLES-15-0104
 0003b520:·3139·0a20·202d·204e·4953·542d·3830·302d··19.··-·NIST-800-
 0003b530:·3533·2d43·4d2d·3628·6129·0a20·202d·2050··53-CM-6(a).··-·P
 0003b540:·4349·2d44·5353·2d52·6571·2d31·312e·350a··CI-DSS-Req-11.5.
 0003b550:·2020·2d20·5043·492d·4453·5376·342d·3131····-·PCI-DSSv4-11
 0003b560:·2e35·2e32·0a20·202d·2065·6e61·626c·655f··.5.2.··-·enable_
 0003b570:·7374·7261·7465·6779·0a20·202d·206c·6f77··strategy.··-·low
 0003b580:·5f63·6f6d·706c·6578·6974·790a·2020·2d20··_complexity.··-·
 0003b590:·6c6f·775f·6469·7372·7570·7469·6f6e·0a20··low_disruption.·
 0003b5a0:·202d·206d·6564·6975·6d5f·7365·7665·7269···-·medium_severi
 0003b5b0:·7479·0a20·202d·206e·6f5f·7265·626f·6f74··ty.··-·no_reboot
 0003b5c0:·5f6e·6565·6465·640a·2020·2d20·7061·636b··_needed.··-·pack
 0003b5d0:·6167·655f·6169·6465·5f69·6e73·7461·6c6c··age_aide_install
 0003b5e0:·6564·0a0a·2d20·6e61·6d65·3a20·456e·7375··ed..-·name:·Ensu
 0003b5f0:·7265·2061·6964·6520·6973·2069·6e73·7461··re·aide·is·insta
 0003b600:·6c6c·6564·0a20·2070·6163·6b61·6765·3a0a··lled.··package:.
 0003b610:·2020·2020·6e61·6d65·3a20·6169·6465·0a20······name:·aide.·
 0003b620:·2020·2073·7461·7465·3a20·7072·6573·656e·····state:·presen
 0003b630:·740a·2020·7768·656e·3a20·2722·6b65·726e··t.··when:·'"kern
 0003b640:·656c·2d64·6566·6175·6c74·2220·696e·2061··el-default"·in·a
 0003b650:·6e73·6962·6c65·5f66·6163·7473·2e70·6163··nsible_facts.pac
 0003b660:·6b61·6765·7327·0a20·2074·6167·733a·0a20··kages'.··tags:.·
 0003b670:·202d·2043·4345·2d38·3332·3839·2d39·0a20···-·CCE-83289-9.·
 0003b680:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3
 0003b690:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
 0003b6a0:·4c45·532d·3135·2d30·3130·3431·390a·2020··LES-15-010419.··
 0003b6b0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 0003b6c0:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
 0003b6d0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
 0003b6e0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
 0003b6f0:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
 0003b700:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp
 0003b710:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
 0003b720:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
 0003b730:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
 0003b740:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
 0003b750:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a
 0003b760:·6964·655f·696e·7374·616c·6c65·640a·3c2f··ide_installed.</
 0003b770:·636f·6465·3e3c·2f70·7265·3e3c·2f64·6976··code></pre></div
 0003b780:·3e3c·6120·636c·6173·733d·2262·746e·2062··><a·class="btn·b
 0003b790:·746e·2d73·7563·6365·7373·2220·6461·7461··tn-success"·data
Max diff block lines reached; 253932/272728 bytes (93.11%) of diff not shown.
17.8 KB
html2text {}
    
Offset 106, 19 lines modifiedOffset 106, 14 lines modified
106 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5106 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199107 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
108 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419108 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLES-15-010419
109 ·············_\x8c_\x8i_\x8s············1.4.1109 ·············_\x8c_\x8i_\x8s············1.4.1
110 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79110 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2111 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
112 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule112 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-255922r958794_rule
113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
114 [[packages]] 
115 name·=·"aide" 
116 version·=·"*" 
117 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8113 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
118 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low114 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
119 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low115 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
120 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false116 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
121 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable117 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
122 #·Remediation·is·applicable·only·in·certain·platforms118 #·Remediation·is·applicable·only·in·certain·platforms
123 if·rpm·--quiet·-q·kernel-default;·then119 if·rpm·--quiet·-q·kernel-default;·then
Offset 164, 14 lines modifiedOffset 159, 19 lines modified
164 ··-·PCI-DSSv4-11.5.2159 ··-·PCI-DSSv4-11.5.2
165 ··-·enable_strategy160 ··-·enable_strategy
166 ··-·low_complexity161 ··-·low_complexity
167 ··-·low_disruption162 ··-·low_disruption
168 ··-·medium_severity163 ··-·medium_severity
169 ··-·no_reboot_needed164 ··-·no_reboot_needed
170 ··-·package_aide_installed165 ··-·package_aide_installed
 166 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 167 [[packages]]
 168 name·=·"aide"
 169 version·=·"*"
171 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8170 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
172 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low171 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
173 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low172 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
174 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false173 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
175 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable174 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
176 include·install_aide175 include·install_aide
  
Offset 9309, 19 lines modifiedOffset 9309, 14 lines modified
9309 Severity: ···medium9309 Severity: ···medium
9310 Rule·ID:·····xccdf_org.ssgproject.content_rule_vlock_installed9310 Rule·ID:·····xccdf_org.ssgproject.content_rule_vlock_installed
9311 Identifiers:·CCE-83268-39311 Identifiers:·CCE-83268-3
9312 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-0000609312 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-000060
9313 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-000119313 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-00011
9314 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-0101109314 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010110
9315 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234811r1009610_rule9315 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234811r1009610_rule
9316 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
9317 [[packages]] 
9318 name·=·"kbd" 
9319 version·=·"*" 
9320 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x89316 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
9321 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9317 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9322 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9318 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9323 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9319 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9324 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9320 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9325 #·Remediation·is·applicable·only·in·certain·platforms9321 #·Remediation·is·applicable·only·in·certain·platforms
9326 if·rpm·--quiet·-q·kernel-default;·then9322 if·rpm·--quiet·-q·kernel-default;·then
Offset 9359, 14 lines modifiedOffset 9354, 19 lines modified
9359 ··-·DISA-STIG-SLES-15-0101109354 ··-·DISA-STIG-SLES-15-010110
9360 ··-·enable_strategy9355 ··-·enable_strategy
9361 ··-·low_complexity9356 ··-·low_complexity
9362 ··-·low_disruption9357 ··-·low_disruption
9363 ··-·medium_severity9358 ··-·medium_severity
9364 ··-·no_reboot_needed9359 ··-·no_reboot_needed
9365 ··-·vlock_installed9360 ··-·vlock_installed
 9361 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 9362 [[packages]]
 9363 name·=·"kbd"
 9364 version·=·"*"
9366 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x89365 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
9367 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low9366 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
9368 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low9367 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
9369 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false9368 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
9370 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable9369 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
9371 include·install_kbd9370 include·install_kbd
  
Offset 12243, 19 lines modifiedOffset 12243, 14 lines modified
12243 ·············_\x8n_\x8i_\x8s_\x8t····AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)12243 ·············_\x8n_\x8i_\x8s_\x8t····AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)
12244 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-12244 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-
12245 References:··········GPOS-00155,·SRG-OS-000480-GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-0023212245 References:··········GPOS-00155,·SRG-OS-000480-GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
12246 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-01039012246 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
12247 ·············_\x8c_\x8i_\x8s·····1.7.1.112247 ·············_\x8c_\x8i_\x8s·····1.7.1.1
12248 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R4512248 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
12249 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule12249 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
12250 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
12251 [[packages]] 
12252 name·=·"pam_apparmor" 
12253 version·=·"*" 
12254 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x812250 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
12255 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12251 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12256 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12252 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12257 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12253 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12258 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable12254 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
12259 #·Remediation·is·applicable·only·in·certain·platforms12255 #·Remediation·is·applicable·only·in·certain·platforms
12260 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then12256 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 12287, 14 lines modifiedOffset 12282, 19 lines modified
12287 ··-·NIST-800-53-SC-7(21)12282 ··-·NIST-800-53-SC-7(21)
12288 ··-·enable_strategy12283 ··-·enable_strategy
12289 ··-·low_complexity12284 ··-·low_complexity
12290 ··-·low_disruption12285 ··-·low_disruption
12291 ··-·medium_severity12286 ··-·medium_severity
12292 ··-·no_reboot_needed12287 ··-·no_reboot_needed
12293 ··-·package_pam_apparmor_installed12288 ··-·package_pam_apparmor_installed
 12289 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 12290 [[packages]]
 12291 name·=·"pam_apparmor"
 12292 version·=·"*"
12294 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x812293 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
12295 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low12294 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
12296 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low12295 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
12297 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false12296 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
12298 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable12297 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
12299 include·install_pam_apparmor12298 include·install_pam_apparmor
  
Offset 12329, 18 lines modifiedOffset 12329, 14 lines modified
12329 ·············_\x8n_\x8i_\x8s_\x8t····AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)12329 ·············_\x8n_\x8i_\x8s_\x8t····AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)
12330 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-12330 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-
12331 References:··········GPOS-00155,·SRG-OS-000480-GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-0023212331 References:··········GPOS-00155,·SRG-OS-000480-GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-00232
12332 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-01039012332 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLES-15-010390
12333 ·············_\x8c_\x8i_\x8s·····1.7.1.212333 ·············_\x8c_\x8i_\x8s·····1.7.1.2
12334 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R4512334 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R45
12335 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule12335 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-234848r958702_rule
Max diff block lines reached; 12601/18221 bytes (69.16%) of diff not shown.
966 KB
./usr/share/doc/ssg-nondebian/ssg-slmicro5-guide-cis.html
    
Offset 15193, 146 lines modifiedOffset 15193, 146 lines modified
0003b580:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b580:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#
0003b590:·6964·6d32·3837·3022·2074·6162·696e·6465··idm2870"·tabinde0003b590:·6964·6d32·3837·3022·2074·6162·696e·6465··idm2870"·tabinde
0003b5a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b5a0:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt
0003b5b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b5b0:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande
0003b5c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b5c0:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=
0003b5d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b5d0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev
0003b5e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b5e0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R
0003b5f0:·656d·6564·6961·7469·6f6e·204f·5342·7569··emediation·OSBui0003b5f0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell
0003b600:·6c64·2042·6c75·6570·7269·6e74·2073·6e69··ld·Blueprint·sni 
0003b610:·7070·6574·20e2·87b2·3c2f·613e·3c62·723e··ppet·...</a><br> 
0003b620:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b630:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b640:·7073·6522·2069·643d·2269·646d·3238·3730··pse"·id="idm28700003b600:·2073·6372·6970·7420·e287·b23c·2f61·3e3c···script·...</a><
 0003b610:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p
 0003b620:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co
 0003b630:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2
 0003b640:·3837·3022·3e3c·7461·626c·6520·636c·6173··870"><table·clas
 0003b650:·733d·2274·6162·6c65·2074·6162·6c65·2d73··s="table·table-s
 0003b660:·7472·6970·6564·2074·6162·6c65·2d62·6f72··triped·table-bor
 0003b670:·6465·7265·6420·7461·626c·652d·636f·6e64··dered·table-cond
 0003b680:·656e·7365·6422·3e3c·7472·3e3c·7468·3e43··ensed"><tr><th>C
 0003b690:·6f6d·706c·6578·6974·793a·3c2f·7468·3e3c··omplexity:</th><
 0003b6a0:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b6b0:·3c74·723e·3c74·683e·4469·7372·7570·7469··<tr><th>Disrupti
 0003b6c0:·6f6e·3a3c·2f74·683e·3c74·643e·6c6f·773c··on:</th><td>low<
 0003b6d0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b6e0:·3e52·6562·6f6f·743a·3c2f·7468·3e3c·7464··>Reboot:</th><td
 0003b6f0:·3e66·616c·7365·3c2f·7464·3e3c·2f74·723e··>false</td></tr>
 0003b700:·3c74·723e·3c74·683e·5374·7261·7465·6779··<tr><th>Strategy
 0003b710:·3a3c·2f74·683e·3c74·643e·656e·6162·6c65··:</th><td>enable
 0003b720:·3c2f·7464·3e3c·2f74·723e·3c2f·7461·626c··</td></tr></tabl
0003b650:·223e·3c70·7265·3e3c·636f·6465·3e0a·5b5b··"><pre><code>.[[0003b730:·653e·3c70·7265·3e3c·636f·6465·3e23·2052··e><pre><code>#·R
0003b660:·7061·636b·6167·6573·5d5d·0a6e·616d·6520··packages]].name· 
0003b670:·3d20·2261·6964·6522·0a76·6572·7369·6f6e··=·"aide".version 
0003b680:·203d·2022·2a22·0a3c·2f63·6f64·653e·3c2f···=·"*".</code></0003b740:·656d·6564·6961·7469·6f6e·2069·7320·6170··emediation·is·ap
 0003b750:·706c·6963·6162·6c65·206f·6e6c·7920·696e··plicable·only·in
 0003b760:·2063·6572·7461·696e·2070·6c61·7466·6f72···certain·platfor
 0003b770:·6d73·0a69·6620·7270·6d20·2d2d·7175·6965··ms.if·rpm·--quie
 0003b780:·7420·2d71·206b·6572·6e65·6c2d·6465·6661··t·-q·kernel-defa
 0003b790:·756c·743b·2074·6865·6e0a·0a7a·7970·7065··ult;·then..zyppe
 0003b7a0:·7220·696e·7374·616c·6c20·2d79·2022·6169··r·install·-y·"ai
 0003b7b0:·6465·220a·0a65·6c73·650a·2020·2020·2667··de"..else.····&g
 0003b7c0:·743b·2661·6d70·3b32·2065·6368·6f20·2752··t;&amp;2·echo·'R
 0003b7d0:·656d·6564·6961·7469·6f6e·2069·7320·6e6f··emediation·is·no
 0003b7e0:·7420·6170·706c·6963·6162·6c65·2c20·6e6f··t·applicable,·no
 0003b7f0:·7468·696e·6720·7761·7320·646f·6e65·270a··thing·was·done'.
 0003b800:·6669·0a3c·2f63·6f64·653e·3c2f·7072·653e··fi.</code></pre>
0003b690:·7072·653e·3c2f·6469·763e·3c61·2063·6c61··pre></div><a·cla0003b810:·3c2f·6469·763e·3c61·2063·6c61·7373·3d22··</div><a·class="
0003b6a0:·7373·3d22·6274·6e20·6274·6e2d·7375·6363··ss="btn·btn-succ0003b820:·6274·6e20·6274·6e2d·7375·6363·6573·7322··btn·btn-success"
0003b6b0:·6573·7322·2064·6174·612d·746f·6767·6c65··ess"·data-toggle0003b830:·2064·6174·612d·746f·6767·6c65·3d22·636f···data-toggle="co
0003b6c0:·3d22·636f·6c6c·6170·7365·2220·6461·7461··="collapse"·data0003b840:·6c6c·6170·7365·2220·6461·7461·2d74·6172··llapse"·data-tar
0003b6d0:·2d74·6172·6765·743d·2223·6964·6d32·3837··-target="#idm2870003b850:·6765·743d·2223·6964·6d32·3837·3122·2074··get="#idm2871"·t
0003b6e0:·3122·2074·6162·696e·6465·783d·2230·2220··1"·tabindex="0"·0003b860:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b6f0:·726f·6c65·3d22·6275·7474·6f6e·2220·6172··role="button"·ar0003b870:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b700:·6961·2d65·7870·616e·6465·643d·2266·616c··ia-expanded="fal0003b880:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b710:·7365·2220·7469·746c·653d·2241·6374·6976··se"·title="Activ0003b890:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b720:·6174·6520·746f·2072·6576·6561·6c22·2068··ate·to·reveal"·h0003b8a0:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b730:·7265·663d·2223·2122·3e52·656d·6564·6961··ref="#!">Remedia0003b8b0:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b740:·7469·6f6e·2053·6865·6c6c·2073·6372·6970··tion·Shell·scrip0003b8c0:·2041·6e73·6962·6c65·2073·6e69·7070·6574···Ansible·snippet
 0003b8d0:·20e2·87b2·3c2f·613e·3c62·723e·3c64·6976···...</a><br><div
 0003b8e0:·2063·6c61·7373·3d22·7061·6e65·6c2d·636f···class="panel-co
 0003b8f0:·6c6c·6170·7365·2063·6f6c·6c61·7073·6522··llapse·collapse"
 0003b900:·2069·643d·2269·646d·3238·3731·223e·3c74···id="idm2871"><t
 0003b910:·6162·6c65·2063·6c61·7373·3d22·7461·626c··able·class="tabl
 0003b920:·6520·7461·626c·652d·7374·7269·7065·6420··e·table-striped·
 0003b930:·7461·626c·652d·626f·7264·6572·6564·2074··table-bordered·t
 0003b940:·6162·6c65·2d63·6f6e·6465·6e73·6564·223e··able-condensed">
 0003b950:·3c74·723e·3c74·683e·436f·6d70·6c65·7869··<tr><th>Complexi
 0003b960:·7479·3a3c·2f74·683e·3c74·643e·6c6f·773c··ty:</th><td>low<
 0003b970:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b980:·3e44·6973·7275·7074·696f·6e3a·3c2f·7468··>Disruption:</th
 0003b990:·3e3c·7464·3e6c·6f77·3c2f·7464·3e3c·2f74··><td>low</td></t
 0003b9a0:·723e·3c74·723e·3c74·683e·5265·626f·6f74··r><tr><th>Reboot
 0003b9b0:·3a3c·2f74·683e·3c74·643e·6661·6c73·653c··:</th><td>false<
 0003b9c0:·2f74·643e·3c2f·7472·3e3c·7472·3e3c·7468··/td></tr><tr><th
 0003b9d0:·3e53·7472·6174·6567·793a·3c2f·7468·3e3c··>Strategy:</th><
 0003b9e0:·7464·3e65·6e61·626c·653c·2f74·643e·3c2f··td>enable</td></
 0003b9f0:·7472·3e3c·2f74·6162·6c65·3e3c·7072·653e··tr></table><pre>
 0003ba00:·3c63·6f64·653e·2d20·6e61·6d65·3a20·4761··<code>-·name:·Ga
 0003ba10:·7468·6572·2074·6865·2070·6163·6b61·6765··ther·the·package
 0003ba20:·2066·6163·7473·0a20·2070·6163·6b61·6765···facts.··package
 0003ba30:·5f66·6163·7473·3a0a·2020·2020·6d61·6e61··_facts:.····mana
 0003ba40:·6765·723a·2061·7574·6f0a·2020·7461·6773··ger:·auto.··tags
 0003ba50:·3a0a·2020·2d20·4343·452d·3933·3735·382d··:.··-·CCE-93758-
 0003ba60:·310a·2020·2d20·434a·4953·2d35·2e31·302e··1.··-·CJIS-5.10.
 0003ba70:·312e·330a·2020·2d20·4449·5341·2d53·5449··1.3.··-·DISA-STI
 0003ba80:·472d·534c·454d·2d30·352d·3635·3130·3130··G-SLEM-05-651010
 0003ba90:·0a20·202d·204e·4953·542d·3830·302d·3533··.··-·NIST-800-53
 0003baa0:·2d43·4d2d·3628·6129·0a20·202d·2050·4349··-CM-6(a).··-·PCI
 0003bab0:·2d44·5353·2d52·6571·2d31·312e·350a·2020··-DSS-Req-11.5.··
 0003bac0:·2d20·5043·492d·4453·5376·342d·3131·2e35··-·PCI-DSSv4-11.5
 0003bad0:·2e32·0a20·202d·2065·6e61·626c·655f·7374··.2.··-·enable_st
 0003bae0:·7261·7465·6779·0a20·202d·206c·6f77·5f63··rategy.··-·low_c
 0003baf0:·6f6d·706c·6578·6974·790a·2020·2d20·6c6f··omplexity.··-·lo
 0003bb00:·775f·6469·7372·7570·7469·6f6e·0a20·202d··w_disruption.··-
 0003bb10:·206d·6564·6975·6d5f·7365·7665·7269·7479···medium_severity
 0003bb20:·0a20·202d·206e·6f5f·7265·626f·6f74·5f6e··.··-·no_reboot_n
 0003bb30:·6565·6465·640a·2020·2d20·7061·636b·6167··eeded.··-·packag
 0003bb40:·655f·6169·6465·5f69·6e73·7461·6c6c·6564··e_aide_installed
 0003bb50:·0a0a·2d20·6e61·6d65·3a20·456e·7375·7265··..-·name:·Ensure
 0003bb60:·2061·6964·6520·6973·2069·6e73·7461·6c6c···aide·is·install
 0003bb70:·6564·0a20·2070·6163·6b61·6765·3a0a·2020··ed.··package:.··
 0003bb80:·2020·6e61·6d65·3a20·6169·6465·0a20·2020····name:·aide.···
 0003bb90:·2073·7461·7465·3a20·7072·6573·656e·740a···state:·present.
 0003bba0:·2020·7768·656e·3a20·2722·6b65·726e·656c····when:·'"kernel
 0003bbb0:·2d64·6566·6175·6c74·2220·696e·2061·6e73··-default"·in·ans
 0003bbc0:·6962·6c65·5f66·6163·7473·2e70·6163·6b61··ible_facts.packa
 0003bbd0:·6765·7327·0a20·2074·6167·733a·0a20·202d··ges'.··tags:.··-
 0003bbe0:·2043·4345·2d39·3337·3538·2d31·0a20·202d···CCE-93758-1.··-
 0003bbf0:·2043·4a49·532d·352e·3130·2e31·2e33·0a20···CJIS-5.10.1.3.·
 0003bc00:·202d·2044·4953·412d·5354·4947·2d53·4c45···-·DISA-STIG-SLE
 0003bc10:·4d2d·3035·2d36·3531·3031·300a·2020·2d20··M-05-651010.··-·
 0003bc20:·4e49·5354·2d38·3030·2d35·332d·434d·2d36··NIST-800-53-CM-6
 0003bc30:·2861·290a·2020·2d20·5043·492d·4453·532d··(a).··-·PCI-DSS-
 0003bc40:·5265·712d·3131·2e35·0a20·202d·2050·4349··Req-11.5.··-·PCI
 0003bc50:·2d44·5353·7634·2d31·312e·352e·320a·2020··-DSSv4-11.5.2.··
 0003bc60:·2d20·656e·6162·6c65·5f73·7472·6174·6567··-·enable_strateg
 0003bc70:·790a·2020·2d20·6c6f·775f·636f·6d70·6c65··y.··-·low_comple
 0003bc80:·7869·7479·0a20·202d·206c·6f77·5f64·6973··xity.··-·low_dis
 0003bc90:·7275·7074·696f·6e0a·2020·2d20·6d65·6469··ruption.··-·medi
 0003bca0:·756d·5f73·6576·6572·6974·790a·2020·2d20··um_severity.··-·
 0003bcb0:·6e6f·5f72·6562·6f6f·745f·6e65·6564·6564··no_reboot_needed
 0003bcc0:·0a20·202d·2070·6163·6b61·6765·5f61·6964··.··-·package_aid
 0003bcd0:·655f·696e·7374·616c·6c65·640a·3c2f·636f··e_installed.</co
 0003bce0:·6465·3e3c·2f70·7265·3e3c·2f64·6976·3e3c··de></pre></div><
 0003bcf0:·6120·636c·6173·733d·2262·746e·2062·746e··a·class="btn·btn
 0003bd00:·2d73·7563·6365·7373·2220·6461·7461·2d74··-success"·data-t
Max diff block lines reached; 921334/940130 bytes (98.00%) of diff not shown.
48.3 KB
html2text {}
    
Offset 131, 19 lines modifiedOffset 131, 14 lines modified
131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
132 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199132 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
133 ·············_\x8c_\x8i_\x8s············1.4.1133 ·············_\x8c_\x8i_\x8s············1.4.1
134 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79134 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
135 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2135 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
136 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010136 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010
137 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule137 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
139 [[packages]] 
140 name·=·"aide" 
141 version·=·"*" 
142 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
143 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
144 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
145 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
146 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
147 #·Remediation·is·applicable·only·in·certain·platforms143 #·Remediation·is·applicable·only·in·certain·platforms
148 if·rpm·--quiet·-q·kernel-default;·then144 if·rpm·--quiet·-q·kernel-default;·then
Offset 189, 14 lines modifiedOffset 184, 19 lines modified
189 ··-·PCI-DSSv4-11.5.2184 ··-·PCI-DSSv4-11.5.2
190 ··-·enable_strategy185 ··-·enable_strategy
191 ··-·low_complexity186 ··-·low_complexity
192 ··-·low_disruption187 ··-·low_disruption
193 ··-·medium_severity188 ··-·medium_severity
194 ··-·no_reboot_needed189 ··-·no_reboot_needed
195 ··-·package_aide_installed190 ··-·package_aide_installed
 191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 192 [[packages]]
 193 name·=·"aide"
 194 version·=·"*"
196 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
197 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
198 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
199 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
200 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
201 include·install_aide200 include·install_aide
  
Offset 799, 19 lines modifiedOffset 799, 14 lines modified
799 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386799 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
800 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)800 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
801 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1801 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
802 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125802 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
803 ·············_\x8c_\x8i_\x8s·····1.3.1803 ·············_\x8c_\x8i_\x8s·····1.3.1
804 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33804 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
805 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2805 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
806 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
807 [[packages]] 
808 name·=·"sudo" 
809 version·=·"*" 
810 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8806 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
811 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low807 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
812 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low808 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
813 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false809 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
814 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable810 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
815 #·Remediation·is·applicable·only·in·certain·platforms811 #·Remediation·is·applicable·only·in·certain·platforms
816 if·rpm·--quiet·-q·kernel-default;·then812 if·rpm·--quiet·-q·kernel-default;·then
Offset 853, 14 lines modifiedOffset 848, 19 lines modified
853 ··-·PCI-DSSv4-2.2.6848 ··-·PCI-DSSv4-2.2.6
854 ··-·enable_strategy849 ··-·enable_strategy
855 ··-·low_complexity850 ··-·low_complexity
856 ··-·low_disruption851 ··-·low_disruption
857 ··-·medium_severity852 ··-·medium_severity
858 ··-·no_reboot_needed853 ··-·no_reboot_needed
859 ··-·package_sudo_installed854 ··-·package_sudo_installed
 855 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 856 [[packages]]
 857 name·=·"sudo"
 858 version·=·"*"
860 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8859 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
861 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low860 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
862 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low861 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
863 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false862 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
864 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable863 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
865 include·install_sudo864 include·install_sudo
  
Offset 8943, 19 lines modifiedOffset 8943, 14 lines modified
8943 ·············_\x8n_\x8i_\x8s_\x8t···AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)8943 ·············_\x8n_\x8i_\x8s_\x8t···AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)
8944 ····················SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-8944 ····················SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-
8945 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-8945 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
8946 ····················GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-8946 ····················GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
8947 ····················002328947 ····················00232
8948 ·············_\x8c_\x8i_\x8s····1.7.1.18948 ·············_\x8c_\x8i_\x8s····1.7.1.1
8949 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R458949 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
8950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
8951 [[packages]] 
8952 name·=·"pam_apparmor" 
8953 version·=·"*" 
8954 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x88950 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
8955 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8951 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8956 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8952 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8957 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8953 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8958 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8954 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8959 #·Remediation·is·applicable·only·in·certain·platforms8955 #·Remediation·is·applicable·only·in·certain·platforms
8960 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8956 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 8986, 14 lines modifiedOffset 8981, 19 lines modified
8986 ··-·NIST-800-53-SC-7(21)8981 ··-·NIST-800-53-SC-7(21)
8987 ··-·enable_strategy8982 ··-·enable_strategy
8988 ··-·low_complexity8983 ··-·low_complexity
8989 ··-·low_disruption8984 ··-·low_disruption
8990 ··-·medium_severity8985 ··-·medium_severity
8991 ··-·no_reboot_needed8986 ··-·no_reboot_needed
8992 ··-·package_pam_apparmor_installed8987 ··-·package_pam_apparmor_installed
 8988 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 8989 [[packages]]
 8990 name·=·"pam_apparmor"
 8991 version·=·"*"
8993 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88992 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8994 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8993 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8995 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8994 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8996 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8995 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8997 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8996 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8998 include·install_pam_apparmor8997 include·install_pam_apparmor
  
Offset 9492, 19 lines modifiedOffset 9492, 14 lines modified
9492 ·············stored·on·the·local·system.9492 ·············stored·on·the·local·system.
9493 Severity: ···medium9493 Severity: ···medium
9494 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed9494 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed
9495 Identifiers:·CCE-94085-89495 Identifiers:·CCE-94085-8
9496 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-002249496 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-00224
9497 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-6520109497 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-652010
9498 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule9498 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule
Max diff block lines reached; 44168/49396 bytes (89.42%) of diff not shown.
892 KB
./usr/share/doc/ssg-nondebian/ssg-slmicro5-guide-cis_server_l1.html
    
Offset 15186, 145 lines modifiedOffset 15186, 145 lines modified
0003b510:·6765·743d·2223·6964·6d32·3837·3022·2074··get="#idm2870"·t0003b510:·6765·743d·2223·6964·6d32·3837·3022·2074··get="#idm2870"·t
0003b520:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role0003b520:·6162·696e·6465·783d·2230·2220·726f·6c65··abindex="0"·role
0003b530:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e0003b530:·3d22·6275·7474·6f6e·2220·6172·6961·2d65··="button"·aria-e
0003b540:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·0003b540:·7870·616e·6465·643d·2266·616c·7365·2220··xpanded="false"·
0003b550:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·0003b550:·7469·746c·653d·2241·6374·6976·6174·6520··title="Activate·
0003b560:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=0003b560:·746f·2072·6576·6561·6c22·2068·7265·663d··to·reveal"·href=
0003b570:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation0003b570:·2223·2122·3e52·656d·6564·6961·7469·6f6e··"#!">Remediation
0003b580:·204f·5342·7569·6c64·2042·6c75·6570·7269···OSBuild·Bluepri 
0003b590:·6e74·2073·6e69·7070·6574·20e2·87b2·3c2f··nt·snippet·...</ 
0003b5a0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class 
0003b5b0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse 
0003b5c0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i 
0003b5d0:·646d·3238·3730·223e·3c70·7265·3e3c·636f··dm2870"><pre><co 
0003b5e0:·6465·3e0a·5b5b·7061·636b·6167·6573·5d5d··de>.[[packages]] 
0003b5f0:·0a6e·616d·6520·3d20·2261·6964·6522·0a76··.name·=·"aide".v 
0003b600:·6572·7369·6f6e·203d·2022·2a22·0a3c·2f63··ersion·=·"*".</c0003b580:·2053·6865·6c6c·2073·6372·6970·7420·e287···Shell·script·..
 0003b590:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b5a0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b5b0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b5c0:·3d22·6964·6d32·3837·3022·3e3c·7461·626c··="idm2870"><tabl
 0003b5d0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b5e0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b5f0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b600:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b610:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b620:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b630:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b640:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b650:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b660:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b670:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b680:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b690:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003b6a0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003b6b0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b6c0:·6465·3e23·2052·656d·6564·6961·7469·6f6e··de>#·Remediation
 0003b6d0:·2069·7320·6170·706c·6963·6162·6c65·206f···is·applicable·o
 0003b6e0:·6e6c·7920·696e·2063·6572·7461·696e·2070··nly·in·certain·p
 0003b6f0:·6c61·7466·6f72·6d73·0a69·6620·7270·6d20··latforms.if·rpm·
 0003b700:·2d2d·7175·6965·7420·2d71·206b·6572·6e65··--quiet·-q·kerne
 0003b710:·6c2d·6465·6661·756c·743b·2074·6865·6e0a··l-default;·then.
 0003b720:·0a7a·7970·7065·7220·696e·7374·616c·6c20··.zypper·install·
 0003b730:·2d79·2022·6169·6465·220a·0a65·6c73·650a··-y·"aide"..else.
 0003b740:·2020·2020·2667·743b·2661·6d70·3b32·2065······&gt;&amp;2·e
 0003b750:·6368·6f20·2752·656d·6564·6961·7469·6f6e··cho·'Remediation
 0003b760:·2069·7320·6e6f·7420·6170·706c·6963·6162···is·not·applicab
 0003b770:·6c65·2c20·6e6f·7468·696e·6720·7761·7320··le,·nothing·was·
 0003b780:·646f·6e65·270a·6669·0a3c·2f63·6f64·653e··done'.fi.</code>
0003b610:·6f64·653e·3c2f·7072·653e·3c2f·6469·763e··ode></pre></div>0003b790:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
0003b620:·3c61·2063·6c61·7373·3d22·6274·6e20·6274··<a·class="btn·bt0003b7a0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
0003b630:·6e2d·7375·6363·6573·7322·2064·6174·612d··n-success"·data-0003b7b0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
0003b640:·746f·6767·6c65·3d22·636f·6c6c·6170·7365··toggle="collapse0003b7c0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
0003b650:·2220·6461·7461·2d74·6172·6765·743d·2223··"·data-target="#0003b7d0:·7461·2d74·6172·6765·743d·2223·6964·6d32··ta-target="#idm2
0003b660:·6964·6d32·3837·3122·2074·6162·696e·6465··idm2871"·tabinde0003b7e0:·3837·3122·2074·6162·696e·6465·783d·2230··871"·tabindex="0
0003b670:·783d·2230·2220·726f·6c65·3d22·6275·7474··x="0"·role="butt0003b7f0:·2220·726f·6c65·3d22·6275·7474·6f6e·2220··"·role="button"·
0003b680:·6f6e·2220·6172·6961·2d65·7870·616e·6465··on"·aria-expande0003b800:·6172·6961·2d65·7870·616e·6465·643d·2266··aria-expanded="f
0003b690:·643d·2266·616c·7365·2220·7469·746c·653d··d="false"·title=0003b810:·616c·7365·2220·7469·746c·653d·2241·6374··alse"·title="Act
0003b6a0:·2241·6374·6976·6174·6520·746f·2072·6576··"Activate·to·rev0003b820:·6976·6174·6520·746f·2072·6576·6561·6c22··ivate·to·reveal"
0003b6b0:·6561·6c22·2068·7265·663d·2223·2122·3e52··eal"·href="#!">R0003b830:·2068·7265·663d·2223·2122·3e52·656d·6564···href="#!">Remed
0003b6c0:·656d·6564·6961·7469·6f6e·2053·6865·6c6c··emediation·Shell0003b840:·6961·7469·6f6e·2041·6e73·6962·6c65·2073··iation·Ansible·s
 0003b850:·6e69·7070·6574·20e2·87b2·3c2f·613e·3c62··nippet·...</a><b
 0003b860:·723e·3c64·6976·2063·6c61·7373·3d22·7061··r><div·class="pa
 0003b870:·6e65·6c2d·636f·6c6c·6170·7365·2063·6f6c··nel-collapse·col
 0003b880:·6c61·7073·6522·2069·643d·2269·646d·3238··lapse"·id="idm28
 0003b890:·3731·223e·3c74·6162·6c65·2063·6c61·7373··71"><table·class
 0003b8a0:·3d22·7461·626c·6520·7461·626c·652d·7374··="table·table-st
 0003b8b0:·7269·7065·6420·7461·626c·652d·626f·7264··riped·table-bord
 0003b8c0:·6572·6564·2074·6162·6c65·2d63·6f6e·6465··ered·table-conde
 0003b8d0:·6e73·6564·223e·3c74·723e·3c74·683e·436f··nsed"><tr><th>Co
 0003b8e0:·6d70·6c65·7869·7479·3a3c·2f74·683e·3c74··mplexity:</th><t
 0003b8f0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b900:·7472·3e3c·7468·3e44·6973·7275·7074·696f··tr><th>Disruptio
 0003b910:·6e3a·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f··n:</th><td>low</
 0003b920:·7464·3e3c·2f74·723e·3c74·723e·3c74·683e··td></tr><tr><th>
 0003b930:·5265·626f·6f74·3a3c·2f74·683e·3c74·643e··Reboot:</th><td>
 0003b940:·6661·6c73·653c·2f74·643e·3c2f·7472·3e3c··false</td></tr><
 0003b950:·7472·3e3c·7468·3e53·7472·6174·6567·793a··tr><th>Strategy:
 0003b960:·3c2f·7468·3e3c·7464·3e65·6e61·626c·653c··</th><td>enable<
 0003b970:·2f74·643e·3c2f·7472·3e3c·2f74·6162·6c65··/td></tr></table
 0003b980:·3e3c·7072·653e·3c63·6f64·653e·2d20·6e61··><pre><code>-·na
 0003b990:·6d65·3a20·4761·7468·6572·2074·6865·2070··me:·Gather·the·p
 0003b9a0:·6163·6b61·6765·2066·6163·7473·0a20·2070··ackage·facts.··p
 0003b9b0:·6163·6b61·6765·5f66·6163·7473·3a0a·2020··ackage_facts:.··
 0003b9c0:·2020·6d61·6e61·6765·723a·2061·7574·6f0a····manager:·auto.
 0003b9d0:·2020·7461·6773·3a0a·2020·2d20·4343·452d····tags:.··-·CCE-
 0003b9e0:·3933·3735·382d·310a·2020·2d20·434a·4953··93758-1.··-·CJIS
 0003b9f0:·2d35·2e31·302e·312e·330a·2020·2d20·4449··-5.10.1.3.··-·DI
 0003ba00:·5341·2d53·5449·472d·534c·454d·2d30·352d··SA-STIG-SLEM-05-
 0003ba10:·3635·3130·3130·0a20·202d·204e·4953·542d··651010.··-·NIST-
 0003ba20:·3830·302d·3533·2d43·4d2d·3628·6129·0a20··800-53-CM-6(a).·
 0003ba30:·202d·2050·4349·2d44·5353·2d52·6571·2d31···-·PCI-DSS-Req-1
 0003ba40:·312e·350a·2020·2d20·5043·492d·4453·5376··1.5.··-·PCI-DSSv
 0003ba50:·342d·3131·2e35·2e32·0a20·202d·2065·6e61··4-11.5.2.··-·ena
 0003ba60:·626c·655f·7374·7261·7465·6779·0a20·202d··ble_strategy.··-
 0003ba70:·206c·6f77·5f63·6f6d·706c·6578·6974·790a···low_complexity.
 0003ba80:·2020·2d20·6c6f·775f·6469·7372·7570·7469····-·low_disrupti
 0003ba90:·6f6e·0a20·202d·206d·6564·6975·6d5f·7365··on.··-·medium_se
 0003baa0:·7665·7269·7479·0a20·202d·206e·6f5f·7265··verity.··-·no_re
 0003bab0:·626f·6f74·5f6e·6565·6465·640a·2020·2d20··boot_needed.··-·
 0003bac0:·7061·636b·6167·655f·6169·6465·5f69·6e73··package_aide_ins
 0003bad0:·7461·6c6c·6564·0a0a·2d20·6e61·6d65·3a20··talled..-·name:·
 0003bae0:·456e·7375·7265·2061·6964·6520·6973·2069··Ensure·aide·is·i
 0003baf0:·6e73·7461·6c6c·6564·0a20·2070·6163·6b61··nstalled.··packa
 0003bb00:·6765·3a0a·2020·2020·6e61·6d65·3a20·6169··ge:.····name:·ai
 0003bb10:·6465·0a20·2020·2073·7461·7465·3a20·7072··de.····state:·pr
 0003bb20:·6573·656e·740a·2020·7768·656e·3a20·2722··esent.··when:·'"
 0003bb30:·6b65·726e·656c·2d64·6566·6175·6c74·2220··kernel-default"·
 0003bb40:·696e·2061·6e73·6962·6c65·5f66·6163·7473··in·ansible_facts
 0003bb50:·2e70·6163·6b61·6765·7327·0a20·2074·6167··.packages'.··tag
 0003bb60:·733a·0a20·202d·2043·4345·2d39·3337·3538··s:.··-·CCE-93758
 0003bb70:·2d31·0a20·202d·2043·4a49·532d·352e·3130··-1.··-·CJIS-5.10
 0003bb80:·2e31·2e33·0a20·202d·2044·4953·412d·5354··.1.3.··-·DISA-ST
 0003bb90:·4947·2d53·4c45·4d2d·3035·2d36·3531·3031··IG-SLEM-05-65101
 0003bba0:·300a·2020·2d20·4e49·5354·2d38·3030·2d35··0.··-·NIST-800-5
 0003bbb0:·332d·434d·2d36·2861·290a·2020·2d20·5043··3-CM-6(a).··-·PC
 0003bbc0:·492d·4453·532d·5265·712d·3131·2e35·0a20··I-DSS-Req-11.5.·
 0003bbd0:·202d·2050·4349·2d44·5353·7634·2d31·312e···-·PCI-DSSv4-11.
 0003bbe0:·352e·320a·2020·2d20·656e·6162·6c65·5f73··5.2.··-·enable_s
 0003bbf0:·7472·6174·6567·790a·2020·2d20·6c6f·775f··trategy.··-·low_
 0003bc00:·636f·6d70·6c65·7869·7479·0a20·202d·206c··complexity.··-·l
 0003bc10:·6f77·5f64·6973·7275·7074·696f·6e0a·2020··ow_disruption.··
 0003bc20:·2d20·6d65·6469·756d·5f73·6576·6572·6974··-·medium_severit
 0003bc30:·790a·2020·2d20·6e6f·5f72·6562·6f6f·745f··y.··-·no_reboot_
 0003bc40:·6e65·6564·6564·0a20·202d·2070·6163·6b61··needed.··-·packa
 0003bc50:·6765·5f61·6964·655f·696e·7374·616c·6c65··ge_aide_installe
 0003bc60:·640a·3c2f·636f·6465·3e3c·2f70·7265·3e3c··d.</code></pre><
 0003bc70:·2f64·6976·3e3c·6120·636c·6173·733d·2262··/div><a·class="b
Max diff block lines reached; 850036/868694 bytes (97.85%) of diff not shown.
43.5 KB
html2text {}
    
Offset 130, 19 lines modifiedOffset 130, 14 lines modified
130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5130 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
131 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199131 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
132 ·············_\x8c_\x8i_\x8s············1.4.1132 ·············_\x8c_\x8i_\x8s············1.4.1
133 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79133 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
134 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2134 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
135 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010135 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010
136 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule136 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule
137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
138 [[packages]] 
139 name·=·"aide" 
140 version·=·"*" 
141 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8137 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
142 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low138 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
143 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low139 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
144 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false140 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
145 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable141 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
146 #·Remediation·is·applicable·only·in·certain·platforms142 #·Remediation·is·applicable·only·in·certain·platforms
147 if·rpm·--quiet·-q·kernel-default;·then143 if·rpm·--quiet·-q·kernel-default;·then
Offset 188, 14 lines modifiedOffset 183, 19 lines modified
188 ··-·PCI-DSSv4-11.5.2183 ··-·PCI-DSSv4-11.5.2
189 ··-·enable_strategy184 ··-·enable_strategy
190 ··-·low_complexity185 ··-·low_complexity
191 ··-·low_disruption186 ··-·low_disruption
192 ··-·medium_severity187 ··-·medium_severity
193 ··-·no_reboot_needed188 ··-·no_reboot_needed
194 ··-·package_aide_installed189 ··-·package_aide_installed
 190 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 191 [[packages]]
 192 name·=·"aide"
 193 version·=·"*"
195 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
196 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
197 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
198 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
199 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
200 include·install_aide199 include·install_aide
  
Offset 725, 19 lines modifiedOffset 725, 14 lines modified
725 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386725 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
726 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)726 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
727 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1727 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
728 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125728 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
729 ·············_\x8c_\x8i_\x8s·····1.3.1729 ·············_\x8c_\x8i_\x8s·····1.3.1
730 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33730 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
731 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2731 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
732 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
733 [[packages]] 
734 name·=·"sudo" 
735 version·=·"*" 
736 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8732 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
737 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low733 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
738 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low734 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
739 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false735 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
740 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable736 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
741 #·Remediation·is·applicable·only·in·certain·platforms737 #·Remediation·is·applicable·only·in·certain·platforms
742 if·rpm·--quiet·-q·kernel-default;·then738 if·rpm·--quiet·-q·kernel-default;·then
Offset 779, 14 lines modifiedOffset 774, 19 lines modified
779 ··-·PCI-DSSv4-2.2.6774 ··-·PCI-DSSv4-2.2.6
780 ··-·enable_strategy775 ··-·enable_strategy
781 ··-·low_complexity776 ··-·low_complexity
782 ··-·low_disruption777 ··-·low_disruption
783 ··-·medium_severity778 ··-·medium_severity
784 ··-·no_reboot_needed779 ··-·no_reboot_needed
785 ··-·package_sudo_installed780 ··-·package_sudo_installed
 781 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 782 [[packages]]
 783 name·=·"sudo"
 784 version·=·"*"
786 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8785 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
787 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low786 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
788 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low787 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
789 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false788 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
790 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable789 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
791 include·install_sudo790 include·install_sudo
  
Offset 8869, 19 lines modifiedOffset 8869, 14 lines modified
8869 ·············_\x8n_\x8i_\x8s_\x8t···AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)8869 ·············_\x8n_\x8i_\x8s_\x8t···AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)
8870 ····················SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-8870 ····················SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-
8871 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-8871 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
8872 ····················GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-8872 ····················GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
8873 ····················002328873 ····················00232
8874 ·············_\x8c_\x8i_\x8s····1.7.1.18874 ·············_\x8c_\x8i_\x8s····1.7.1.1
8875 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R458875 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
8876 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
8877 [[packages]] 
8878 name·=·"pam_apparmor" 
8879 version·=·"*" 
8880 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x88876 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
8881 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8877 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8882 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8878 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8883 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8879 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8884 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8880 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8885 #·Remediation·is·applicable·only·in·certain·platforms8881 #·Remediation·is·applicable·only·in·certain·platforms
8886 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8882 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 8912, 14 lines modifiedOffset 8907, 19 lines modified
8912 ··-·NIST-800-53-SC-7(21)8907 ··-·NIST-800-53-SC-7(21)
8913 ··-·enable_strategy8908 ··-·enable_strategy
8914 ··-·low_complexity8909 ··-·low_complexity
8915 ··-·low_disruption8910 ··-·low_disruption
8916 ··-·medium_severity8911 ··-·medium_severity
8917 ··-·no_reboot_needed8912 ··-·no_reboot_needed
8918 ··-·package_pam_apparmor_installed8913 ··-·package_pam_apparmor_installed
 8914 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 8915 [[packages]]
 8916 name·=·"pam_apparmor"
 8917 version·=·"*"
8919 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88918 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8920 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8919 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8921 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8920 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8922 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8921 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8923 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8922 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8924 include·install_pam_apparmor8923 include·install_pam_apparmor
  
Offset 9418, 19 lines modifiedOffset 9418, 14 lines modified
9418 ·············stored·on·the·local·system.9418 ·············stored·on·the·local·system.
9419 Severity: ···medium9419 Severity: ···medium
9420 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed9420 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed
9421 Identifiers:·CCE-94085-89421 Identifiers:·CCE-94085-8
9422 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-002249422 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-00224
9423 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-6520109423 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-652010
9424 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule9424 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule
Max diff block lines reached; 39244/44472 bytes (88.24%) of diff not shown.
761 KB
./usr/share/doc/ssg-nondebian/ssg-slmicro5-guide-cis_workstation_l1.html
    
Offset 15172, 146 lines modifiedOffset 15172, 146 lines modified
0003b430:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm0003b430:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm
0003b440:·3238·3730·2220·7461·6269·6e64·6578·3d22··2870"·tabindex="0003b440:·3238·3730·2220·7461·6269·6e64·6578·3d22··2870"·tabindex="
0003b450:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"0003b450:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button"
0003b460:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="0003b460:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded="
0003b470:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac0003b470:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac
0003b480:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal0003b480:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal
0003b490:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme0003b490:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme
0003b4a0:·6469·6174·696f·6e20·4f53·4275·696c·6420··diation·OSBuild·0003b4a0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc
0003b4b0:·426c·7565·7072·696e·7420·736e·6970·7065··Blueprint·snippe 
0003b4c0:·7420·e287·b23c·2f61·3e3c·6272·3e3c·6469··t·...</a><br><di 
0003b4d0:·7620·636c·6173·733d·2270·616e·656c·2d63··v·class="panel-c 
0003b4e0:·6f6c·6c61·7073·6520·636f·6c6c·6170·7365··ollapse·collapse 
0003b4f0:·2220·6964·3d22·6964·6d32·3837·3022·3e3c··"·id="idm2870"><0003b4b0:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br>
 0003b4c0:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane
 0003b4d0:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla
 0003b4e0:·7073·6522·2069·643d·2269·646d·3238·3730··pse"·id="idm2870
 0003b4f0:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class="
 0003b500:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri
 0003b510:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border
 0003b520:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens
 0003b530:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp
 0003b540:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td>
 0003b550:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr
 0003b560:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption:
 0003b570:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b580:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re
 0003b590:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa
 0003b5a0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr
 0003b5b0:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</
 0003b5c0:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t
 0003b5d0:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table><
0003b500:·7072·653e·3c63·6f64·653e·0a5b·5b70·6163··pre><code>.[[pac0003b5e0:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme
0003b510:·6b61·6765·735d·5d0a·6e61·6d65·203d·2022··kages]].name·=·" 
0003b520:·6169·6465·220a·7665·7273·696f·6e20·3d20··aide".version·=·0003b5f0:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli
 0003b600:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce
 0003b610:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms.
 0003b620:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·-
 0003b630:·7120·6b65·726e·656c·2d64·6566·6175·6c74··q·kernel-default
 0003b640:·3b20·7468·656e·0a0a·7a79·7070·6572·2069··;·then..zypper·i
 0003b650:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide"
 0003b660:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;&
 0003b670:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme
 0003b680:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a
 0003b690:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi
 0003b6a0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi.
0003b530:·222a·220a·3c2f·636f·6465·3e3c·2f70·7265··"*".</code></pre0003b6b0:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d
0003b540:·3e3c·2f64·6976·3e3c·6120·636c·6173·733d··></div><a·class=0003b6c0:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn
0003b550:·2262·746e·2062·746e·2d73·7563·6365·7373··"btn·btn-success0003b6d0:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da
0003b560:·2220·6461·7461·2d74·6f67·676c·653d·2263··"·data-toggle="c0003b6e0:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla
0003b570:·6f6c·6c61·7073·6522·2064·6174·612d·7461··ollapse"·data-ta0003b6f0:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b580:·7267·6574·3d22·2369·646d·3238·3731·2220··rget="#idm2871"·0003b700:·3d22·2369·646d·3238·3731·2220·7461·6269··="#idm2871"·tabi
0003b590:·7461·6269·6e64·6578·3d22·3022·2072·6f6c··tabindex="0"·rol0003b710:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b5a0:·653d·2262·7574·746f·6e22·2061·7269·612d··e="button"·aria-0003b720:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b5b0:·6578·7061·6e64·6564·3d22·6661·6c73·6522··expanded="false"0003b730:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b5c0:·2074·6974·6c65·3d22·4163·7469·7661·7465···title="Activate0003b740:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b5d0:·2074·6f20·7265·7665·616c·2220·6872·6566···to·reveal"·href0003b750:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b5e0:·3d22·2321·223e·5265·6d65·6469·6174·696f··="#!">Remediatio0003b760:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An
0003b5f0:·6e20·5368·656c·6c20·7363·7269·7074·20e2··n·Shell·script·.0003b770:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·..
 0003b780:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl
 0003b790:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla
 0003b7a0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id
 0003b7b0:·3d22·6964·6d32·3837·3122·3e3c·7461·626c··="idm2871"><tabl
 0003b7c0:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t
 0003b7d0:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab
 0003b7e0:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl
 0003b7f0:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr
 0003b800:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity:
 0003b810:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td
 0003b820:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di
 0003b830:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t
 0003b840:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr><
 0003b850:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</
 0003b860:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td
 0003b870:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St
 0003b880:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td>
 0003b890:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr>
 0003b8a0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co
 0003b8b0:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe
 0003b8c0:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa
 0003b8d0:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa
 0003b8e0:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager
 0003b8f0:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.·
 0003b900:·202d·2043·4345·2d39·3337·3538·2d31·0a20···-·CCE-93758-1.·
 0003b910:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3
 0003b920:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S
 0003b930:·4c45·4d2d·3035·2d36·3531·3031·300a·2020··LEM-05-651010.··
 0003b940:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM
 0003b950:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS
 0003b960:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P
 0003b970:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2.
 0003b980:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat
 0003b990:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp
 0003b9a0:·6c65·7869·7479·0a20·202d·206c·6f77·5f64··lexity.··-·low_d
 0003b9b0:·6973·7275·7074·696f·6e0a·2020·2d20·6d65··isruption.··-·me
 0003b9c0:·6469·756d·5f73·6576·6572·6974·790a·2020··dium_severity.··
 0003b9d0:·2d20·6e6f·5f72·6562·6f6f·745f·6e65·6564··-·no_reboot_need
 0003b9e0:·6564·0a20·202d·2070·6163·6b61·6765·5f61··ed.··-·package_a
 0003b9f0:·6964·655f·696e·7374·616c·6c65·640a·0a2d··ide_installed..-
 0003ba00:·206e·616d·653a·2045·6e73·7572·6520·6169···name:·Ensure·ai
 0003ba10:·6465·2069·7320·696e·7374·616c·6c65·640a··de·is·installed.
 0003ba20:·2020·7061·636b·6167·653a·0a20·2020·206e····package:.····n
 0003ba30:·616d·653a·2061·6964·650a·2020·2020·7374··ame:·aide.····st
 0003ba40:·6174·653a·2070·7265·7365·6e74·0a20·2077··ate:·present.··w
 0003ba50:·6865·6e3a·2027·226b·6572·6e65·6c2d·6465··hen:·'"kernel-de
 0003ba60:·6661·756c·7422·2069·6e20·616e·7369·626c··fault"·in·ansibl
 0003ba70:·655f·6661·6374·732e·7061·636b·6167·6573··e_facts.packages
 0003ba80:·270a·2020·7461·6773·3a0a·2020·2d20·4343··'.··tags:.··-·CC
 0003ba90:·452d·3933·3735·382d·310a·2020·2d20·434a··E-93758-1.··-·CJ
 0003baa0:·4953·2d35·2e31·302e·312e·330a·2020·2d20··IS-5.10.1.3.··-·
 0003bab0:·4449·5341·2d53·5449·472d·534c·454d·2d30··DISA-STIG-SLEM-0
 0003bac0:·352d·3635·3130·3130·0a20·202d·204e·4953··5-651010.··-·NIS
 0003bad0:·542d·3830·302d·3533·2d43·4d2d·3628·6129··T-800-53-CM-6(a)
 0003bae0:·0a20·202d·2050·4349·2d44·5353·2d52·6571··.··-·PCI-DSS-Req
 0003baf0:·2d31·312e·350a·2020·2d20·5043·492d·4453··-11.5.··-·PCI-DS
 0003bb00:·5376·342d·3131·2e35·2e32·0a20·202d·2065··Sv4-11.5.2.··-·e
 0003bb10:·6e61·626c·655f·7374·7261·7465·6779·0a20··nable_strategy.·
 0003bb20:·202d·206c·6f77·5f63·6f6d·706c·6578·6974···-·low_complexit
 0003bb30:·790a·2020·2d20·6c6f·775f·6469·7372·7570··y.··-·low_disrup
 0003bb40:·7469·6f6e·0a20·202d·206d·6564·6975·6d5f··tion.··-·medium_
 0003bb50:·7365·7665·7269·7479·0a20·202d·206e·6f5f··severity.··-·no_
 0003bb60:·7265·626f·6f74·5f6e·6565·6465·640a·2020··reboot_needed.··
 0003bb70:·2d20·7061·636b·6167·655f·6169·6465·5f69··-·package_aide_i
 0003bb80:·6e73·7461·6c6c·6564·0a3c·2f63·6f64·653e··nstalled.</code>
 0003bb90:·3c2f·7072·653e·3c2f·6469·763e·3c61·2063··</pre></div><a·c
 0003bba0:·6c61·7373·3d22·6274·6e20·6274·6e2d·7375··lass="btn·btn-su
 0003bbb0:·6363·6573·7322·2064·6174·612d·746f·6767··ccess"·data-togg
 0003bbc0:·6c65·3d22·636f·6c6c·6170·7365·2220·6461··le="collapse"·da
Max diff block lines reached; 720640/739436 bytes (97.46%) of diff not shown.
38.5 KB
html2text {}
    
Offset 127, 19 lines modifiedOffset 127, 14 lines modified
127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5127 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
128 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199128 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
129 ·············_\x8c_\x8i_\x8s············1.4.1129 ·············_\x8c_\x8i_\x8s············1.4.1
130 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79130 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2131 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
132 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010132 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010
133 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule133 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule
134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
135 [[packages]] 
136 name·=·"aide" 
137 version·=·"*" 
138 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8134 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
139 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low135 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
140 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low136 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
141 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false137 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
142 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable138 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
143 #·Remediation·is·applicable·only·in·certain·platforms139 #·Remediation·is·applicable·only·in·certain·platforms
144 if·rpm·--quiet·-q·kernel-default;·then140 if·rpm·--quiet·-q·kernel-default;·then
Offset 185, 14 lines modifiedOffset 180, 19 lines modified
185 ··-·PCI-DSSv4-11.5.2180 ··-·PCI-DSSv4-11.5.2
186 ··-·enable_strategy181 ··-·enable_strategy
187 ··-·low_complexity182 ··-·low_complexity
188 ··-·low_disruption183 ··-·low_disruption
189 ··-·medium_severity184 ··-·medium_severity
190 ··-·no_reboot_needed185 ··-·no_reboot_needed
191 ··-·package_aide_installed186 ··-·package_aide_installed
 187 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 188 [[packages]]
 189 name·=·"aide"
 190 version·=·"*"
192 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8191 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
193 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low192 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
194 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low193 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
195 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false194 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
196 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable195 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
197 include·install_aide196 include·install_aide
  
Offset 722, 19 lines modifiedOffset 722, 14 lines modified
722 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386722 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
723 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)723 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
724 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1724 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
725 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125725 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
726 ·············_\x8c_\x8i_\x8s·····1.3.1726 ·············_\x8c_\x8i_\x8s·····1.3.1
727 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33727 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
728 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2728 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
729 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
730 [[packages]] 
731 name·=·"sudo" 
732 version·=·"*" 
733 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8729 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
734 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low730 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
735 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low731 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
736 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false732 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
737 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable733 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
738 #·Remediation·is·applicable·only·in·certain·platforms734 #·Remediation·is·applicable·only·in·certain·platforms
739 if·rpm·--quiet·-q·kernel-default;·then735 if·rpm·--quiet·-q·kernel-default;·then
Offset 776, 14 lines modifiedOffset 771, 19 lines modified
776 ··-·PCI-DSSv4-2.2.6771 ··-·PCI-DSSv4-2.2.6
777 ··-·enable_strategy772 ··-·enable_strategy
778 ··-·low_complexity773 ··-·low_complexity
779 ··-·low_disruption774 ··-·low_disruption
780 ··-·medium_severity775 ··-·medium_severity
781 ··-·no_reboot_needed776 ··-·no_reboot_needed
782 ··-·package_sudo_installed777 ··-·package_sudo_installed
 778 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 779 [[packages]]
 780 name·=·"sudo"
 781 version·=·"*"
783 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8782 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
784 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low783 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
785 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low784 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
786 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false785 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
787 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable786 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
788 include·install_sudo787 include·install_sudo
  
Offset 8866, 19 lines modifiedOffset 8866, 14 lines modified
8866 ·············_\x8n_\x8i_\x8s_\x8t···AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)8866 ·············_\x8n_\x8i_\x8s_\x8t···AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)
8867 ····················SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-8867 ····················SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-
8868 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-8868 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
8869 ····················GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-8869 ····················GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
8870 ····················002328870 ····················00232
8871 ·············_\x8c_\x8i_\x8s····1.7.1.18871 ·············_\x8c_\x8i_\x8s····1.7.1.1
8872 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R458872 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
8873 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
8874 [[packages]] 
8875 name·=·"pam_apparmor" 
8876 version·=·"*" 
8877 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x88873 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
8878 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8874 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8879 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8875 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8880 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8876 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8881 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8877 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8882 #·Remediation·is·applicable·only·in·certain·platforms8878 #·Remediation·is·applicable·only·in·certain·platforms
8883 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8879 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 8909, 14 lines modifiedOffset 8904, 19 lines modified
8909 ··-·NIST-800-53-SC-7(21)8904 ··-·NIST-800-53-SC-7(21)
8910 ··-·enable_strategy8905 ··-·enable_strategy
8911 ··-·low_complexity8906 ··-·low_complexity
8912 ··-·low_disruption8907 ··-·low_disruption
8913 ··-·medium_severity8908 ··-·medium_severity
8914 ··-·no_reboot_needed8909 ··-·no_reboot_needed
8915 ··-·package_pam_apparmor_installed8910 ··-·package_pam_apparmor_installed
 8911 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 8912 [[packages]]
 8913 name·=·"pam_apparmor"
 8914 version·=·"*"
8916 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88915 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8917 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8916 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8918 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8917 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8919 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8918 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8920 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8919 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8921 include·install_pam_apparmor8920 include·install_pam_apparmor
  
Offset 9415, 19 lines modifiedOffset 9415, 14 lines modified
9415 ·············stored·on·the·local·system.9415 ·············stored·on·the·local·system.
9416 Severity: ···medium9416 Severity: ···medium
9417 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed9417 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed
9418 Identifiers:·CCE-94085-89418 Identifiers:·CCE-94085-8
9419 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-002249419 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-00224
9420 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-6520109420 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-652010
9421 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule9421 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule
Max diff block lines reached; 34155/39383 bytes (86.73%) of diff not shown.
926 KB
./usr/share/doc/ssg-nondebian/ssg-slmicro5-guide-cis_workstation_l2.html
    
Offset 15185, 146 lines modifiedOffset 15185, 146 lines modified
0003b500:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id0003b500:·6461·7461·2d74·6172·6765·743d·2223·6964··data-target="#id
0003b510:·6d32·3837·3022·2074·6162·696e·6465·783d··m2870"·tabindex=0003b510:·6d32·3837·3022·2074·6162·696e·6465·783d··m2870"·tabindex=
0003b520:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button0003b520:·2230·2220·726f·6c65·3d22·6275·7474·6f6e··"0"·role="button
0003b530:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=0003b530:·2220·6172·6961·2d65·7870·616e·6465·643d··"·aria-expanded=
0003b540:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A0003b540:·2266·616c·7365·2220·7469·746c·653d·2241··"false"·title="A
0003b550:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea0003b550:·6374·6976·6174·6520·746f·2072·6576·6561··ctivate·to·revea
0003b560:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem0003b560:·6c22·2068·7265·663d·2223·2122·3e52·656d··l"·href="#!">Rem
0003b570:·6564·6961·7469·6f6e·204f·5342·7569·6c64··ediation·OSBuild0003b570:·6564·6961·7469·6f6e·2053·6865·6c6c·2073··ediation·Shell·s
0003b580:·2042·6c75·6570·7269·6e74·2073·6e69·7070···Blueprint·snipp0003b580:·6372·6970·7420·e287·b23c·2f61·3e3c·6272··cript·...</a><br
 0003b590:·3e3c·6469·7620·636c·6173·733d·2270·616e··><div·class="pan
 0003b5a0:·656c·2d63·6f6c·6c61·7073·6520·636f·6c6c··el-collapse·coll
 0003b5b0:·6170·7365·2220·6964·3d22·6964·6d32·3837··apse"·id="idm287
 0003b5c0:·3022·3e3c·7461·626c·6520·636c·6173·733d··0"><table·class=
 0003b5d0:·2274·6162·6c65·2074·6162·6c65·2d73·7472··"table·table-str
 0003b5e0:·6970·6564·2074·6162·6c65·2d62·6f72·6465··iped·table-borde
 0003b5f0:·7265·6420·7461·626c·652d·636f·6e64·656e··red·table-conden
 0003b600:·7365·6422·3e3c·7472·3e3c·7468·3e43·6f6d··sed"><tr><th>Com
 0003b610:·706c·6578·6974·793a·3c2f·7468·3e3c·7464··plexity:</th><td
 0003b620:·3e6c·6f77·3c2f·7464·3e3c·2f74·723e·3c74··>low</td></tr><t
 0003b630:·723e·3c74·683e·4469·7372·7570·7469·6f6e··r><th>Disruption
 0003b640:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b650:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e52··d></tr><tr><th>R
 0003b660:·6562·6f6f·743a·3c2f·7468·3e3c·7464·3e66··eboot:</th><td>f
 0003b670:·616c·7365·3c2f·7464·3e3c·2f74·723e·3c74··alse</td></tr><t
 0003b680:·723e·3c74·683e·5374·7261·7465·6779·3a3c··r><th>Strategy:<
 0003b690:·2f74·683e·3c74·643e·656e·6162·6c65·3c2f··/th><td>enable</
 0003b6a0:·7464·3e3c·2f74·723e·3c2f·7461·626c·653e··td></tr></table>
 0003b6b0:·3c70·7265·3e3c·636f·6465·3e23·2052·656d··<pre><code>#·Rem
 0003b6c0:·6564·6961·7469·6f6e·2069·7320·6170·706c··ediation·is·appl
 0003b6d0:·6963·6162·6c65·206f·6e6c·7920·696e·2063··icable·only·in·c
 0003b6e0:·6572·7461·696e·2070·6c61·7466·6f72·6d73··ertain·platforms
 0003b6f0:·0a69·6620·7270·6d20·2d2d·7175·6965·7420··.if·rpm·--quiet·
 0003b700:·2d71·206b·6572·6e65·6c2d·6465·6661·756c··-q·kernel-defaul
 0003b710:·743b·2074·6865·6e0a·0a7a·7970·7065·7220··t;·then..zypper·
 0003b720:·696e·7374·616c·6c20·2d79·2022·6169·6465··install·-y·"aide
 0003b730:·220a·0a65·6c73·650a·2020·2020·2667·743b··"..else.····&gt;
 0003b740:·2661·6d70·3b32·2065·6368·6f20·2752·656d··&amp;2·echo·'Rem
 0003b750:·6564·6961·7469·6f6e·2069·7320·6e6f·7420··ediation·is·not·
 0003b760:·6170·706c·6963·6162·6c65·2c20·6e6f·7468··applicable,·noth
 0003b770:·696e·6720·7761·7320·646f·6e65·270a·6669··ing·was·done'.fi
 0003b780:·0a3c·2f63·6f64·653e·3c2f·7072·653e·3c2f··.</code></pre></
 0003b790:·6469·763e·3c61·2063·6c61·7373·3d22·6274··div><a·class="bt
 0003b7a0:·6e20·6274·6e2d·7375·6363·6573·7322·2064··n·btn-success"·d
 0003b7b0:·6174·612d·746f·6767·6c65·3d22·636f·6c6c··ata-toggle="coll
 0003b7c0:·6170·7365·2220·6461·7461·2d74·6172·6765··apse"·data-targe
 0003b7d0:·743d·2223·6964·6d32·3837·3122·2074·6162··t="#idm2871"·tab
 0003b7e0:·696e·6465·783d·2230·2220·726f·6c65·3d22··index="0"·role="
 0003b7f0:·6275·7474·6f6e·2220·6172·6961·2d65·7870··button"·aria-exp
 0003b800:·616e·6465·643d·2266·616c·7365·2220·7469··anded="false"·ti
 0003b810:·746c·653d·2241·6374·6976·6174·6520·746f··tle="Activate·to
 0003b820:·2072·6576·6561·6c22·2068·7265·663d·2223···reveal"·href="#
 0003b830:·2122·3e52·656d·6564·6961·7469·6f6e·2041··!">Remediation·A
 0003b840:·6e73·6962·6c65·2073·6e69·7070·6574·20e2··nsible·snippet·.
0003b590:·6574·20e2·87b2·3c2f·613e·3c62·723e·3c64··et·...</a><br><d0003b850:·87b2·3c2f·613e·3c62·723e·3c64·6976·2063··..</a><br><div·c
0003b5a0:·6976·2063·6c61·7373·3d22·7061·6e65·6c2d··iv·class="panel-0003b860:·6c61·7373·3d22·7061·6e65·6c2d·636f·6c6c··lass="panel-coll
0003b5b0:·636f·6c6c·6170·7365·2063·6f6c·6c61·7073··collapse·collaps0003b870:·6170·7365·2063·6f6c·6c61·7073·6522·2069··apse·collapse"·i
0003b5c0:·6522·2069·643d·2269·646d·3238·3730·223e··e"·id="idm2870"> 
0003b5d0:·3c70·7265·3e3c·636f·6465·3e0a·5b5b·7061··<pre><code>.[[pa 
0003b5e0:·636b·6167·6573·5d5d·0a6e·616d·6520·3d20··ckages]].name·=· 
0003b5f0:·2261·6964·6522·0a76·6572·7369·6f6e·203d··"aide".version·= 
0003b600:·2022·2a22·0a3c·2f63·6f64·653e·3c2f·7072···"*".</code></pr 
0003b610:·653e·3c2f·6469·763e·3c61·2063·6c61·7373··e></div><a·class 
0003b620:·3d22·6274·6e20·6274·6e2d·7375·6363·6573··="btn·btn-succes 
0003b630:·7322·2064·6174·612d·746f·6767·6c65·3d22··s"·data-toggle=" 
0003b640:·636f·6c6c·6170·7365·2220·6461·7461·2d74··collapse"·data-t 
0003b650:·6172·6765·743d·2223·6964·6d32·3837·3122··arget="#idm2871" 
0003b660:·2074·6162·696e·6465·783d·2230·2220·726f···tabindex="0"·ro 
0003b670:·6c65·3d22·6275·7474·6f6e·2220·6172·6961··le="button"·aria 
0003b680:·2d65·7870·616e·6465·643d·2266·616c·7365··-expanded="false 
0003b690:·2220·7469·746c·653d·2241·6374·6976·6174··"·title="Activat 
0003b6a0:·6520·746f·2072·6576·6561·6c22·2068·7265··e·to·reveal"·hre 
0003b6b0:·663d·2223·2122·3e52·656d·6564·6961·7469··f="#!">Remediati 
0003b6c0:·6f6e·2053·6865·6c6c·2073·6372·6970·7420··on·Shell·script·0003b880:·643d·2269·646d·3238·3731·223e·3c74·6162··d="idm2871"><tab
 0003b890:·6c65·2063·6c61·7373·3d22·7461·626c·6520··le·class="table·
 0003b8a0:·7461·626c·652d·7374·7269·7065·6420·7461··table-striped·ta
 0003b8b0:·626c·652d·626f·7264·6572·6564·2074·6162··ble-bordered·tab
 0003b8c0:·6c65·2d63·6f6e·6465·6e73·6564·223e·3c74··le-condensed"><t
 0003b8d0:·723e·3c74·683e·436f·6d70·6c65·7869·7479··r><th>Complexity
 0003b8e0:·3a3c·2f74·683e·3c74·643e·6c6f·773c·2f74··:</th><td>low</t
 0003b8f0:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e44··d></tr><tr><th>D
 0003b900:·6973·7275·7074·696f·6e3a·3c2f·7468·3e3c··isruption:</th><
 0003b910:·7464·3e6c·6f77·3c2f·7464·3e3c·2f74·723e··td>low</td></tr>
 0003b920:·3c74·723e·3c74·683e·5265·626f·6f74·3a3c··<tr><th>Reboot:<
 0003b930:·2f74·683e·3c74·643e·6661·6c73·653c·2f74··/th><td>false</t
 0003b940:·643e·3c2f·7472·3e3c·7472·3e3c·7468·3e53··d></tr><tr><th>S
 0003b950:·7472·6174·6567·793a·3c2f·7468·3e3c·7464··trategy:</th><td
 0003b960:·3e65·6e61·626c·653c·2f74·643e·3c2f·7472··>enable</td></tr
 0003b970:·3e3c·2f74·6162·6c65·3e3c·7072·653e·3c63··></table><pre><c
 0003b980:·6f64·653e·2d20·6e61·6d65·3a20·4761·7468··ode>-·name:·Gath
 0003b990:·6572·2074·6865·2070·6163·6b61·6765·2066··er·the·package·f
 0003b9a0:·6163·7473·0a20·2070·6163·6b61·6765·5f66··acts.··package_f
 0003b9b0:·6163·7473·3a0a·2020·2020·6d61·6e61·6765··acts:.····manage
 0003b9c0:·723a·2061·7574·6f0a·2020·7461·6773·3a0a··r:·auto.··tags:.
 0003b9d0:·2020·2d20·4343·452d·3933·3735·382d·310a····-·CCE-93758-1.
 0003b9e0:·2020·2d20·434a·4953·2d35·2e31·302e·312e····-·CJIS-5.10.1.
 0003b9f0:·330a·2020·2d20·4449·5341·2d53·5449·472d··3.··-·DISA-STIG-
 0003ba00:·534c·454d·2d30·352d·3635·3130·3130·0a20··SLEM-05-651010.·
 0003ba10:·202d·204e·4953·542d·3830·302d·3533·2d43···-·NIST-800-53-C
 0003ba20:·4d2d·3628·6129·0a20·202d·2050·4349·2d44··M-6(a).··-·PCI-D
 0003ba30:·5353·2d52·6571·2d31·312e·350a·2020·2d20··SS-Req-11.5.··-·
 0003ba40:·5043·492d·4453·5376·342d·3131·2e35·2e32··PCI-DSSv4-11.5.2
 0003ba50:·0a20·202d·2065·6e61·626c·655f·7374·7261··.··-·enable_stra
 0003ba60:·7465·6779·0a20·202d·206c·6f77·5f63·6f6d··tegy.··-·low_com
 0003ba70:·706c·6578·6974·790a·2020·2d20·6c6f·775f··plexity.··-·low_
 0003ba80:·6469·7372·7570·7469·6f6e·0a20·202d·206d··disruption.··-·m
 0003ba90:·6564·6975·6d5f·7365·7665·7269·7479·0a20··edium_severity.·
 0003baa0:·202d·206e·6f5f·7265·626f·6f74·5f6e·6565···-·no_reboot_nee
 0003bab0:·6465·640a·2020·2d20·7061·636b·6167·655f··ded.··-·package_
 0003bac0:·6169·6465·5f69·6e73·7461·6c6c·6564·0a0a··aide_installed..
 0003bad0:·2d20·6e61·6d65·3a20·456e·7375·7265·2061··-·name:·Ensure·a
 0003bae0:·6964·6520·6973·2069·6e73·7461·6c6c·6564··ide·is·installed
 0003baf0:·0a20·2070·6163·6b61·6765·3a0a·2020·2020··.··package:.····
 0003bb00:·6e61·6d65·3a20·6169·6465·0a20·2020·2073··name:·aide.····s
 0003bb10:·7461·7465·3a20·7072·6573·656e·740a·2020··tate:·present.··
 0003bb20:·7768·656e·3a20·2722·6b65·726e·656c·2d64··when:·'"kernel-d
 0003bb30:·6566·6175·6c74·2220·696e·2061·6e73·6962··efault"·in·ansib
 0003bb40:·6c65·5f66·6163·7473·2e70·6163·6b61·6765··le_facts.package
 0003bb50:·7327·0a20·2074·6167·733a·0a20·202d·2043··s'.··tags:.··-·C
 0003bb60:·4345·2d39·3337·3538·2d31·0a20·202d·2043··CE-93758-1.··-·C
 0003bb70:·4a49·532d·352e·3130·2e31·2e33·0a20·202d··JIS-5.10.1.3.··-
 0003bb80:·2044·4953·412d·5354·4947·2d53·4c45·4d2d···DISA-STIG-SLEM-
 0003bb90:·3035·2d36·3531·3031·300a·2020·2d20·4e49··05-651010.··-·NI
 0003bba0:·5354·2d38·3030·2d35·332d·434d·2d36·2861··ST-800-53-CM-6(a
 0003bbb0:·290a·2020·2d20·5043·492d·4453·532d·5265··).··-·PCI-DSS-Re
 0003bbc0:·712d·3131·2e35·0a20·202d·2050·4349·2d44··q-11.5.··-·PCI-D
 0003bbd0:·5353·7634·2d31·312e·352e·320a·2020·2d20··SSv4-11.5.2.··-·
 0003bbe0:·656e·6162·6c65·5f73·7472·6174·6567·790a··enable_strategy.
Max diff block lines reached; 881560/900356 bytes (97.91%) of diff not shown.
46.6 KB
html2text {}
    
Offset 129, 19 lines modifiedOffset 129, 14 lines modified
129 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5129 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
130 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199130 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
131 ·············_\x8c_\x8i_\x8s············1.4.1131 ·············_\x8c_\x8i_\x8s············1.4.1
132 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79132 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
133 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2133 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
134 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010134 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010
135 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule135 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule
136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
137 [[packages]] 
138 name·=·"aide" 
139 version·=·"*" 
140 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8136 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
141 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low137 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
142 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low138 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
143 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false139 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
144 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable140 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
145 #·Remediation·is·applicable·only·in·certain·platforms141 #·Remediation·is·applicable·only·in·certain·platforms
146 if·rpm·--quiet·-q·kernel-default;·then142 if·rpm·--quiet·-q·kernel-default;·then
Offset 187, 14 lines modifiedOffset 182, 19 lines modified
187 ··-·PCI-DSSv4-11.5.2182 ··-·PCI-DSSv4-11.5.2
188 ··-·enable_strategy183 ··-·enable_strategy
189 ··-·low_complexity184 ··-·low_complexity
190 ··-·low_disruption185 ··-·low_disruption
191 ··-·medium_severity186 ··-·medium_severity
192 ··-·no_reboot_needed187 ··-·no_reboot_needed
193 ··-·package_aide_installed188 ··-·package_aide_installed
 189 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 190 [[packages]]
 191 name·=·"aide"
 192 version·=·"*"
194 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8193 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
195 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low194 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
196 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low195 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
197 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false196 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
198 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable197 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
199 include·install_aide198 include·install_aide
  
Offset 797, 19 lines modifiedOffset 797, 14 lines modified
797 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386797 ·············_\x8i_\x8s_\x8m·····1382,·1384,·1386
798 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)798 ·············_\x8n_\x8i_\x8s_\x8t····CM-6(a)
799 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1799 References:··_\x8o_\x8s_\x8p_\x8p····FMT_MOF_EXT.1
800 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125800 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000324-GPOS-00125
801 ·············_\x8c_\x8i_\x8s·····1.3.1801 ·············_\x8c_\x8i_\x8s·····1.3.1
802 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33802 ·············_\x8a_\x8n_\x8s_\x8s_\x8i···R33
803 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2803 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84·2.2.6,·2.2
804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
805 [[packages]] 
806 name·=·"sudo" 
807 version·=·"*" 
808 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8804 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
809 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low805 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
810 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low806 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
811 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false807 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
812 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable808 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
813 #·Remediation·is·applicable·only·in·certain·platforms809 #·Remediation·is·applicable·only·in·certain·platforms
814 if·rpm·--quiet·-q·kernel-default;·then810 if·rpm·--quiet·-q·kernel-default;·then
Offset 851, 14 lines modifiedOffset 846, 19 lines modified
851 ··-·PCI-DSSv4-2.2.6846 ··-·PCI-DSSv4-2.2.6
852 ··-·enable_strategy847 ··-·enable_strategy
853 ··-·low_complexity848 ··-·low_complexity
854 ··-·low_disruption849 ··-·low_disruption
855 ··-·medium_severity850 ··-·medium_severity
856 ··-·no_reboot_needed851 ··-·no_reboot_needed
857 ··-·package_sudo_installed852 ··-·package_sudo_installed
 853 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 854 [[packages]]
 855 name·=·"sudo"
 856 version·=·"*"
858 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8857 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
859 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low858 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
860 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low859 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
861 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false860 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
862 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable861 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
863 include·install_sudo862 include·install_sudo
  
Offset 8941, 19 lines modifiedOffset 8941, 14 lines modified
8941 ·············_\x8n_\x8i_\x8s_\x8t···AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)8941 ·············_\x8n_\x8i_\x8s_\x8t···AC-3(4),·AC-6(8),·AC-6(10),·CM-7(5)(b),·CM-7(2),·SC-7(21),·CM-6(a)
8942 ····················SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-8942 ····················SRG-OS-000312-GPOS-00122,·SRG-OS-000312-GPOS-00123,·SRG-OS-000312-GPOS-00124,·SRG-OS-
8943 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-8943 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·000324-GPOS-00125,·SRG-OS-000326-GPOS-00126,·SRG-OS-000370-GPOS-00155,·SRG-OS-000480-
8944 ····················GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-8944 ····················GPOS-00230,·SRG-OS-000480-GPOS-00227,·SRG-OS-000480-GPOS-00231,·SRG-OS-000480-GPOS-
8945 ····················002328945 ····················00232
8946 ·············_\x8c_\x8i_\x8s····1.7.1.18946 ·············_\x8c_\x8i_\x8s····1.7.1.1
8947 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R458947 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··R45
8948 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
8949 [[packages]] 
8950 name·=·"pam_apparmor" 
8951 version·=·"*" 
8952 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x88948 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
8953 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8949 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8954 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8950 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8955 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8951 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8956 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8952 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8957 #·Remediation·is·applicable·only·in·certain·platforms8953 #·Remediation·is·applicable·only·in·certain·platforms
8958 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then8954 if·[·!·-f·/.dockerenv·]·&&·[·!·-f·/run/.containerenv·];·then
Offset 8984, 14 lines modifiedOffset 8979, 19 lines modified
8984 ··-·NIST-800-53-SC-7(21)8979 ··-·NIST-800-53-SC-7(21)
8985 ··-·enable_strategy8980 ··-·enable_strategy
8986 ··-·low_complexity8981 ··-·low_complexity
8987 ··-·low_disruption8982 ··-·low_disruption
8988 ··-·medium_severity8983 ··-·medium_severity
8989 ··-·no_reboot_needed8984 ··-·no_reboot_needed
8990 ··-·package_pam_apparmor_installed8985 ··-·package_pam_apparmor_installed
 8986 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 8987 [[packages]]
 8988 name·=·"pam_apparmor"
 8989 version·=·"*"
8991 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88990 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8992 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8991 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8993 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8992 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8994 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8993 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8995 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8994 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8996 include·install_pam_apparmor8995 include·install_pam_apparmor
  
Offset 9490, 19 lines modifiedOffset 9490, 14 lines modified
9490 ·············stored·on·the·local·system.9490 ·············stored·on·the·local·system.
9491 Severity: ···medium9491 Severity: ···medium
9492 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed9492 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed
9493 Identifiers:·CCE-94085-89493 Identifiers:·CCE-94085-8
9494 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-002249494 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-00224
9495 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-6520109495 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-652010
9496 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule9496 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule
Max diff block lines reached; 42465/47693 bytes (89.04%) of diff not shown.
241 KB
./usr/share/doc/ssg-nondebian/ssg-slmicro5-guide-pcs-hardening.html
    
Offset 15110, 146 lines modifiedOffset 15110, 146 lines modified
0003b050:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b050:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b060:·3d22·2369·646d·3238·3730·2220·7461·6269··="#idm2870"·tabi0003b060:·3d22·2369·646d·3238·3730·2220·7461·6269··="#idm2870"·tabi
0003b070:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b070:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b080:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b080:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b090:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b090:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b0a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b0a0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b0b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b0b0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b0c0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003b0c0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003b0d0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003b0e0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b0f0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b100:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b110:·646d·3238·3730·223e·3c74·6162·6c65·2063··dm2870"><table·c
 0003b120:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003b130:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b140:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b150:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b160:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b170:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b180:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b190:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b1a0:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b1b0:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b1c0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b1d0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b1e0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003b0d0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003b0e0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b0f0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b100:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b110:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
0003b120:·3837·3022·3e3c·7072·653e·3c63·6f64·653e··870"><pre><code> 
0003b130:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003b140:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003b150:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003b160:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b170:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b180:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b190:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b1a0:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b1b0:·3238·3731·2220·7461·6269·6e64·6578·3d22··2871"·tabindex=" 
0003b1c0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b1d0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b1e0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b1f0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b200:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b210:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b220:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003b230:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b240:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b250:·7073·6522·2069·643d·2269·646d·3238·3731··pse"·id="idm2871 
0003b260:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b270:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b280:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b290:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b2a0:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b2b0:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003b2c0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b2d0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b2e0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b2f0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b300:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003b310:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b1f0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003b200:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003b320:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003b330:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003b340:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b350:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003b360:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b370:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b380:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b390:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003b3a0:·7120·6b65·726e·656c·2d64·6566·6175·6c74··q·kernel-default 
0003b3b0:·3b20·7468·656e·0a0a·7a79·7070·6572·2069··;·then..zypper·i 
0003b3c0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003b3d0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b3e0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b3f0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b400:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b410:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b420:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b430:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b440:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b450:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b460:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b470:·3d22·2369·646d·3238·3732·2220·7461·6269··="#idm2872"·tabi 
0003b480:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b490:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b4a0:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b4b0:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b4c0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b4d0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b210:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
0003b4e0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b4f0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b500:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b510:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b520:·3d22·6964·6d32·3837·3222·3e3c·7461·626c··="idm2872"><tabl 
0003b530:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b540:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b550:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b560:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b570:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b580:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b590:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b5a0:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b5b0:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b5c0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b5d0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b5e0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b5f0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b600:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b610:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b620:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
0003b630:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
0003b640:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
0003b650:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
0003b660:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
0003b670:·202d·2043·4345·2d39·3337·3538·2d31·0a20···-·CCE-93758-1.· 
0003b680:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003b690:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S 
0003b6a0:·4c45·4d2d·3035·2d36·3531·3031·300a·2020··LEM-05-651010.·· 
0003b6b0:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
0003b6c0:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
0003b6d0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
0003b6e0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
0003b6f0:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
0003b700:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
Max diff block lines reached; 211674/230470 bytes (91.84%) of diff not shown.
15.4 KB
html2text {}
    
Offset 115, 19 lines modifiedOffset 115, 14 lines modified
115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5115 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
116 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199116 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
117 ·············_\x8c_\x8i_\x8s············1.4.1117 ·············_\x8c_\x8i_\x8s············1.4.1
118 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79118 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2119 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
120 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010120 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010
121 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule121 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule
122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
123 [[packages]] 
124 name·=·"aide" 
125 version·=·"*" 
126 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8122 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
127 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low123 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
128 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low124 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
129 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false125 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
130 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable126 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
131 #·Remediation·is·applicable·only·in·certain·platforms127 #·Remediation·is·applicable·only·in·certain·platforms
132 if·rpm·--quiet·-q·kernel-default;·then128 if·rpm·--quiet·-q·kernel-default;·then
Offset 173, 14 lines modifiedOffset 168, 19 lines modified
173 ··-·PCI-DSSv4-11.5.2168 ··-·PCI-DSSv4-11.5.2
174 ··-·enable_strategy169 ··-·enable_strategy
175 ··-·low_complexity170 ··-·low_complexity
176 ··-·low_disruption171 ··-·low_disruption
177 ··-·medium_severity172 ··-·medium_severity
178 ··-·no_reboot_needed173 ··-·no_reboot_needed
179 ··-·package_aide_installed174 ··-·package_aide_installed
 175 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 176 [[packages]]
 177 name·=·"aide"
 178 version·=·"*"
180 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8179 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
181 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low180 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
182 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low181 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
183 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false182 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
184 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable183 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
185 include·install_aide184 include·install_aide
  
Offset 6926, 19 lines modifiedOffset 6926, 14 lines modified
6926 Severity: ···medium6926 Severity: ···medium
6927 Rule·ID:·····xccdf_org.ssgproject.content_rule_vlock_installed6927 Rule·ID:·····xccdf_org.ssgproject.content_rule_vlock_installed
6928 Identifiers:·CCE-93755-76928 Identifiers:·CCE-93755-7
6929 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-0000606929 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-000060
6930 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-000116930 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-00011
6931 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-2150106931 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-215010
6932 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261276r996316_rule6932 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261276r996316_rule
6933 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
6934 [[packages]] 
6935 name·=·"kbd" 
6936 version·=·"*" 
6937 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x86933 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
6938 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6934 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6939 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6935 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6940 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6936 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6941 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6937 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6942 #·Remediation·is·applicable·only·in·certain·platforms6938 #·Remediation·is·applicable·only·in·certain·platforms
6943 if·rpm·--quiet·-q·kernel-default;·then6939 if·rpm·--quiet·-q·kernel-default;·then
Offset 6976, 14 lines modifiedOffset 6971, 19 lines modified
6976 ··-·DISA-STIG-SLEM-05-2150106971 ··-·DISA-STIG-SLEM-05-215010
6977 ··-·enable_strategy6972 ··-·enable_strategy
6978 ··-·low_complexity6973 ··-·low_complexity
6979 ··-·low_disruption6974 ··-·low_disruption
6980 ··-·medium_severity6975 ··-·medium_severity
6981 ··-·no_reboot_needed6976 ··-·no_reboot_needed
6982 ··-·vlock_installed6977 ··-·vlock_installed
 6978 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 6979 [[packages]]
 6980 name·=·"kbd"
 6981 version·=·"*"
6983 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x86982 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
6984 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low6983 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
6985 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low6984 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
6986 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false6985 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
6987 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable6986 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
6988 include·install_kbd6987 include·install_kbd
  
Offset 17013, 19 lines modifiedOffset 17013, 14 lines modified
17013 Severity: ···medium17013 Severity: ···medium
17014 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_policycoreutils-python-utils_installed17014 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_policycoreutils-python-utils_installed
17015 Identifiers:·CCE-94091-617015 Identifiers:·CCE-94091-6
17016 ·············_\x8d_\x8i_\x8s_\x8a····CCI-00036617016 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000366
17017 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-0022717017 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00227
17018 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-65422017018 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-654220
17019 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261467r996808_rule17019 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261467r996808_rule
17020 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
17021 [[packages]] 
17022 name·=·"policycoreutils-python-utils" 
17023 version·=·"*" 
17024 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x817020 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
17025 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low17021 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
17026 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low17022 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
17027 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false17023 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
17028 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable17024 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
17029 #·Remediation·is·applicable·only·in·certain·platforms17025 #·Remediation·is·applicable·only·in·certain·platforms
17030 if·rpm·--quiet·-q·kernel-default;·then17026 if·rpm·--quiet·-q·kernel-default;·then
Offset 17063, 14 lines modifiedOffset 17058, 19 lines modified
17063 ··-·DISA-STIG-SLEM-05-65422017058 ··-·DISA-STIG-SLEM-05-654220
17064 ··-·enable_strategy17059 ··-·enable_strategy
17065 ··-·low_complexity17060 ··-·low_complexity
17066 ··-·low_disruption17061 ··-·low_disruption
17067 ··-·medium_severity17062 ··-·medium_severity
17068 ··-·no_reboot_needed17063 ··-·no_reboot_needed
17069 ··-·package_policycoreutils-python-utils_installed17064 ··-·package_policycoreutils-python-utils_installed
 17065 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 17066 [[packages]]
 17067 name·=·"policycoreutils-python-utils"
 17068 version·=·"*"
17070 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x817069 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
17071 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low17070 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
17072 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low17071 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
17073 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false17072 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
17074 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable17073 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
17075 include·install_policycoreutils-python-utils17074 include·install_policycoreutils-python-utils
  
Offset 17095, 19 lines modifiedOffset 17095, 14 lines modified
17095 Severity: ···low17095 Severity: ···low
17096 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_policycoreutils_installed17096 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_policycoreutils_installed
17097 Identifiers:·CCE-94097-317097 Identifiers:·CCE-94097-3
17098 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-00108417098 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000366,·CCI-001084
17099 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00227,·SRG-OS-000134-GPOS-0006817099 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000480-GPOS-00227,·SRG-OS-000134-GPOS-00068
17100 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-43101017100 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-431010
17101 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261368r996548_rule17101 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261368r996548_rule
Max diff block lines reached; 10547/15752 bytes (66.96%) of diff not shown.
359 KB
./usr/share/doc/ssg-nondebian/ssg-slmicro5-guide-stig.html
    
Offset 15124, 146 lines modifiedOffset 15124, 146 lines modified
0003b130:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target0003b130:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target
0003b140:·3d22·2369·646d·3238·3730·2220·7461·6269··="#idm2870"·tabi0003b140:·3d22·2369·646d·3238·3730·2220·7461·6269··="#idm2870"·tabi
0003b150:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b0003b150:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b
0003b160:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa0003b160:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa
0003b170:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit0003b170:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit
0003b180:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·0003b180:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to·
0003b190:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!0003b190:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#!
0003b1a0:·223e·5265·6d65·6469·6174·696f·6e20·4f53··">Remediation·OS0003b1a0:·223e·5265·6d65·6469·6174·696f·6e20·5368··">Remediation·Sh
 0003b1b0:·656c·6c20·7363·7269·7074·20e2·87b2·3c2f··ell·script·...</
 0003b1c0:·613e·3c62·723e·3c64·6976·2063·6c61·7373··a><br><div·class
 0003b1d0:·3d22·7061·6e65·6c2d·636f·6c6c·6170·7365··="panel-collapse
 0003b1e0:·2063·6f6c·6c61·7073·6522·2069·643d·2269···collapse"·id="i
 0003b1f0:·646d·3238·3730·223e·3c74·6162·6c65·2063··dm2870"><table·c
 0003b200:·6c61·7373·3d22·7461·626c·6520·7461·626c··lass="table·tabl
 0003b210:·652d·7374·7269·7065·6420·7461·626c·652d··e-striped·table-
 0003b220:·626f·7264·6572·6564·2074·6162·6c65·2d63··bordered·table-c
 0003b230:·6f6e·6465·6e73·6564·223e·3c74·723e·3c74··ondensed"><tr><t
 0003b240:·683e·436f·6d70·6c65·7869·7479·3a3c·2f74··h>Complexity:</t
 0003b250:·683e·3c74·643e·6c6f·773c·2f74·643e·3c2f··h><td>low</td></
 0003b260:·7472·3e3c·7472·3e3c·7468·3e44·6973·7275··tr><tr><th>Disru
 0003b270:·7074·696f·6e3a·3c2f·7468·3e3c·7464·3e6c··ption:</th><td>l
 0003b280:·6f77·3c2f·7464·3e3c·2f74·723e·3c74·723e··ow</td></tr><tr>
 0003b290:·3c74·683e·5265·626f·6f74·3a3c·2f74·683e··<th>Reboot:</th>
 0003b2a0:·3c74·643e·6661·6c73·653c·2f74·643e·3c2f··<td>false</td></
 0003b2b0:·7472·3e3c·7472·3e3c·7468·3e53·7472·6174··tr><tr><th>Strat
 0003b2c0:·6567·793a·3c2f·7468·3e3c·7464·3e65·6e61··egy:</th><td>ena
0003b1b0:·4275·696c·6420·426c·7565·7072·696e·7420··Build·Blueprint· 
0003b1c0:·736e·6970·7065·7420·e287·b23c·2f61·3e3c··snippet·...</a>< 
0003b1d0:·6272·3e3c·6469·7620·636c·6173·733d·2270··br><div·class="p 
0003b1e0:·616e·656c·2d63·6f6c·6c61·7073·6520·636f··anel-collapse·co 
0003b1f0:·6c6c·6170·7365·2220·6964·3d22·6964·6d32··llapse"·id="idm2 
0003b200:·3837·3022·3e3c·7072·653e·3c63·6f64·653e··870"><pre><code> 
0003b210:·0a5b·5b70·6163·6b61·6765·735d·5d0a·6e61··.[[packages]].na 
0003b220:·6d65·203d·2022·6169·6465·220a·7665·7273··me·=·"aide".vers 
0003b230:·696f·6e20·3d20·222a·220a·3c2f·636f·6465··ion·=·"*".</code 
0003b240:·3e3c·2f70·7265·3e3c·2f64·6976·3e3c·6120··></pre></div><a· 
0003b250:·636c·6173·733d·2262·746e·2062·746e·2d73··class="btn·btn-s 
0003b260:·7563·6365·7373·2220·6461·7461·2d74·6f67··uccess"·data-tog 
0003b270:·676c·653d·2263·6f6c·6c61·7073·6522·2064··gle="collapse"·d 
0003b280:·6174·612d·7461·7267·6574·3d22·2369·646d··ata-target="#idm 
0003b290:·3238·3731·2220·7461·6269·6e64·6578·3d22··2871"·tabindex=" 
0003b2a0:·3022·2072·6f6c·653d·2262·7574·746f·6e22··0"·role="button" 
0003b2b0:·2061·7269·612d·6578·7061·6e64·6564·3d22···aria-expanded=" 
0003b2c0:·6661·6c73·6522·2074·6974·6c65·3d22·4163··false"·title="Ac 
0003b2d0:·7469·7661·7465·2074·6f20·7265·7665·616c··tivate·to·reveal 
0003b2e0:·2220·6872·6566·3d22·2321·223e·5265·6d65··"·href="#!">Reme 
0003b2f0:·6469·6174·696f·6e20·5368·656c·6c20·7363··diation·Shell·sc 
0003b300:·7269·7074·20e2·87b2·3c2f·613e·3c62·723e··ript·...</a><br> 
0003b310:·3c64·6976·2063·6c61·7373·3d22·7061·6e65··<div·class="pane 
0003b320:·6c2d·636f·6c6c·6170·7365·2063·6f6c·6c61··l-collapse·colla 
0003b330:·7073·6522·2069·643d·2269·646d·3238·3731··pse"·id="idm2871 
0003b340:·223e·3c74·6162·6c65·2063·6c61·7373·3d22··"><table·class=" 
0003b350:·7461·626c·6520·7461·626c·652d·7374·7269··table·table-stri 
0003b360:·7065·6420·7461·626c·652d·626f·7264·6572··ped·table-border 
0003b370:·6564·2074·6162·6c65·2d63·6f6e·6465·6e73··ed·table-condens 
0003b380:·6564·223e·3c74·723e·3c74·683e·436f·6d70··ed"><tr><th>Comp 
0003b390:·6c65·7869·7479·3a3c·2f74·683e·3c74·643e··lexity:</th><td> 
0003b3a0:·6c6f·773c·2f74·643e·3c2f·7472·3e3c·7472··low</td></tr><tr 
0003b3b0:·3e3c·7468·3e44·6973·7275·7074·696f·6e3a··><th>Disruption: 
0003b3c0:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b3d0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5265··></tr><tr><th>Re 
0003b3e0:·626f·6f74·3a3c·2f74·683e·3c74·643e·6661··boot:</th><td>fa 
0003b3f0:·6c73·653c·2f74·643e·3c2f·7472·3e3c·7472··lse</td></tr><tr0003b2d0:·626c·653c·2f74·643e·3c2f·7472·3e3c·2f74··ble</td></tr></t
 0003b2e0:·6162·6c65·3e3c·7072·653e·3c63·6f64·653e··able><pre><code>
0003b400:·3e3c·7468·3e53·7472·6174·6567·793a·3c2f··><th>Strategy:</ 
0003b410:·7468·3e3c·7464·3e65·6e61·626c·653c·2f74··th><td>enable</t 
0003b420:·643e·3c2f·7472·3e3c·2f74·6162·6c65·3e3c··d></tr></table>< 
0003b430:·7072·653e·3c63·6f64·653e·2320·5265·6d65··pre><code>#·Reme 
0003b440:·6469·6174·696f·6e20·6973·2061·7070·6c69··diation·is·appli 
0003b450:·6361·626c·6520·6f6e·6c79·2069·6e20·6365··cable·only·in·ce 
0003b460:·7274·6169·6e20·706c·6174·666f·726d·730a··rtain·platforms. 
0003b470:·6966·2072·706d·202d·2d71·7569·6574·202d··if·rpm·--quiet·- 
0003b480:·7120·6b65·726e·656c·2d64·6566·6175·6c74··q·kernel-default 
0003b490:·3b20·7468·656e·0a0a·7a79·7070·6572·2069··;·then..zypper·i 
0003b4a0:·6e73·7461·6c6c·202d·7920·2261·6964·6522··nstall·-y·"aide" 
0003b4b0:·0a0a·656c·7365·0a20·2020·2026·6774·3b26··..else.····&gt;& 
0003b4c0:·616d·703b·3220·6563·686f·2027·5265·6d65··amp;2·echo·'Reme 
0003b4d0:·6469·6174·696f·6e20·6973·206e·6f74·2061··diation·is·not·a 
0003b4e0:·7070·6c69·6361·626c·652c·206e·6f74·6869··pplicable,·nothi 
0003b4f0:·6e67·2077·6173·2064·6f6e·6527·0a66·690a··ng·was·done'.fi. 
0003b500:·3c2f·636f·6465·3e3c·2f70·7265·3e3c·2f64··</code></pre></d 
0003b510:·6976·3e3c·6120·636c·6173·733d·2262·746e··iv><a·class="btn 
0003b520:·2062·746e·2d73·7563·6365·7373·2220·6461···btn-success"·da 
0003b530:·7461·2d74·6f67·676c·653d·2263·6f6c·6c61··ta-toggle="colla 
0003b540:·7073·6522·2064·6174·612d·7461·7267·6574··pse"·data-target 
0003b550:·3d22·2369·646d·3238·3732·2220·7461·6269··="#idm2872"·tabi 
0003b560:·6e64·6578·3d22·3022·2072·6f6c·653d·2262··ndex="0"·role="b 
0003b570:·7574·746f·6e22·2061·7269·612d·6578·7061··utton"·aria-expa 
0003b580:·6e64·6564·3d22·6661·6c73·6522·2074·6974··nded="false"·tit 
0003b590:·6c65·3d22·4163·7469·7661·7465·2074·6f20··le="Activate·to· 
0003b5a0:·7265·7665·616c·2220·6872·6566·3d22·2321··reveal"·href="#! 
0003b5b0:·223e·5265·6d65·6469·6174·696f·6e20·416e··">Remediation·An0003b2f0:·2320·5265·6d65·6469·6174·696f·6e20·6973··#·Remediation·is
0003b5c0:·7369·626c·6520·736e·6970·7065·7420·e287··sible·snippet·.. 
0003b5d0:·b23c·2f61·3e3c·6272·3e3c·6469·7620·636c··.</a><br><div·cl 
0003b5e0:·6173·733d·2270·616e·656c·2d63·6f6c·6c61··ass="panel-colla 
0003b5f0:·7073·6520·636f·6c6c·6170·7365·2220·6964··pse·collapse"·id 
0003b600:·3d22·6964·6d32·3837·3222·3e3c·7461·626c··="idm2872"><tabl 
0003b610:·6520·636c·6173·733d·2274·6162·6c65·2074··e·class="table·t 
0003b620:·6162·6c65·2d73·7472·6970·6564·2074·6162··able-striped·tab 
0003b630:·6c65·2d62·6f72·6465·7265·6420·7461·626c··le-bordered·tabl 
0003b640:·652d·636f·6e64·656e·7365·6422·3e3c·7472··e-condensed"><tr 
0003b650:·3e3c·7468·3e43·6f6d·706c·6578·6974·793a··><th>Complexity: 
0003b660:·3c2f·7468·3e3c·7464·3e6c·6f77·3c2f·7464··</th><td>low</td 
0003b670:·3e3c·2f74·723e·3c74·723e·3c74·683e·4469··></tr><tr><th>Di 
0003b680:·7372·7570·7469·6f6e·3a3c·2f74·683e·3c74··sruption:</th><t 
0003b690:·643e·6c6f·773c·2f74·643e·3c2f·7472·3e3c··d>low</td></tr>< 
0003b6a0:·7472·3e3c·7468·3e52·6562·6f6f·743a·3c2f··tr><th>Reboot:</ 
0003b6b0:·7468·3e3c·7464·3e66·616c·7365·3c2f·7464··th><td>false</td 
0003b6c0:·3e3c·2f74·723e·3c74·723e·3c74·683e·5374··></tr><tr><th>St 
0003b6d0:·7261·7465·6779·3a3c·2f74·683e·3c74·643e··rategy:</th><td> 
0003b6e0:·656e·6162·6c65·3c2f·7464·3e3c·2f74·723e··enable</td></tr> 
0003b6f0:·3c2f·7461·626c·653e·3c70·7265·3e3c·636f··</table><pre><co 
0003b700:·6465·3e2d·206e·616d·653a·2047·6174·6865··de>-·name:·Gathe 
0003b710:·7220·7468·6520·7061·636b·6167·6520·6661··r·the·package·fa 
0003b720:·6374·730a·2020·7061·636b·6167·655f·6661··cts.··package_fa 
0003b730:·6374·733a·0a20·2020·206d·616e·6167·6572··cts:.····manager 
0003b740:·3a20·6175·746f·0a20·2074·6167·733a·0a20··:·auto.··tags:.· 
0003b750:·202d·2043·4345·2d39·3337·3538·2d31·0a20···-·CCE-93758-1.· 
0003b760:·202d·2043·4a49·532d·352e·3130·2e31·2e33···-·CJIS-5.10.1.3 
0003b770:·0a20·202d·2044·4953·412d·5354·4947·2d53··.··-·DISA-STIG-S 
0003b780:·4c45·4d2d·3035·2d36·3531·3031·300a·2020··LEM-05-651010.·· 
0003b790:·2d20·4e49·5354·2d38·3030·2d35·332d·434d··-·NIST-800-53-CM 
0003b7a0:·2d36·2861·290a·2020·2d20·5043·492d·4453··-6(a).··-·PCI-DS 
0003b7b0:·532d·5265·712d·3131·2e35·0a20·202d·2050··S-Req-11.5.··-·P 
0003b7c0:·4349·2d44·5353·7634·2d31·312e·352e·320a··CI-DSSv4-11.5.2. 
0003b7d0:·2020·2d20·656e·6162·6c65·5f73·7472·6174····-·enable_strat 
0003b7e0:·6567·790a·2020·2d20·6c6f·775f·636f·6d70··egy.··-·low_comp 
Max diff block lines reached; 326882/345678 bytes (94.56%) of diff not shown.
21.7 KB
html2text {}
    
Offset 117, 19 lines modifiedOffset 117, 14 lines modified
117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5117 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s·········Req-11.5
118 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199118 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g·········SRG-OS-000445-GPOS-00199
119 ·············_\x8c_\x8i_\x8s············1.4.1119 ·············_\x8c_\x8i_\x8s············1.4.1
120 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79120 ·············_\x8a_\x8n_\x8s_\x8s_\x8i··········R76,·R79
121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2121 ·············_\x8p_\x8c_\x8i_\x8d_\x8s_\x8s_\x84········11.5.2
122 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010122 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d·········SLEM-05-651010
123 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule123 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f········SV-261403r996627_rule
124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
125 [[packages]] 
126 name·=·"aide" 
127 version·=·"*" 
128 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8124 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
129 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low125 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
130 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low126 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
131 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false127 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
132 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable128 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
133 #·Remediation·is·applicable·only·in·certain·platforms129 #·Remediation·is·applicable·only·in·certain·platforms
134 if·rpm·--quiet·-q·kernel-default;·then130 if·rpm·--quiet·-q·kernel-default;·then
Offset 175, 14 lines modifiedOffset 170, 19 lines modified
175 ··-·PCI-DSSv4-11.5.2170 ··-·PCI-DSSv4-11.5.2
176 ··-·enable_strategy171 ··-·enable_strategy
177 ··-·low_complexity172 ··-·low_complexity
178 ··-·low_disruption173 ··-·low_disruption
179 ··-·medium_severity174 ··-·medium_severity
180 ··-·no_reboot_needed175 ··-·no_reboot_needed
181 ··-·package_aide_installed176 ··-·package_aide_installed
 177 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 178 [[packages]]
 179 name·=·"aide"
 180 version·=·"*"
182 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8181 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
183 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low182 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
184 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low183 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
185 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false184 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
186 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable185 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
187 include·install_aide186 include·install_aide
  
Offset 8380, 19 lines modifiedOffset 8380, 14 lines modified
8380 Severity: ···medium8380 Severity: ···medium
8381 Rule·ID:·····xccdf_org.ssgproject.content_rule_vlock_installed8381 Rule·ID:·····xccdf_org.ssgproject.content_rule_vlock_installed
8382 Identifiers:·CCE-93755-78382 Identifiers:·CCE-93755-7
8383 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-0000608383 ·············_\x8d_\x8i_\x8s_\x8a····CCI-000056,·CCI-000057,·CCI-000058,·CCI-000060
8384 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-000118384 References:··_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000028-GPOS-00009,·SRG-OS-000030-GPOS-00011
8385 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-2150108385 ·············_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-215010
8386 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261276r996316_rule8386 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261276r996316_rule
8387 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
8388 [[packages]] 
8389 name·=·"kbd" 
8390 version·=·"*" 
8391 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x88387 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
8392 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8388 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8393 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8389 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8394 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8390 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8395 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8391 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8396 #·Remediation·is·applicable·only·in·certain·platforms8392 #·Remediation·is·applicable·only·in·certain·platforms
8397 if·rpm·--quiet·-q·kernel-default;·then8393 if·rpm·--quiet·-q·kernel-default;·then
Offset 8430, 14 lines modifiedOffset 8425, 19 lines modified
8430 ··-·DISA-STIG-SLEM-05-2150108425 ··-·DISA-STIG-SLEM-05-215010
8431 ··-·enable_strategy8426 ··-·enable_strategy
8432 ··-·low_complexity8427 ··-·low_complexity
8433 ··-·low_disruption8428 ··-·low_disruption
8434 ··-·medium_severity8429 ··-·medium_severity
8435 ··-·no_reboot_needed8430 ··-·no_reboot_needed
8436 ··-·vlock_installed8431 ··-·vlock_installed
 8432 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 8433 [[packages]]
 8434 name·=·"kbd"
 8435 version·=·"*"
8437 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x88436 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
8438 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low8437 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
8439 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low8438 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
8440 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false8439 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
8441 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable8440 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
8442 include·install_kbd8441 include·install_kbd
  
Offset 11667, 19 lines modifiedOffset 11667, 14 lines modified
11667 ·············data·that·is·stored·on·the·local·system.11667 ·············data·that·is·stored·on·the·local·system.
11668 Severity: ···medium11668 Severity: ···medium
11669 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed11669 Rule·ID:·····xccdf_org.ssgproject.content_rule_package_systemd-journal-remote_installed
11670 Identifiers:·CCE-94085-811670 Identifiers:·CCE-94085-8
11671 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-0022411671 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-00224
11672 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-65201011672 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-652010
11673 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule11673 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule
11674 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8 
  
11675 [[packages]] 
11676 name·=·"systemd-journal-remote" 
11677 version·=·"*" 
11678 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x811674 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8S_\x8h_\x8e_\x8l_\x8l_\x8·_\x8s_\x8c_\x8r_\x8i_\x8p_\x8t_\x8·_\x8
11679 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11675 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11680 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11676 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11681 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11677 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11682 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable11678 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
11683 #·Remediation·is·applicable·only·in·certain·platforms11679 #·Remediation·is·applicable·only·in·certain·platforms
11684 if·rpm·--quiet·-q·kernel-default;·then11680 if·rpm·--quiet·-q·kernel-default;·then
Offset 11717, 14 lines modifiedOffset 11712, 19 lines modified
11717 ··-·DISA-STIG-SLEM-05-65201011712 ··-·DISA-STIG-SLEM-05-652010
11718 ··-·enable_strategy11713 ··-·enable_strategy
11719 ··-·low_complexity11714 ··-·low_complexity
11720 ··-·low_disruption11715 ··-·low_disruption
11721 ··-·medium_severity11716 ··-·medium_severity
11722 ··-·no_reboot_needed11717 ··-·no_reboot_needed
11723 ··-·package_systemd-journal-remote_installed11718 ··-·package_systemd-journal-remote_installed
 11719 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8O_\x8S_\x8B_\x8u_\x8i_\x8l_\x8d_\x8·_\x8B_\x8l_\x8u_\x8e_\x8p_\x8r_\x8i_\x8n_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
  
 11720 [[packages]]
 11721 name·=·"systemd-journal-remote"
 11722 version·=·"*"
11724 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x811723 _\x8R_\x8e_\x8m_\x8e_\x8d_\x8i_\x8a_\x8t_\x8i_\x8o_\x8n_\x8·_\x8P_\x8u_\x8p_\x8p_\x8e_\x8t_\x8·_\x8s_\x8n_\x8i_\x8p_\x8p_\x8e_\x8t_\x8·_\x8
11725 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low11724 C\x8Co\x8om\x8mp\x8pl\x8le\x8ex\x8xi\x8it\x8ty\x8y:\x8:·low
11726 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low11725 D\x8Di\x8is\x8sr\x8ru\x8up\x8pt\x8ti\x8io\x8on\x8n:\x8:·low
11727 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false11726 R\x8Re\x8eb\x8bo\x8oo\x8ot\x8t:\x8:·····false
11728 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable11727 S\x8St\x8tr\x8ra\x8at\x8te\x8eg\x8gy\x8y:\x8:···enable
11729 include·install_systemd-journal-remote11728 include·install_systemd-journal-remote
  
Offset 11742, 18 lines modifiedOffset 11742, 14 lines modified
11742 ·············real·time·and·offload·standalone·systems·at·least·weekly.11742 ·············real·time·and·offload·standalone·systems·at·least·weekly.
11743 Severity: ···medium11743 Severity: ···medium
11744 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_systemd-journal-upload_enabled11744 Rule·ID:·····xccdf_org.ssgproject.content_rule_service_systemd-journal-upload_enabled
11745 Identifiers:·CCE-94084-111745 Identifiers:·CCE-94084-1
11746 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-0022411746 ·············_\x8o_\x8s_\x8-_\x8s_\x8r_\x8g··SRG-OS-000479-GPOS-00224
11747 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-65201011747 References:··_\x8s_\x8t_\x8i_\x8g_\x8i_\x8d··SLEM-05-652010
11748 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule11748 ·············_\x8s_\x8t_\x8i_\x8g_\x8r_\x8e_\x8f·SV-261409r996643_rule
Max diff block lines reached; 17014/22214 bytes (76.59%) of diff not shown.
3.51 MB
./usr/share/doc/ssg-nondebian/table-ol7-anssirefs.html
    
Offset 63, 273 lines modifiedOffset 63, 273 lines modified
000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····
000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<
00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat
00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</
00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>
00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t
00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······
 00000450:·3c74·643e·456e·7375·7265·2053·4d41·5020··<td>Ensure·SMAP·
 00000460:·6973·206e·6f74·2064·6973·6162·6c65·6420··is·not·disabled·
 00000470:·6475·7269·6e67·2062·6f6f·743c·2f74·643e··during·boot</td>
00000450:·3c74·643e·496e·7374·616c·6c20·5041·4520··<td>Install·PAE· 
00000460:·4b65·726e·656c·206f·6e20·5375·7070·6f72··Kernel·on·Suppor 
00000470:·7465·6420·3332·2d62·6974·2078·3836·2053··ted·32-bit·x86·S 
00000480:·7973·7465·6d73·3c2f·7464·3e0a·2020·2020··ystems</td>.···· 
00000490:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang=" 
000004a0:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········ 
000004b0:·5379·7374·656d·7320·7468·6174·2061·7265··Systems·that·are 
000004c0:·2075·7369·6e67·2074·6865·2036·342d·6269···using·the·64-bi 
000004d0:·7420·7838·3620·6b65·726e·656c·2070·6163··t·x86·kernel·pac 
000004e0:·6b61·6765·0a64·6f20·6e6f·7420·6e65·6564··kage.do·not·need 
000004f0:·2074·6f20·696e·7374·616c·6c20·7468·6520···to·install·the· 
00000500:·6b65·726e·656c·2d50·4145·2070·6163·6b61··kernel-PAE·packa 
00000510:·6765·2062·6563·6175·7365·2074·6865·2036··ge·because·the·6 
00000520:·342d·6269·740a·7838·3620·6b65·726e·656c··4-bit.x86·kernel 
00000530:·2061·6c72·6561·6479·2069·6e63·6c75·6465···already·include 
00000540:·7320·7468·6973·2073·7570·706f·7274·2e20··s·this·support.· 
00000550:·486f·7765·7665·722c·2069·6620·7468·6520··However,·if·the· 
00000560:·7379·7374·656d·2069·730a·3332·2d62·6974··system·is.32-bit 
00000570:·2061·6e64·2061·6c73·6f20·7375·7070·6f72···and·also·suppor 
00000580:·7473·2074·6865·2050·4145·2061·6e64·204e··ts·the·PAE·and·N 
00000590:·5820·6665·6174·7572·6573·2061·730a·6465··X·features·as.de 
000005a0:·7465·726d·696e·6564·2069·6e20·7468·6520··termined·in·the· 
000005b0:·7072·6576·696f·7573·2073·6563·7469·6f6e··previous·section 
000005c0:·2c20·7468·6520·6b65·726e·656c·2d50·4145··,·the·kernel-PAE 
000005d0:·2070·6163·6b61·6765·2073·686f·756c·640a···package·should. 
000005e0:·6265·2069·6e73·7461·6c6c·6564·2074·6f20··be·installed·to· 
000005f0:·656e·6162·6c65·2058·4420·6f72·204e·5820··enable·XD·or·NX· 
00000600:·7375·7070·6f72·742e·0a54·6865·203c·636f··support..The·<co 
00000610:·6465·3e6b·6572·6e65·6c2d·5041·453c·2f63··de>kernel-PAE</c 
00000620:·6f64·653e·2070·6163·6b61·6765·2063·616e··ode>·package·can 
00000630:·2062·6520·696e·7374·616c·6c65·6420·7769···be·installed·wi 
00000640:·7468·2074·6865·2066·6f6c·6c6f·7769·6e67··th·the·following 
00000650:·2063·6f6d·6d61·6e64·3a0a·3c70·7265·3e0a···command:.<pre>. 
00000660:·2420·7375·646f·2079·756d·2069·6e73·7461··$·sudo·yum·insta 
00000670:·6c6c·206b·6572·6e65·6c2d·5041·453c·2f70··ll·kernel-PAE</p 
00000680:·7265·3e0a·5468·6520·696e·7374·616c·6c61··re>.The·installa 
00000690:·7469·6f6e·2070·726f·6365·7373·2073·686f··tion·process·sho 
000006a0:·756c·6420·616c·736f·2068·6176·6520·636f··uld·also·have·co 
000006b0:·6e66·6967·7572·6564·2074·6865·0a62·6f6f··nfigured·the.boo 
000006c0:·746c·6f61·6465·7220·746f·206c·6f61·6420··tloader·to·load· 
000006d0:·7468·6520·6e65·7720·6b65·726e·656c·2061··the·new·kernel·a 
000006e0:·7420·626f·6f74·2e20·5665·7269·6679·2074··t·boot.·Verify·t 
000006f0:·6869·7320·6166·7465·7220·7265·626f·6f74··his·after·reboot 
00000700:·0a61·6e64·206d·6f64·6966·7920·3c74·743e··.and·modify·<tt> 
00000710:·2f65·7463·2f64·6566·6175·6c74·2f67·7275··/etc/default/gru 
00000720:·623c·2f74·743e·2069·6620·6e65·6365·7373··b</tt>·if·necess 
00000730:·6172·792e·0a20·2020·2020·203c·2f74·643e··ary..······</td> 
00000740:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l00000480:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l
00000750:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···00000490:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···
00000760:·2020·2020·204f·6e20·3332·2d62·6974·2073·······On·32-bit·s 
00000770:·7973·7465·6d73·2074·6861·7420·7375·7070··ystems·that·supp 
00000780:·6f72·7420·7468·6520·5844·206f·7220·4e58··ort·the·XD·or·NX 
00000790:·2062·6974·2c20·7468·6520·7665·6e64·6f72···bit,·the·vendor 
000007a0:·2d73·7570·706c·6965·640a·5041·4520·6b65··-supplied.PAE·ke 
000007b0:·726e·656c·2069·7320·7265·7175·6972·6564··rnel·is·required 
000007c0:·2074·6f20·656e·6162·6c65·2065·6974·6865···to·enable·eithe 
000007d0:·7220·4578·6563·7574·6520·4469·7361·626c··r·Execute·Disabl 
000007e0:·6520·2858·4429·206f·7220·4e6f·2045·7865··e·(XD)·or·No·Exe 
000007f0:·6375·7465·2028·4e58·2920·7375·7070·6f72··cute·(NX)·suppor 
00000800:·742e·0a20·2020·2020·203c·2f74·643e·0a20··t..······</td>.· 
00000810:·2020·203c·2f74·723e·0a20·2020·203c·7472·····</tr>.····<tr 
00000820:·3e0a·2020·2020·2020·3c74·643e·5231·3c2f··>.······<td>R1</ 
00000830:·7464·3e0a·2020·2020·2020·3c74·643e·5072··td>.······<td>Pr 
00000840:·6566·6572·2074·6f20·7573·6520·6120·3634··efer·to·use·a·64 
00000850:·2d62·6974·204f·7065·7261·7469·6e67·2053··-bit·Operating·S 
00000860:·7973·7465·6d20·7768·656e·2073·7570·706f··ystem·when·suppo 
00000870:·7274·6564·3c2f·7464·3e0a·2020·2020·2020··rted</td>.······ 
00000880:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en 
00000890:·2d55·5322·3e0a·2020·2020·2020·2020·5072··-US">.········Pr 
000008a0:·6566·6572·2069·6e73·7461·6c6c·6174·696f··efer·installatio 
000008b0:·6e20·6f66·2036·342d·6269·7420·6f70·6572··n·of·64-bit·oper 
000008c0:·6174·696e·6720·7379·7374·656d·7320·7768··ating·systems·wh 
000008d0:·656e·2074·6865·2043·5055·2073·7570·706f··en·the·CPU·suppo 
000008e0:·7274·7320·6974·2e0a·2020·2020·2020·3c2f··rts·it..······</ 
000008f0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm 
00000900:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">. 
00000910:·2020·2020·2020·2020·5573·6520·6f66·2061··········Use·of·a 
00000920:·2036·342d·6269·7420·6f70·6572·6174·696e···64-bit·operatin 
00000930:·6720·7379·7374·656d·206f·6666·6572·7320··g·system·offers· 
00000940:·6120·6665·7720·6164·7661·6e74·6167·6573··a·few·advantages 
00000950:·2c20·6c69·6b65·2061·206c·6172·6765·7220··,·like·a·larger· 
00000960:·6164·6472·6573·7320·7370·6163·6520·7261··address·space·ra 
00000970:·6e67·6520·666f·720a·4164·6472·6573·7320··nge·for.Address· 
00000980:·5370·6163·6520·4c61·796f·7574·2052·616e··Space·Layout·Ran 
00000990:·646f·6d69·7a61·7469·6f6e·2028·4153·4c52··domization·(ASLR 
000009a0:·2920·616e·6420·7379·7374·656d·6174·6963··)·and·systematic 
000009b0:·2070·7265·7365·6e63·6520·6f66·204e·6f20···presence·of·No· 
000009c0:·6558·6563·7574·6520·616e·6420·4578·6563··eXecute·and·Exec 
000009d0:·7574·6520·4469·7361·626c·6520·284e·582f··ute·Disable·(NX/ 
000009e0:·5844·2920·7072·6f74·6563·7469·6f6e·2062··XD)·protection·b 
000009f0:·6974·732e·0a20·2020·2020·203c·2f74·643e··its..······</td> 
00000a00:·0a20·2020·203c·2f74·723e·0a20·2020·203c··.····</tr>.····< 
00000a10:·7472·3e0a·2020·2020·2020·3c74·643e·5231··tr>.······<td>R1 
00000a20:·3c2f·7464·3e0a·2020·2020·2020·3c74·643e··</td>.······<td> 
00000a30:·456e·7375·7265·2053·4d45·5020·6973·206e··Ensure·SMEP·is·n 
00000a40:·6f74·2064·6973·6162·6c65·6420·6475·7269··ot·disabled·duri 
00000a50:·6e67·2062·6f6f·743c·2f74·643e·0a20·2020··ng·boot</td>.··· 
00000a60:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang= 
00000a70:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.······· 
00000a80:·2054·6865·2053·4d45·5020·6973·2075·7365···The·SMEP·is·use000004a0:·2020·2020·2054·6865·2053·4d41·5020·6973·······The·SMAP·is
00000a90:·6420·746f·2070·7265·7665·6e74·2074·6865··d·to·prevent·the000004b0:·2075·7365·6420·746f·2070·7265·7665·6e74···used·to·prevent
00000aa0:·2073·7570·6572·7669·736f·7220·6d6f·6465···supervisor·mode000004c0:·2074·6865·2073·7570·6572·7669·736f·7220···the·supervisor·
00000ab0:·2066·726f·6d20·6578·6563·7574·696e·6720···from·executing· 
00000ac0:·7573·6572·2073·7061·6365·2063·6f64·652c··user·space·code,000004d0:·6d6f·6465·2066·726f·6d20·756e·696e·7465··mode·from·uninte
 000004e0:·6e74·696f·6e61·6c6c·7920·7265·6164·696e··ntionally·readin
 000004f0:·672f·7772·6974·696e·6720·696e·746f·0a6d··g/writing·into.m
 00000500:·656d·6f72·7920·7061·6765·7320·696e·2074··emory·pages·in·t
 00000510:·6865·2075·7365·7220·7370·6163·652c·2069··he·user·space,·i
00000ad0:·0a69·7420·6973·2065·6e61·626c·6564·2062··.it·is·enabled·b00000520:·7420·6973·2065·6e61·626c·6564·2062·7920··t·is·enabled·by·
00000ae0:·7920·6465·6661·756c·7420·7369·6e63·6520··y·default·since·00000530:·6465·6661·756c·7420·7369·6e63·6520·4c69··default·since·Li
00000af0:·4c69·6e75·7820·6b65·726e·656c·2033·2e30··Linux·kernel·3.000000540:·6e75·7820·6b65·726e·656c·2033·2e37·2e0a··nux·kernel·3.7..
00000b00:·2e20·4275·7420·6974·2063·6f75·6c64·2062··.·But·it·could·b00000550:·4275·7420·6974·2063·6f75·6c64·2062·6520··But·it·could·be·
00000b10:·6520·6469·7361·626c·6564·2074·6872·6f75··e·disabled·throu00000560:·6469·7361·626c·6564·2074·6872·6f75·6768··disabled·through
00000b20:·6768·0a6b·6572·6e65·6c20·626f·6f74·2070··gh.kernel·boot·p00000570:·206b·6572·6e65·6c20·626f·6f74·2070·6172···kernel·boot·par
00000b30:·6172·616d·6574·6572·732e·0a0a·456e·7375··arameters...Ensu00000580:·616d·6574·6572·732e·0a0a·456e·7375·7265··ameters...Ensure
00000b40:·7265·2074·6861·7420·5375·7065·7276·6973··re·that·Supervis00000590:·2074·6861·7420·5375·7065·7276·6973·6f72···that·Supervisor
00000b50:·6f72·204d·6f64·6520·4578·6563·7574·696f··or·Mode·Executio 
Max diff block lines reached; 2960854/2997170 bytes (98.79%) of diff not shown.
664 KB
html2text {}
Max HTML report size reached
1.26 MB
./usr/share/doc/ssg-nondebian/table-ol7-cuirefs.html
Ordering differences only
    
Offset 41, 78 lines modifiedOffset 41, 30 lines modified
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td>47 ······<td>3.1.1<br/>3.1.5</td>
 48 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td>
48 ······<td>Verify·Only·Root·Has·UID·0</td> 
49 ······<td·xml:lang="en-US"> 
50 ········If·any·account·other·than·root·has·a·UID·of·0,·this·misconfiguration·should 
51 be·investigated·and·the·accounts·other·than·root·should·be·removed·or·have 
52 their·UID·changed. 
53 <br·/> 
54 If·the·account·is·associated·with·system·commands·or·applications·the·UID 
55 should·be·changed·to·one·greater·than·"0"·but·less·than·"1000." 
56 Otherwise·assign·a·UID·greater·than·"1000"·that·has·not·already·been 
57 assigned. 
58 ······</td> 
59 ······<td·xml:lang="en-US"> 
60 ········An·account·has·root·authority·if·it·has·a·UID·of·0.·Multiple·accounts 
61 with·a·UID·of·0·afford·more·opportunity·for·potential·intruders·to 
62 guess·a·password·for·a·privileged·account.·Proper·configuration·of 
63 sudo·is·recommended·to·afford·multiple·system·administrators 
64 access·to·root·privileges·in·an·accountable·manner. 
65 ······</td> 
66 ····</tr> 
67 ····<tr> 
68 ······<td>3.1.1<br/>3.1.6</td> 
69 ······<td>Direct·root·Logins·Not·Allowed</td> 
70 ······<td·xml:lang="en-US"> 
71 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators 
72 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file. 
73 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does 
74 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the 
75 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous 
76 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in 
77 plain·text·over·the·network.·By·default,·Oracle·Linux·7's 
78 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console 
79 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the 
80 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this 
81 file·by·typing·the·following·command: 
82 <pre> 
83 $·sudo·echo·&gt;·/etc/securetty 
84 </pre> 
85 ······</td> 
86 ······<td·xml:lang="en-US"> 
87 ········Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor 
88 authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate 
89 to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low 
90 and·FISMA·Moderate·systems. 
91 ······</td> 
92 ····</tr> 
93 ····<tr> 
94 ······<td>3.1.1<br/>3.1.5</td> 
95 ······<td>Disable·SSH·Root·Login</td> 
96 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
97 ········The·root·user·should·never·be·allowed·to·login·to·a 
98 system·directly·over·a·network. 
99 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
 50 ········If·an·account·is·configured·for·password·authentication
 51 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log
 52 into·the·account·without·authentication.·Remove·any·instances·of·the
 53 <tt>nullok</tt>·in
  
100 <tt>/etc/ssh/sshd_config</tt>:54 <tt>/etc/pam.d/system-auth</tt>·and
 55 <tt>/etc/pam.d/password-auth</tt>
  
101 <pre>PermitRootLogin·no</pre>56 to·prevent·logins·with·empty·passwords.
102 ······</td>57 ······</td>
103 ······<td·xml:lang="en-US">58 ······<td·xml:lang="en-US">
 59 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and
 60 run·commands·with·the·privileges·of·that·account.·Accounts·with
 61 empty·passwords·should·never·be·used·in·operational·environments.
104 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
105 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
106 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
107 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
108 direct·attack·attempts·on·root's·password. 
109 ······</td>62 ······</td>
110 ····</tr>63 ····</tr>
111 ····<tr>64 ····<tr>
112 ······<td>3.1.1</td>65 ······<td>3.1.1</td>
113 ······<td>Disable·GDM·Automatic·Login</td>66 ······<td>Disable·GDM·Automatic·Login</td>
114 ······<td·xml:lang="en-US">67 ······<td·xml:lang="en-US">
115 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without68 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without
Offset 125, 63 lines modifiedOffset 77, 28 lines modified
125 ······</td>77 ······</td>
126 ······<td·xml:lang="en-US">78 ······<td·xml:lang="en-US">
127 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating79 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
128 system·security.80 system·security.
129 ······</td>81 ······</td>
130 ····</tr>82 ····</tr>
131 ····<tr>83 ····<tr>
132 ······<td>3.1.1<br/>3.1.5</td>84 ······<td>3.1.1<br/>3.4.5</td>
 85 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td>
133 ······<td>Restrict·Virtual·Console·Root·Logins</td> 
134 ······<td·xml:lang="en-US"> 
135 ········To·restrict·root·logins·through·the·(deprecated)·virtual·console·devices, 
136 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
137 <pre>vc/1 
138 vc/2 
139 vc/3 
140 vc/4</pre> 
141 ······</td> 
142 ······<td·xml:lang="en-US"> 
143 ········Preventing·direct·root·login·to·virtual·console·devices 
144 helps·ensure·accountability·for·actions·taken·on·the·system 
145 using·the·root·account. 
146 ······</td> 
147 ····</tr> 
148 ····<tr> 
149 ······<td>3.1.1<br/>3.1.5</td> 
150 ······<td>Restrict·Serial·Port·Root·Logins</td> 
151 ······<td·xml:lang="en-US"> 
152 ········To·restrict·root·logins·on·serial·ports, 
153 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
154 <pre>ttyS0 
155 ttyS1</pre> 
156 ······</td> 
157 ······<td·xml:lang="en-US"> 
158 ········Preventing·direct·root·login·to·serial·port·interfaces 
159 helps·ensure·accountability·for·actions·taken·on·the·systems 
160 using·the·root·account. 
161 ······</td> 
162 ····</tr> 
163 ····<tr> 
Max diff block lines reached; 466633/472009 bytes (98.86%) of diff not shown.
829 KB
html2text {}
Max HTML report size reached
9.66 MB
./usr/share/doc/ssg-nondebian/table-ol7-nistrefs.html
    
Offset 64, 14948 lines modifiedOffset 64, 14948 lines modified
000003f0:·6c65·3c2f·7468·3e0a·2020·2020·3c74·683e··le</th>.····<th>000003f0:·6c65·3c2f·7468·3e0a·2020·2020·3c74·683e··le</th>.····<th>
00000400:·4465·7363·7269·7074·696f·6e3c·2f74·683e··Description</th>00000400:·4465·7363·7269·7074·696f·6e3c·2f74·683e··Description</th>
00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa
00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea
00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<
00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU
Diff chunk too large, falling back to line-by-line diff (14934 lines added, 14934 lines removed)
00000450:·2d32·2864·293c·6272·2f3e·4155·2d31·3228··-2(d)<br/>AU-12(00000450:·2d32·2864·293c·6272·2f3e·4155·2d31·3228··-2(d)<br/>AU-12(
00000460:·6329·3c62·722f·3e43·4d2d·3628·6129·3c2f··c)<br/>CM-6(a)</00000460:·6329·3c62·722f·3e41·432d·3628·3929·3c62··c)<br/>AC-6(9)<b
00000470:·7464·3e0a·2020·2020·2020·3c74·643e·5265··td>.······<td>Re00000470:·722f·3e43·4d2d·3628·6129·3c2f·7464·3e0a··r/>CM-6(a)</td>.
00000480:·636f·7264·2045·7665·6e74·7320·7468·6174··cord·Events·that00000480:·2020·2020·2020·3c74·643e·456e·7375·7265········<td>Ensure
00000490:·204d·6f64·6966·7920·7468·6520·5379·7374···Modify·the·Syst00000490:·2061·7564·6974·6420·436f·6c6c·6563·7473···auditd·Collects
000004a0:·656d·2773·2044·6973·6372·6574·696f·6e61··em's·Discretiona000004a0:·2049·6e66·6f72·6d61·7469·6f6e·206f·6e20···Information·on·
000004b0:·7279·2041·6363·6573·7320·436f·6e74·726f··ry·Access·Contro000004b0:·7468·6520·5573·6520·6f66·2050·7269·7669··the·Use·of·Privi
000004c0:·6c73·202d·2063·686d·6f64·3c2f·7464·3e0a··ls·-·chmod</td>.000004c0:·6c65·6765·6420·436f·6d6d·616e·6473·202d··leged·Commands·-
000004d0:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la000004d0:·2075·6d6f·756e·743c·2f74·643e·0a20·2020···umount</td>.···
000004e0:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····000004e0:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=
000004f0:·2020·2020·4174·2061·206d·696e·696d·756d······At·a·minimum000004f0:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······
00000500:·2c20·7468·6520·6175·6469·7420·7379·7374··,·the·audit·syst00000500:·2041·7420·6120·6d69·6e69·6d75·6d2c·2074···At·a·minimum,·t
00000510:·656d·2073·686f·756c·6420·636f·6c6c·6563··em·should·collec00000510:·6865·2061·7564·6974·2073·7973·7465·6d20··he·audit·system·
00000520:·7420·6669·6c65·2070·6572·6d69·7373·696f··t·file·permissio00000520:·7368·6f75·6c64·2063·6f6c·6c65·6374·2074··should·collect·t
00000530:·6e0a·6368·616e·6765·7320·666f·7220·616c··n.changes·for·al00000530:·6865·2065·7865·6375·7469·6f6e·206f·660a··he·execution·of.
00000540:·6c20·7573·6572·7320·616e·6420·726f·6f74··l·users·and·root00000540:·7072·6976·696c·6567·6564·2063·6f6d·6d61··privileged·comma
00000550:·2e20·4966·2074·6865·203c·7474·3e61·7564··.·If·the·<tt>aud00000550:·6e64·7320·666f·7220·616c·6c20·7573·6572··nds·for·all·user
00000560:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·00000560:·7320·616e·6420·726f·6f74·2e20·4966·2074··s·and·root.·If·t
00000570:·6973·2063·6f6e·6669·6775·7265·6420·746f··is·configured·to00000570:·6865·203c·7474·3e61·7564·6974·643c·2f74··he·<tt>auditd</t
00000580:·0a75·7365·2074·6865·203c·7474·3e61·7567··.use·the·<tt>aug00000580:·743e·2064·6165·6d6f·6e20·6973·0a63·6f6e··t>·daemon·is.con
00000590:·656e·7275·6c65·733c·2f74·743e·2070·726f··enrules</tt>·pro00000590:·6669·6775·7265·6420·746f·2075·7365·2074··figured·to·use·t
000005a0:·6772·616d·2074·6f20·7265·6164·2061·7564··gram·to·read·aud000005a0:·6865·203c·7474·3e61·7567·656e·7275·6c65··he·<tt>augenrule
000005b0:·6974·2072·756c·6573·2064·7572·696e·6720··it·rules·during·000005b0:·733c·2f74·743e·2070·726f·6772·616d·2074··s</tt>·program·t
000005c0:·6461·656d·6f6e·2073·7461·7274·7570·0a28··daemon·startup.(000005c0:·6f20·7265·6164·2061·7564·6974·2072·756c··o·read·audit·rul
000005d0:·7468·6520·6465·6661·756c·7429·2c20·6164··the·default),·ad000005d0:·6573·2064·7572·696e·670a·6461·656d·6f6e··es·during.daemon
000005e0:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·000005e0:·2073·7461·7274·7570·2028·7468·6520·6465···startup·(the·de
000005f0:·6c69·6e65·2074·6f20·6120·6669·6c65·2077··line·to·a·file·w000005f0:·6661·756c·7429·2c20·6164·6420·6120·6c69··fault),·add·a·li
00000600:·6974·6820·7375·6666·6978·203c·7474·3e2e··ith·suffix·<tt>.00000600:·6e65·206f·6620·7468·6520·666f·6c6c·6f77··ne·of·the·follow
00000610:·7275·6c65·733c·2f74·743e·2069·6e0a·7468··rules</tt>·in.th00000610:·696e·6720·666f·726d·2074·6f20·6120·6669··ing·form·to·a·fi
00000620:·6520·6469·7265·6374·6f72·7920·3c74·743e··e·directory·<tt>00000620:·6c65·2077·6974·680a·7375·6666·6978·203c··le·with.suffix·<
00000630:·2f65·7463·2f61·7564·6974·2f72·756c·6573··/etc/audit/rules00000630:·7474·3e2e·7275·6c65·733c·2f74·743e·2069··tt>.rules</tt>·i
00000640:·2e64·3c2f·7474·3e3a·0a3c·7072·653e·2d61··.d</tt>:.<pre>-a00000640:·6e20·7468·6520·6469·7265·6374·6f72·7920··n·the·directory·
00000650:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·00000650:·3c74·743e·2f65·7463·2f61·7564·6974·2f72··<tt>/etc/audit/r
00000660:·6172·6368·3d62·3332·202d·5320·6368·6d6f··arch=b32·-S·chmo00000660:·756c·6573·2e64·3c2f·7474·3e3a·0a3c·7072··ules.d</tt>:.<pr
00000670:·6420·2d46·2061·7569·6426·6774·3b3d·3130··d·-F·auid&gt;=1000000670:·653e·2d61·2061·6c77·6179·732c·6578·6974··e>-a·always,exit
00000680:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse00000680:·202d·4620·7061·7468·3d2f·7573·722f·6269···-F·path=/usr/bi
00000690:·7420·2d46·206b·6579·3d70·6572·6d5f·6d6f··t·-F·key=perm_mo00000690:·6e2f·756d·6f75·6e74·202d·4620·7065·726d··n/umount·-F·perm
000006a0:·643c·2f70·7265·3e0a·4966·2074·6865·2073··d</pre>.If·the·s000006a0:·3d78·202d·4620·6175·6964·2667·743b·3d31··=x·-F·auid&gt;=1
000006b0:·7973·7465·6d20·6973·2036·3420·6269·7420··ystem·is·64·bit·000006b0:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns
000006c0:·7468·656e·2061·6c73·6f20·6164·6420·7468··then·also·add·th000006c0:·6574·202d·4620·6b65·793d·7072·6976·696c··et·-F·key=privil
000006d0:·6520·666f·6c6c·6f77·696e·6720·6c69·6e65··e·following·line000006d0:·6567·6564·3c2f·7072·653e·0a49·6620·7468··eged</pre>.If·th
000006e0:·3a0a·3c70·7265·3e2d·6120·616c·7761·7973··:.<pre>-a·always000006e0:·6520·3c74·743e·6175·6469·7464·3c2f·7474··e·<tt>auditd</tt
000006f0:·2c65·7869·7420·2d46·2061·7263·683d·6236··,exit·-F·arch=b6000006f0:·3e20·6461·656d·6f6e·2069·7320·636f·6e66··>·daemon·is·conf
00000700:·3420·2d53·2063·686d·6f64·202d·4620·6175··4·-S·chmod·-F·au00000700:·6967·7572·6564·2074·6f20·7573·6520·7468··igured·to·use·th
00000710:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a00000710:·6520·3c74·743e·6175·6469·7463·746c·3c2f··e·<tt>auditctl</
00000720:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke00000720:·7474·3e0a·7574·696c·6974·7920·746f·2072··tt>.utility·to·r
00000730:·793d·7065·726d·5f6d·6f64·3c2f·7072·653e··y=perm_mod</pre>00000730:·6561·6420·6175·6469·7420·7275·6c65·7320··ead·audit·rules·
00000740:·0a49·6620·7468·6520·3c74·743e·6175·6469··.If·the·<tt>audi00000740:·6475·7269·6e67·2064·6165·6d6f·6e20·7374··during·daemon·st
00000750:·7464·3c2f·7474·3e20·6461·656d·6f6e·2069··td</tt>·daemon·i00000750:·6172·7475·702c·2061·6464·2061·206c·696e··artup,·add·a·lin
00000760:·7320·636f·6e66·6967·7572·6564·2074·6f20··s·configured·to·00000760:·6520·6f66·2074·6865·2066·6f6c·6c6f·7769··e·of·the·followi
00000770:·7573·6520·7468·6520·3c74·743e·6175·6469··use·the·<tt>audi00000770:·6e67·0a66·6f72·6d20·746f·203c·7474·3e2f··ng.form·to·<tt>/
00000780:·7463·746c·3c2f·7474·3e0a·7574·696c·6974··tctl</tt>.utilit00000780:·6574·632f·6175·6469·742f·6175·6469·742e··etc/audit/audit.
00000790:·7920·746f·2072·6561·6420·6175·6469·7420··y·to·read·audit·00000790:·7275·6c65·733c·2f74·743e·3a0a·3c70·7265··rules</tt>:.<pre
000007a0:·7275·6c65·7320·6475·7269·6e67·2064·6165··rules·during·dae000007a0:·3e2d·6120·616c·7761·7973·2c65·7869·7420··>-a·always,exit·
000007b0:·6d6f·6e20·7374·6172·7475·702c·2061·6464··mon·startup,·add000007b0:·2d46·2070·6174·683d·2f75·7372·2f62·696e··-F·path=/usr/bin
000007c0:·2074·6865·2066·6f6c·6c6f·7769·6e67·206c···the·following·l000007c0:·2f75·6d6f·756e·7420·2d46·2070·6572·6d3d··/umount·-F·perm=
000007d0:·696e·6520·746f·0a3c·7474·3e2f·6574·632f··ine·to.<tt>/etc/000007d0:·7820·2d46·2061·7569·6426·6774·3b3d·3130··x·-F·auid&gt;=10
000007e0:·6175·6469·742f·6175·6469·742e·7275·6c65··audit/audit.rule000007e0:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
000007f0:·733c·2f74·743e·2066·696c·653a·0a3c·7072··s</tt>·file:.<pr000007f0:·7420·2d46·206b·6579·3d70·7269·7669·6c65··t·-F·key=privile
00000800:·653e·2d61·2061·6c77·6179·732c·6578·6974··e>-a·always,exit00000800:·6765·643c·2f70·7265·3e0a·2020·2020·2020··ged</pre>.······
00000810:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·00000810:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000820:·6368·6d6f·6420·2d46·2061·7569·6426·6774··chmod·-F·auid&gt00000820:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
00000830:·3b3d·3130·3030·202d·4620·6175·6964·213d··;=1000·-F·auid!=00000830:·3e0a·2020·2020·2020·2020·4d69·7375·7365··>.········Misuse
00000840:·756e·7365·7420·2d46·206b·6579·3d70·6572··unset·-F·key=per00000840:·206f·6620·7072·6976·696c·6567·6564·2066···of·privileged·f
00000850:·6d5f·6d6f·643c·2f70·7265·3e0a·4966·2074··m_mod</pre>.If·t00000850:·756e·6374·696f·6e73·2c20·6569·7468·6572··unctions,·either
00000860:·6865·2073·7973·7465·6d20·6973·2036·3420··he·system·is·64·00000860:·2069·6e74·656e·7469·6f6e·616c·6c79·206f···intentionally·o
00000870:·6269·7420·7468·656e·2061·6c73·6f20·6164··bit·then·also·ad00000870:·7220·756e·696e·7465·6e74·696f·6e61·6c6c··r·unintentionall
00000880:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·00000880:·7920·6279·0a61·7574·686f·7269·7a65·6420··y·by.authorized·
00000890:·6c69·6e65·3a0a·3c70·7265·3e2d·6120·616c··line:.<pre>-a·al00000890:·7573·6572·732c·206f·7220·6279·2075·6e61··users,·or·by·una
000008a0:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc000008a0:·7574·686f·7269·7a65·6420·6578·7465·726e··uthorized·extern
000008b0:·683d·6236·3420·2d53·2063·686d·6f64·202d··h=b64·-S·chmod·-000008b0:·616c·2065·6e74·6974·6965·7320·7468·6174··al·entities·that
000008c0:·4620·6175·6964·2667·743b·3d31·3030·3020··F·auid&gt;=1000·000008c0:·2068·6176·6520·636f·6d70·726f·6d69·7365···have·compromise
000008d0:·2d46·2061·7569·6421·3d75·6e73·6574·202d··-F·auid!=unset·-000008d0:·6420·7379·7374·656d·2061·6363·6f75·6e74··d·system·account
000008e0:·4620·6b65·793d·7065·726d·5f6d·6f64·3c2f··F·key=perm_mod</000008e0:·732c·0a69·7320·6120·7365·7269·6f75·7320··s,.is·a·serious·
000008f0:·7072·653e·0a20·2020·2020·203c·2f74·643e··pre>.······</td>000008f0:·616e·6420·6f6e·676f·696e·6720·636f·6e63··and·ongoing·conc
00000900:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l00000900:·6572·6e20·616e·6420·6361·6e20·6861·7665··ern·and·can·have
00000910:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···00000910:·2073·6967·6e69·6669·6361·6e74·2061·6476···significant·adv
00000920:·2020·2020·2054·6865·2063·6861·6e67·696e·······The·changin00000920:·6572·7365·2069·6d70·6163·7473·206f·6e20··erse·impacts·on·
00000930:·6720·6f66·2066·696c·6520·7065·726d·6973··g·of·file·permis00000930:·6f72·6761·6e69·7a61·7469·6f6e·732e·0a41··organizations..A
00000940:·7369·6f6e·7320·636f·756c·6420·696e·6469··sions·could·indi00000940:·7564·6974·696e·6720·7468·6520·7573·6520··uditing·the·use·
00000950:·6361·7465·2074·6861·7420·6120·7573·6572··cate·that·a·user00000950:·6f66·2070·7269·7669·6c65·6765·6420·6675··of·privileged·fu
00000960:·2069·7320·6174·7465·6d70·7469·6e67·2074···is·attempting·t00000960:·6e63·7469·6f6e·7320·6973·206f·6e65·2077··nctions·is·one·w
00000970:·6f0a·6761·696e·2061·6363·6573·7320·746f··o.gain·access·to00000970:·6179·2074·6f20·6465·7465·6374·2073·7563··ay·to·detect·suc
00000980:·2069·6e66·6f72·6d61·7469·6f6e·2074·6861···information·tha00000980:·6820·6d69·7375·7365·2061·6e64·2069·6465··h·misuse·and·ide
00000990:·7420·776f·756c·6420·6f74·6865·7277·6973··t·would·otherwis00000990:·6e74·6966·790a·7468·6520·7269·736b·2066··ntify.the·risk·f
000009a0:·6520·6265·2064·6973·616c·6c6f·7765·642e··e·be·disallowed.000009a0:·726f·6d20·696e·7369·6465·7220·616e·6420··rom·insider·and·
000009b0:·2041·7564·6974·696e·6720·4441·4320·6d6f···Auditing·DAC·mo000009b0:·6164·7661·6e63·6564·2070·6572·7369·7374··advanced·persist
000009c0:·6469·6669·6361·7469·6f6e·730a·6361·6e20··difications.can·000009c0:·656e·7420·7468·7265·6174·732e·0a3c·6272··ent·threats..<br
000009d0:·6661·6369·6c69·7461·7465·2074·6865·2069··facilitate·the·i000009d0:·202f·3e3c·6272·202f·3e0a·5072·6976·696c···/><br·/>.Privil
000009e0:·6465·6e74·6966·6963·6174·696f·6e20·6f66··dentification·of000009e0:·6567·6564·2070·726f·6772·616d·7320·6172··eged·programs·ar
000009f0:·2070·6174·7465·726e·7320·6f66·2061·6275···patterns·of·abu000009f0:·6520·7375·626a·6563·7420·746f·2065·7363··e·subject·to·esc
00000a00:·7365·2061·6d6f·6e67·2062·6f74·6820·6175··se·among·both·au00000a00:·616c·6174·696f·6e2d·6f66·2d70·7269·7669··alation-of-privi
00000a10:·7468·6f72·697a·6564·2061·6e64·0a75·6e61··thorized·and.una00000a10:·6c65·6765·2061·7474·6163·6b73·2c0a·7768··lege·attacks,.wh
00000a20:·7574·686f·7269·7a65·6420·7573·6572·732e··uthorized·users.00000a20:·6963·6820·6174·7465·6d70·7420·746f·2073··ich·attempt·to·s
00000a30:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···00000a30:·7562·7665·7274·2074·6865·6972·206e·6f72··ubvert·their·nor
00000a40:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.00000a40:·6d61·6c20·726f·6c65·206f·6620·7072·6f76··mal·role·of·prov
00000a50:·2020·2020·2020·3c74·643e·4155·2d32·2864········<td>AU-2(d00000a50:·6964·696e·6720·736f·6d65·206e·6563·6573··iding·some·neces
00000a60:·293c·6272·2f3e·4155·2d31·3228·6329·3c62··)<br/>AU-12(c)<b00000a60:·7361·7279·2062·7574·0a6c·696d·6974·6564··sary·but.limited
00000a70:·722f·3e41·432d·3628·3929·3c62·722f·3e43··r/>AC-6(9)<br/>C00000a70:·2063·6170·6162·696c·6974·792e·2041·7320···capability.·As·
00000a80:·4d2d·3628·6129·3c2f·7464·3e0a·2020·2020··M-6(a)</td>.····00000a80:·7375·6368·2c20·6d6f·7469·7661·7469·6f6e··such,·motivation
00000a90:·2020·3c74·643e·5265·636f·7264·2041·7474····<td>Record·Att00000a90:·2065·7869·7374·7320·746f·206d·6f6e·6974···exists·to·monit
00000aa0:·656d·7074·7320·746f·2041·6c74·6572·204c··empts·to·Alter·L00000aa0:·6f72·2074·6865·7365·2070·726f·6772·616d··or·these·program
00000ab0:·6f67·6f6e·2061·6e64·204c·6f67·6f75·7420··ogon·and·Logout·00000ab0:·7320·666f·720a·756e·7573·7561·6c20·6163··s·for.unusual·ac
00000ac0:·4576·656e·7473·202d·2074·616c·6c79·6c6f··Events·-·tallylo00000ac0:·7469·7669·7479·2e0a·2020·2020·2020·3c2f··tivity..······</
00000ad0:·673c·2f74·643e·0a20·2020·2020·203c·7464··g</td>.······<td00000ad0:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··
00000ae0:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US00000ae0:·2020·3c74·723e·0a20·2020·2020·203c·7464····<tr>.······<td
00000af0:·223e·0a20·2020·2020·2020·2054·6865·2061··">.········The·a00000af0:·3e41·552d·3228·6429·3c62·722f·3e41·552d··>AU-2(d)<br/>AU-
00000b00:·7564·6974·2073·7973·7465·6d20·616c·7265··udit·system·alre00000b00:·3132·2863·293c·6272·2f3e·4143·2d36·2839··12(c)<br/>AC-6(9
00000b10:·6164·7920·636f·6c6c·6563·7473·206c·6f67··ady·collects·log00000b10:·293c·6272·2f3e·434d·2d36·2861·293c·2f74··)<br/>CM-6(a)</t
00000b20:·696e·2069·6e66·6f72·6d61·7469·6f6e·2066··in·information·f00000b20:·643e·0a20·2020·2020·203c·7464·3e45·6e73··d>.······<td>Ens
00000b30:·6f72·2061·6c6c·2075·7365·7273·0a61·6e64··or·all·users.and00000b30:·7572·6520·6175·6469·7464·2043·6f6c·6c65··ure·auditd·Colle
00000b40:·2072·6f6f·742e·2049·6620·7468·6520·3c74···root.·If·the·<t00000b40:·6374·7320·496e·666f·726d·6174·696f·6e20··cts·Information·
00000b50:·743e·6175·6469·7464·3c2f·7474·3e20·6461··t>auditd</tt>·da00000b50:·6f6e·2074·6865·2055·7365·206f·6620·5072··on·the·Use·of·Pr
00000b60:·656d·6f6e·2069·7320·636f·6e66·6967·7572··emon·is·configur00000b60:·6976·696c·6567·6564·2043·6f6d·6d61·6e64··ivileged·Command
00000b70:·6564·2074·6f20·7573·6520·7468·650a·3c74··ed·to·use·the.<t00000b70:·7320·2d20·6d6f·756e·743c·2f74·643e·0a20··s·-·mount</td>.·
00000b80:·743e·6175·6765·6e72·756c·6573·3c2f·7474··t>augenrules</tt00000b80:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan
00000b90:·3e20·7072·6f67·7261·6d20·746f·2072·6561··>·program·to·rea00000b90:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····
00000ba0:·6420·6175·6469·7420·7275·6c65·7320·6475··d·audit·rules·du00000ba0:·2020·2041·7420·6120·6d69·6e69·6d75·6d2c·····At·a·minimum,
00000bb0:·7269·6e67·2064·6165·6d6f·6e20·7374·6172··ring·daemon·star00000bb0:·2074·6865·2061·7564·6974·2073·7973·7465···the·audit·syste
00000bc0:·7475·7020·2874·6865·0a64·6566·6175·6c74··tup·(the.default00000bc0:·6d20·7368·6f75·6c64·2063·6f6c·6c65·6374··m·should·collect
Max diff block lines reached; 5411274/7472744 bytes (72.41%) of diff not shown.
2.53 MB
html2text {}
Max HTML report size reached
579 KB
./usr/share/doc/ssg-nondebian/table-ol7-ospprefs.html
Ordering differences only
    
Offset 41, 28 lines modifiedOffset 41, 14 lines modified
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>AGD_PRE.1<br/>AGD_OPE.1</td>47 ······<td>AGD_PRE.1<br/>AGD_OPE.1</td>
48 ······<td>Install·openscap-scanner·Package</td> 
49 ······<td·xml:lang="en-US"> 
50 ········The·<code>openscap-scanner</code>·package·can·be·installed·with·the·following·command: 
51 <pre> 
52 $·sudo·yum·install·openscap-scanner</pre> 
53 ······</td> 
54 ······<td·xml:lang="en-US"> 
55 ········<tt>openscap-scanner</tt>·contains·the·<tt>oscap</tt>·command·line·tool.·This·tool·is·a 
56 configuration·and·vulnerability·scanner,·capable·of·performing·compliance·checking·using 
57 SCAP·content. 
58 ······</td> 
59 ····</tr> 
60 ····<tr> 
61 ······<td>AGD_PRE.1<br/>AGD_OPE.1</td> 
62 ······<td>Install·scap-security-guide·Package</td>48 ······<td>Install·scap-security-guide·Package</td>
63 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
64 ········The·<code>scap-security-guide</code>·package·can·be·installed·with·the·following·command:50 ········The·<code>scap-security-guide</code>·package·can·be·installed·with·the·following·command:
65 <pre>51 <pre>
66 $·sudo·yum·install·scap-security-guide</pre>52 $·sudo·yum·install·scap-security-guide</pre>
67 ······</td>53 ······</td>
68 ······<td·xml:lang="en-US">54 ······<td·xml:lang="en-US">
Offset 74, 14 lines modifiedOffset 60, 52 lines modified
74 A·system·administrator·can·use·the·<tt>oscap</tt>·CLI·tool·from·the·<tt>openscap-scanner</tt>60 A·system·administrator·can·use·the·<tt>oscap</tt>·CLI·tool·from·the·<tt>openscap-scanner</tt>
75 package,·or·the·SCAP·Workbench·GUI·tool·from·the·<tt>scap-workbench</tt>·package,·to·verify61 package,·or·the·SCAP·Workbench·GUI·tool·from·the·<tt>scap-workbench</tt>·package,·to·verify
76 that·the·system·conforms·to·provided·guidelines.·Refer·to·the·scap-security-guide(8)·manual62 that·the·system·conforms·to·provided·guidelines.·Refer·to·the·scap-security-guide(8)·manual
77 page·for·futher·information.63 page·for·futher·information.
78 ······</td>64 ······</td>
79 ····</tr>65 ····</tr>
80 ····<tr>66 ····<tr>
 67 ······<td>AGD_PRE.1<br/>AGD_OPE.1</td>
 68 ······<td>Install·openscap-scanner·Package</td>
 69 ······<td·xml:lang="en-US">
 70 ········The·<code>openscap-scanner</code>·package·can·be·installed·with·the·following·command:
 71 <pre>
 72 $·sudo·yum·install·openscap-scanner</pre>
 73 ······</td>
 74 ······<td·xml:lang="en-US">
 75 ········<tt>openscap-scanner</tt>·contains·the·<tt>oscap</tt>·command·line·tool.·This·tool·is·a
 76 configuration·and·vulnerability·scanner,·capable·of·performing·compliance·checking·using
 77 SCAP·content.
 78 ······</td>
 79 ····</tr>
 80 ····<tr>
 81 ······<td>AVA_VAN.1</td>
 82 ······<td>Enable·randomization·of·the·page·allocator·in·zIPL</td>
 83 ······<td·xml:lang="en-US">
 84 ········To·enable·the·randomization·of·the·page·allocator·in·the·kernel,·check·that
 85 all·boot·entries·in·<tt>/boot/loader/entries/*.conf</tt>·have
 86 <tt>page_alloc.shuffle=1</tt>·included·in·its·options.<br·/>
  
 87 To·enable·randomization·of·the·page·allocator·also·for··newly·installed
 88 kernels,·add·<tt>page_alloc.shuffle=1</tt>·to·<tt>/etc/kernel/cmdline</tt>.
 89 ······</td>
 90 ······<td·xml:lang="en-US">
 91 ········The·<tt>CONFIG_SHUFFLE_PAGE_ALLOCATOR</tt>·config·option·is·primarily
 92 focused·on·improving·the·average·utilization·of·a·direct-mapped
 93 memory-side-cache.·Aside·of·this·performance·effect,·it·also·reduces
 94 predictability·of·page·allocations·in·situations·when·the·bad·actor·can
 95 crash·the·system·and·somehow·leverage·knowledge·of·(page)·allocation·order
 96 right·after·a·fresh·reboot,·or·can·control·the·timing·between·a
 97 hot-pluggable·memory·node·(as·in·NUMA·node)·and·applications·allocating
 98 memory·ouf·of·that·node.·The·<tt>page_alloc.shuffle=1</tt>·kernel·command
 99 line·parameter·then·forces·this·functionality·irrespectively·of·memory·cache
 100 architecture.
 101 ······</td>
 102 ····</tr>
 103 ····<tr>
81 ······<td>AVA_VAN.1</td>104 ······<td>AVA_VAN.1</td>
82 ······<td>Configure·kernel·to·zero·out·memory·before·allocation</td>105 ······<td>Configure·kernel·to·zero·out·memory·before·allocation</td>
83 ······<td·xml:lang="en-US">106 ······<td·xml:lang="en-US">
84 ········To·configure·the·kernel·to·zero·out·memory·before·allocating·it,·add·the107 ········To·configure·the·kernel·to·zero·out·memory·before·allocating·it,·add·the
85 <tt>init_on_alloc=1</tt>·argument·to·the·default·GRUB·2·command·line.108 <tt>init_on_alloc=1</tt>·argument·to·the·default·GRUB·2·command·line.
86 To·ensure·that·<tt>init_on_alloc=1</tt>·is·added·as·a·kernel·command·line109 To·ensure·that·<tt>init_on_alloc=1</tt>·is·added·as·a·kernel·command·line
87 argument·to·newly·installed·kernels,·add·<tt>init_on_alloc=1</tt>·to·the110 argument·to·newly·installed·kernels,·add·<tt>init_on_alloc=1</tt>·to·the
Offset 114, 38 lines modifiedOffset 138, 14 lines modified
114 all·page·allocator·and·slab·allocator·memory·will·be·zeroed·when·allocated,138 all·page·allocator·and·slab·allocator·memory·will·be·zeroed·when·allocated,
115 eliminating·many·kinds·of·"uninitialized·heap·memory"·flaws,·effectively139 eliminating·many·kinds·of·"uninitialized·heap·memory"·flaws,·effectively
116 preventing·data·leaks.140 preventing·data·leaks.
117 ······</td>141 ······</td>
118 ····</tr>142 ····</tr>
119 ····<tr>143 ····<tr>
120 ······<td>AVA_VAN.1</td>144 ······<td>AVA_VAN.1</td>
121 ······<td>Enable·randomization·of·the·page·allocator·in·zIPL</td> 
122 ······<td·xml:lang="en-US"> 
123 ········To·enable·the·randomization·of·the·page·allocator·in·the·kernel,·check·that 
124 all·boot·entries·in·<tt>/boot/loader/entries/*.conf</tt>·have 
125 <tt>page_alloc.shuffle=1</tt>·included·in·its·options.<br·/> 
  
126 To·enable·randomization·of·the·page·allocator·also·for··newly·installed 
127 kernels,·add·<tt>page_alloc.shuffle=1</tt>·to·<tt>/etc/kernel/cmdline</tt>. 
128 ······</td> 
129 ······<td·xml:lang="en-US"> 
130 ········The·<tt>CONFIG_SHUFFLE_PAGE_ALLOCATOR</tt>·config·option·is·primarily 
131 focused·on·improving·the·average·utilization·of·a·direct-mapped 
132 memory-side-cache.·Aside·of·this·performance·effect,·it·also·reduces 
133 predictability·of·page·allocations·in·situations·when·the·bad·actor·can 
134 crash·the·system·and·somehow·leverage·knowledge·of·(page)·allocation·order 
135 right·after·a·fresh·reboot,·or·can·control·the·timing·between·a 
136 hot-pluggable·memory·node·(as·in·NUMA·node)·and·applications·allocating 
137 memory·ouf·of·that·node.·The·<tt>page_alloc.shuffle=1</tt>·kernel·command 
138 line·parameter·then·forces·this·functionality·irrespectively·of·memory·cache 
139 architecture. 
140 ······</td> 
141 ····</tr> 
142 ····<tr> 
143 ······<td>AVA_VAN.1</td> 
144 ······<td>Enable·randomization·of·the·page·allocator</td>145 ······<td>Enable·randomization·of·the·page·allocator</td>
145 ······<td·xml:lang="en-US">146 ······<td·xml:lang="en-US">
146 ········To·enable·randomization·of·the·page·allocator·in·the·kernel,·add·the147 ········To·enable·randomization·of·the·page·allocator·in·the·kernel,·add·the
147 <tt>page_alloc.shuffle=1</tt>·argument·to·the·default·GRUB·2·command·line.148 <tt>page_alloc.shuffle=1</tt>·argument·to·the·default·GRUB·2·command·line.
148 To·ensure·that·<tt>page_alloc.shuffle=1</tt>·is·added·as·a·kernel·command·line149 To·ensure·that·<tt>page_alloc.shuffle=1</tt>·is·added·as·a·kernel·command·line
149 argument·to·newly·installed·kernels,·add·<tt>page_alloc.shuffle=1</tt>·to·the150 argument·to·newly·installed·kernels,·add·<tt>page_alloc.shuffle=1</tt>·to·the
150 default·Grub2·command·line·for·Linux·operating·systems.·Modify·the·line·within151 default·Grub2·command·line·for·Linux·operating·systems.·Modify·the·line·within
Offset 164, 43 lines modifiedOffset 164, 52 lines modified
164 memory·ouf·of·that·node.·The·<tt>page_alloc.shuffle=1</tt>·kernel·command164 memory·ouf·of·that·node.·The·<tt>page_alloc.shuffle=1</tt>·kernel·command
165 line·parameter·then·forces·this·functionality·irrespectively·of·memory·cache165 line·parameter·then·forces·this·functionality·irrespectively·of·memory·cache
166 architecture.166 architecture.
167 ······</td>167 ······</td>
168 ····</tr>168 ····</tr>
169 ····<tr>169 ····<tr>
Max diff block lines reached; 207141/212904 bytes (97.29%) of diff not shown.
371 KB
html2text {}
    
Offset 1, 20 lines modifiedOffset 1, 13 lines modified
  
  
1 Rules·with·OSPP·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux1 Rules·with·OSPP·Reference·in·Guide·to·the·Secure·Configuration·of·Oracle·Linux
2 72 7
  
  
3 ·························································································································openscap-scanner·contains·the 
4 ·················Install·································································································oscap·command·line·tool.·This 
5 AGD_PRE.1········openscap-······The·openscap-scanner·package·can·be·installed·with·the·following·command:················tool·is·a·configuration·and 
6 AGD_OPE.1········scanner········$·sudo·yum·install·openscap-scanner······················································vulnerability·scanner, 
7 ·················Package·································································································capable·of·performing 
8 ·························································································································compliance·checking·using 
9 ·························································································································SCAP·content. 
10 ·························································································································The·scap-security-guide3 ·························································································································The·scap-security-guide
11 ·························································································································package·provides·a·guide·for4 ·························································································································package·provides·a·guide·for
12 ·························································································································configuration·of·the·system5 ·························································································································configuration·of·the·system
13 ·························································································································from·the·final·system's6 ·························································································································from·the·final·system's
14 ·························································································································security·point·of·view.·The7 ·························································································································security·point·of·view.·The
15 ·························································································································guidance·is·specified·in·the8 ·························································································································guidance·is·specified·in·the
16 ·························································································································Security·Content·Automation9 ·························································································································Security·Content·Automation
Offset 34, 32 lines modifiedOffset 27, 21 lines modified
34 ·························································································································the·SCAP·Workbench·GUI·tool27 ·························································································································the·SCAP·Workbench·GUI·tool
35 ·························································································································from·the·scap-workbench28 ·························································································································from·the·scap-workbench
36 ·························································································································package,·to·verify·that·the29 ·························································································································package,·to·verify·that·the
37 ·························································································································system·conforms·to·provided30 ·························································································································system·conforms·to·provided
38 ·························································································································guidelines.·Refer·to·the31 ·························································································································guidelines.·Refer·to·the
39 ·························································································································scap-security-guide(8)·manual32 ·························································································································scap-security-guide(8)·manual
40 ·························································································································page·for·futher·information.33 ·························································································································page·for·futher·information.
 34 ·························································································································openscap-scanner·contains·the
 35 ·················Install·································································································oscap·command·line·tool.·This
 36 AGD_PRE.1········openscap-······The·openscap-scanner·package·can·be·installed·with·the·following·command:················tool·is·a·configuration·and
 37 AGD_OPE.1········scanner········$·sudo·yum·install·openscap-scanner······················································vulnerability·scanner,
 38 ·················Package·································································································capable·of·performing
 39 ·························································································································compliance·checking·using
41 ································To·configure·the·kernel·to·zero·out·memory·before·allocating·it,·add·the·init_on_alloc=1·When·the·kernel·configuration 
42 ································argument·to·the·default·GRUB·2·command·line.·To·ensure·that·init_on_alloc=1·is·added·as··option·init_on_alloc·is 
43 ·················Configure······a·kernel·command·line·argument·to·newly·installed·kernels,·add·init_on_alloc=1·to·the····enabled,·all·page·allocator 
44 ·················kernel·to·zero·default·Grub2·command·line·for·Linux·operating·systems.·Modify·the·line·within·/etc/·····and·slab·allocator·memory 
45 AVA_VAN.1········out·memory·····default/grub·as·shown·below:·····························································will·be·zeroed·when 
46 ·················before·········GRUB_CMDLINE_LINUX="...·init_on_alloc=1·..."·············································allocated,·eliminating·many 
47 ·················allocation·····Run·the·following·command·to·update·command·line·for·already·installed·kernels:··········kinds·of·"uninitialized·heap 
48 ································#·grubby·--update-kernel=ALL·--args="init_on_alloc=1"····································memory"·flaws,·effectively 
49 ·························································································································preventing·data·leaks.40 ·························································································································SCAP·content.
50 ·························································································································When·the·kernel·configuration 
51 ·················Configure·······························································································option·init_on_alloc·is 
52 ·················kernel·to·zero·To·ensure·that·the·kernel·is·configured·to·zero·out·memory·before·allocation,·check·that·enabled,·all·page·allocator 
53 ·················out·memory·····all·boot·entries·in·/boot/loader/entries/*.conf·have·init_on_alloc=1·included·in·its·····and·slab·allocator·memory 
54 AVA_VAN.1········before·········options.·················································································will·be·zeroed·when 
55 ·················allocation·in··To·ensure·that·new·kernels·and·boot·entries·continue·to·zero·out·memory·before···········allocated,·eliminating·many 
56 ·················zIPL···········allocation,·add·init_on_alloc=1·to·/etc/kernel/cmdline.··································kinds·of·"uninitialized·heap 
57 ·························································································································memory"·flaws,·effectively 
58 ·························································································································preventing·data·leaks. 
59 ·························································································································The41 ·························································································································The
60 ·························································································································CONFIG_SHUFFLE_PAGE_ALLOCATOR42 ·························································································································CONFIG_SHUFFLE_PAGE_ALLOCATOR
61 ·························································································································config·option·is·primarily43 ·························································································································config·option·is·primarily
62 ·························································································································focused·on·improving·the44 ·························································································································focused·on·improving·the
63 ·························································································································average·utilization·of·a45 ·························································································································average·utilization·of·a
64 ·························································································································direct-mapped·memory-side-46 ·························································································································direct-mapped·memory-side-
65 ·························································································································cache.·Aside·of·this47 ·························································································································cache.·Aside·of·this
Offset 77, 14 lines modifiedOffset 59, 32 lines modified
77 ·························································································································applications·allocating59 ·························································································································applications·allocating
78 ·························································································································memory·ouf·of·that·node.·The60 ·························································································································memory·ouf·of·that·node.·The
79 ·························································································································page_alloc.shuffle=1·kernel61 ·························································································································page_alloc.shuffle=1·kernel
80 ·························································································································command·line·parameter·then62 ·························································································································command·line·parameter·then
81 ·························································································································forces·this·functionality63 ·························································································································forces·this·functionality
82 ·························································································································irrespectively·of·memory64 ·························································································································irrespectively·of·memory
83 ·························································································································cache·architecture.65 ·························································································································cache·architecture.
 66 ································To·configure·the·kernel·to·zero·out·memory·before·allocating·it,·add·the·init_on_alloc=1·When·the·kernel·configuration
 67 ································argument·to·the·default·GRUB·2·command·line.·To·ensure·that·init_on_alloc=1·is·added·as··option·init_on_alloc·is
 68 ·················Configure······a·kernel·command·line·argument·to·newly·installed·kernels,·add·init_on_alloc=1·to·the····enabled,·all·page·allocator
 69 ·················kernel·to·zero·default·Grub2·command·line·for·Linux·operating·systems.·Modify·the·line·within·/etc/·····and·slab·allocator·memory
 70 AVA_VAN.1········out·memory·····default/grub·as·shown·below:·····························································will·be·zeroed·when
 71 ·················before·········GRUB_CMDLINE_LINUX="...·init_on_alloc=1·..."·············································allocated,·eliminating·many
 72 ·················allocation·····Run·the·following·command·to·update·command·line·for·already·installed·kernels:··········kinds·of·"uninitialized·heap
 73 ································#·grubby·--update-kernel=ALL·--args="init_on_alloc=1"····································memory"·flaws,·effectively
 74 ·························································································································preventing·data·leaks.
 75 ·························································································································When·the·kernel·configuration
 76 ·················Configure·······························································································option·init_on_alloc·is
 77 ·················kernel·to·zero·To·ensure·that·the·kernel·is·configured·to·zero·out·memory·before·allocation,·check·that·enabled,·all·page·allocator
 78 ·················out·memory·····all·boot·entries·in·/boot/loader/entries/*.conf·have·init_on_alloc=1·included·in·its·····and·slab·allocator·memory
 79 AVA_VAN.1········before·········options.·················································································will·be·zeroed·when
 80 ·················allocation·in··To·ensure·that·new·kernels·and·boot·entries·continue·to·zero·out·memory·before···········allocated,·eliminating·many
 81 ·················zIPL···········allocation,·add·init_on_alloc=1·to·/etc/kernel/cmdline.··································kinds·of·"uninitialized·heap
 82 ·························································································································memory"·flaws,·effectively
 83 ·························································································································preventing·data·leaks.
84 ·························································································································The84 ·························································································································The
85 ·························································································································CONFIG_SHUFFLE_PAGE_ALLOCATOR85 ·························································································································CONFIG_SHUFFLE_PAGE_ALLOCATOR
86 ·························································································································config·option·is·primarily86 ·························································································································config·option·is·primarily
87 ·························································································································focused·on·improving·the87 ·························································································································focused·on·improving·the
88 ·························································································································average·utilization·of·a88 ·························································································································average·utilization·of·a
89 ·························································································································direct-mapped·memory-side-89 ·························································································································direct-mapped·memory-side-
90 ·························································································································cache.·Aside·of·this90 ·························································································································cache.·Aside·of·this
Offset 102, 36 lines modifiedOffset 102, 37 lines modified
102 ·························································································································applications·allocating102 ·························································································································applications·allocating
103 ·························································································································memory·ouf·of·that·node.·The103 ·························································································································memory·ouf·of·that·node.·The
104 ·························································································································page_alloc.shuffle=1·kernel104 ·························································································································page_alloc.shuffle=1·kernel
105 ·························································································································command·line·parameter·then105 ·························································································································command·line·parameter·then
106 ·························································································································forces·this·functionality106 ·························································································································forces·this·functionality
107 ·························································································································irrespectively·of·memory107 ·························································································································irrespectively·of·memory
108 ·························································································································cache·architecture.108 ·························································································································cache·architecture.
 109 ·························································································································Audit·data·should·be
 110 ································The·auditd·service·can·be·configured·to·synchronously·write·audit·event·data·to·disk.····synchronously·written·to·disk
 111 ·················Configure······Add·or·correct·the·following·line·in·/etc/audit/auditd.conf·to·ensure·that·audit·event···to·ensure·log·integrity.
 112 FAU_GEN.1········auditd·flush···data·is·fully·synchronized·with·the·log·files·on·the·disk:·······························These·parameters·assure·that
 113 ·················priority·······flush·=·data·············································································all·audit·event·data·is·fully
 114 ·························································································································synchronized·with·the·log
 115 ·························································································································files·on·the·disk.
 116 ·················Set·number·of···························································································If·option·freq·isn't·set·to·,
 117 ·················records·to·····To·configure·Audit·daemon·to·issue·an·explicit·flush·to·disk·command·after·writing·50····the·flush·to·disk·may·happen
 118 FAU_GEN.1········cause·an·······records,·set·freq·to·50·in·/etc/audit/auditd.conf.·······································after·higher·number·of
 119 ·················explicit·flush··························································································records,·increasing·the
 120 ·················to·audit·logs···························································································danger·of·audit·loss.
109 ·························································································································Each·process·on·the·system121 ·························································································································Each·process·on·the·system
110 ·························································································································carries·an·"auditable"·flag122 ·························································································································carries·an·"auditable"·flag
111 ·························································································································which·indicates·whether·its123 ·························································································································which·indicates·whether·its
112 ·················Enable·········To·ensure·all·processes·can·be·audited,·even·those·which·start·prior·to·the·audit········activities·can·be·audited.124 ·················Enable·········To·ensure·all·processes·can·be·audited,·even·those·which·start·prior·to·the·audit········activities·can·be·audited.
113 ·················Auditing·to····daemon,·check·that·all·boot·entries·in·/boot/loader/entries/*.conf·have·audit=1·included·Although·auditd·takes·care·of125 ·················Auditing·to····daemon,·check·that·all·boot·entries·in·/boot/loader/entries/*.conf·have·audit=1·included·Although·auditd·takes·care·of
114 FAU_GEN.1········Start·Prior·to·in·its·options.··········································································enabling·this·for·all126 FAU_GEN.1········Start·Prior·to·in·its·options.··········································································enabling·this·for·all
115 ·················the·Audit······To·ensure·that·new·kernels·and·boot·entries·continue·to·enable·audit,·add·audit=1·to·/···processes·which·launch·after127 ·················the·Audit······To·ensure·that·new·kernels·and·boot·entries·continue·to·enable·audit,·add·audit=1·to·/···processes·which·launch·after
116 ·················Daemon·in·zIPL·etc/kernel/cmdline.······································································it·does,·adding·the·kernel128 ·················Daemon·in·zIPL·etc/kernel/cmdline.······································································it·does,·adding·the·kernel
117 ·························································································································argument·ensures·it·is·set129 ·························································································································argument·ensures·it·is·set
118 ·························································································································for·every·process·during130 ·························································································································for·every·process·during
119 ·························································································································boot.131 ·························································································································boot.
120 ·························································································································Each·process·on·the·system 
121 ································To·ensure·all·processes·can·be·audited,·even·those·which·start·prior·to·the·audit········carries·an·"auditable"·flag 
122 ·················Enable·········daemon,·add·the·argument·audit=1·to·the·default·GRUB·2·command·line·for·the·Linux········which·indicates·whether·its 
123 ·················Auditing·for···operating·system.·To·ensure·that·audit=1·is·added·as·a·kernel·command·line·argument·to···activities·can·be·audited. 
Max diff block lines reached; 361151/380048 bytes (95.03%) of diff not shown.
796 KB
./usr/share/doc/ssg-nondebian/table-ol7-pcidssrefs.html
Ordering differences only
    
Offset 73, 28 lines modifiedOffset 73, 14 lines modified
73 is·the·only·place·that·loopback·network·traffic·should·be·seen,73 is·the·only·place·that·loopback·network·traffic·should·be·seen,
74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
75 anti-spoofing·measure.75 anti-spoofing·measure.
76 ······</td>76 ······</td>
77 ····</tr>77 ····</tr>
78 ····<tr>78 ····<tr>
79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
80 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td> 
81 ······<td·xml:lang="en-US"> 
82 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre> 
83 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre> 
84 ······</td> 
85 ······<td·xml:lang="en-US"> 
86 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange 
87 network·topology·information·with·other·routers.·If·this·capability·is·used·when 
88 not·required,·system·network·information·may·be·unnecessarily·transmitted·across 
89 the·network. 
90 ······</td> 
91 ····</tr> 
92 ····<tr> 
93 ······<td>Req-1.3.1<br/>Req-1.3.2</td> 
94 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>80 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>
95 ······<td·xml:lang="en-US">81 ······<td·xml:lang="en-US">
96 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,82 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,
97 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default83 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default
98 GRUB2·command·line·for·the·Linux·operating·system.84 GRUB2·command·line·for·the·Linux·operating·system.
99 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line85 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line
100 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the86 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the
Offset 105, 14 lines modifiedOffset 91, 28 lines modified
105 ······</td>91 ······</td>
106 ······<td·xml:lang="en-US">92 ······<td·xml:lang="en-US">
107 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce93 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce
108 the·vulnerability·to·exploitation.94 the·vulnerability·to·exploitation.
109 ······</td>95 ······</td>
110 ····</tr>96 ····</tr>
111 ····<tr>97 ····<tr>
 98 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
 99 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td>
 100 ······<td·xml:lang="en-US">
 101 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre>
 102 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre>
 103 ······</td>
 104 ······<td·xml:lang="en-US">
 105 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange
 106 network·topology·information·with·other·routers.·If·this·capability·is·used·when
 107 not·required,·system·network·information·may·be·unnecessarily·transmitted·across
 108 the·network.
 109 ······</td>
 110 ····</tr>
 111 ····<tr>
112 ······<td>Req-1.3.3</td>112 ······<td>Req-1.3.3</td>
113 ······<td>Deactivate·Wireless·Network·Interfaces</td>113 ······<td>Deactivate·Wireless·Network·Interfaces</td>
114 ······<td·xml:lang="en-US">114 ······<td·xml:lang="en-US">
115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless
116 capability.116 capability.
117 <br·/><br·/>117 <br·/><br·/>
  
Offset 157, 26 lines modifiedOffset 157, 26 lines modified
157 ······<td·xml:lang="en-US">157 ······<td·xml:lang="en-US">
158 ········Without·a·firewall·rule·configured·for·open·ports·default·firewall·policy·will·drop·all158 ········Without·a·firewall·rule·configured·for·open·ports·default·firewall·policy·will·drop·all
159 packets·to·these·ports.159 packets·to·these·ports.
160 ······</td>160 ······</td>
161 ····</tr>161 ····</tr>
162 ····<tr>162 ····<tr>
163 ······<td>Req-1.4.1</td>163 ······<td>Req-1.4.1</td>
164 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>164 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
165 ······<td·xml:lang="en-US">165 ······<td·xml:lang="en-US">
 166 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
 167 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
166 ········Configure·the·loopback·interface·to·accept·traffic. 
167 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback 
168 network. 
169 ······</td>168 ······</td>
170 ······<td·xml:lang="en-US">169 ······<td·xml:lang="en-US">
171 ········Loopback·traffic·is·generated·between·processes·on·machine·and·is 
172 typically·critical·to·operation·of·the·system.·The·loopback·interface 
173 is·the·only·place·that·loopback·network·traffic·should·be·seen, 
174 all·other·interfaces·should·ignore·traffic·on·this·network·as·an 
175 anti-spoofing·measure.170 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
 171 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state.
 172 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received,
 173 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
 174 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
 175 enables·the·system·to·continue·servicing·valid·connection·requests.
176 ······</td>176 ······</td>
177 ····</tr>177 ····</tr>
178 ····<tr>178 ····<tr>
179 ······<td>Req-1.4.1</td>179 ······<td>Req-1.4.1</td>
180 ······<td>Install·iptables·Package</td>180 ······<td>Install·iptables·Package</td>
181 ······<td·xml:lang="en-US">181 ······<td·xml:lang="en-US">
182 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command:182 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command:
Offset 187, 26 lines modifiedOffset 187, 26 lines modified
187 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering187 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
188 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP188 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
189 masquerading,·etc.189 masquerading,·etc.
190 ······</td>190 ······</td>
191 ····</tr>191 ····</tr>
192 ····<tr>192 ····<tr>
193 ······<td>Req-1.4.1</td>193 ······<td>Req-1.4.1</td>
194 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>194 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>
195 ······<td·xml:lang="en-US">195 ······<td·xml:lang="en-US">
196 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre> 
197 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>196 ········Configure·the·loopback·interface·to·accept·traffic.
 197 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback
 198 network.
198 ······</td>199 ······</td>
199 ······<td·xml:lang="en-US">200 ······<td·xml:lang="en-US">
 201 ········Loopback·traffic·is·generated·between·processes·on·machine·and·is
 202 typically·critical·to·operation·of·the·system.·The·loopback·interface
 203 is·the·only·place·that·loopback·network·traffic·should·be·seen,
 204 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
 205 anti-spoofing·measure.
200 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a 
201 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state. 
202 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received, 
203 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood 
204 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and 
205 enables·the·system·to·continue·servicing·valid·connection·requests. 
206 ······</td>206 ······</td>
207 ····</tr>207 ····</tr>
208 ····<tr>208 ····<tr>
209 ······<td>Req-1.4.2</td>209 ······<td>Req-1.4.2</td>
210 ······<td>Disable·SCTP·Support</td>210 ······<td>Disable·SCTP·Support</td>
211 ······<td·xml:lang="en-US">211 ······<td·xml:lang="en-US">
212 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a212 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
Offset 246, 41 lines modifiedOffset 246, 22 lines modified
246 ······<td·xml:lang="en-US">246 ······<td·xml:lang="en-US">
Max diff block lines reached; 300271/306853 bytes (97.85%) of diff not shown.
496 KB
html2text {}
Max HTML report size reached
3.53 MB
./usr/share/doc/ssg-nondebian/table-ol8-anssirefs.html
    
Offset 63, 273 lines modifiedOffset 63, 273 lines modified
000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····000003e0:·2054·6974·6c65·3c2f·7468·3e0a·2020·2020···Title</th>.····
000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<000003f0:·3c74·683e·4465·7363·7269·7074·696f·6e3c··<th>Description<
00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat00000400:·2f74·683e·0a20·2020·203c·7468·3e52·6174··/th>.····<th>Rat
00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</00000410:·696f·6e61·6c65·3c2f·7468·3e0a·2020·3c2f··ionale</th>.··</
00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>00000420:·7468·6561·643e·0a20·203c·7462·6f64·793e··thead>.··<tbody>
00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t00000430:·0a20·203c·7472·3e0a·2020·2020·2020·3c74··.··<tr>.······<t
00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······00000440:·643e·5231·3c2f·7464·3e0a·2020·2020·2020··d>R1</td>.······
 00000450:·3c74·643e·456e·7375·7265·2053·4d41·5020··<td>Ensure·SMAP·
 00000460:·6973·206e·6f74·2064·6973·6162·6c65·6420··is·not·disabled·
 00000470:·6475·7269·6e67·2062·6f6f·743c·2f74·643e··during·boot</td>
00000450:·3c74·643e·496e·7374·616c·6c20·5041·4520··<td>Install·PAE· 
00000460:·4b65·726e·656c·206f·6e20·5375·7070·6f72··Kernel·on·Suppor 
00000470:·7465·6420·3332·2d62·6974·2078·3836·2053··ted·32-bit·x86·S 
00000480:·7973·7465·6d73·3c2f·7464·3e0a·2020·2020··ystems</td>.···· 
00000490:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang=" 
000004a0:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········ 
000004b0:·5379·7374·656d·7320·7468·6174·2061·7265··Systems·that·are 
000004c0:·2075·7369·6e67·2074·6865·2036·342d·6269···using·the·64-bi 
000004d0:·7420·7838·3620·6b65·726e·656c·2070·6163··t·x86·kernel·pac 
000004e0:·6b61·6765·0a64·6f20·6e6f·7420·6e65·6564··kage.do·not·need 
000004f0:·2074·6f20·696e·7374·616c·6c20·7468·6520···to·install·the· 
00000500:·6b65·726e·656c·2d50·4145·2070·6163·6b61··kernel-PAE·packa 
00000510:·6765·2062·6563·6175·7365·2074·6865·2036··ge·because·the·6 
00000520:·342d·6269·740a·7838·3620·6b65·726e·656c··4-bit.x86·kernel 
00000530:·2061·6c72·6561·6479·2069·6e63·6c75·6465···already·include 
00000540:·7320·7468·6973·2073·7570·706f·7274·2e20··s·this·support.· 
00000550:·486f·7765·7665·722c·2069·6620·7468·6520··However,·if·the· 
00000560:·7379·7374·656d·2069·730a·3332·2d62·6974··system·is.32-bit 
00000570:·2061·6e64·2061·6c73·6f20·7375·7070·6f72···and·also·suppor 
00000580:·7473·2074·6865·2050·4145·2061·6e64·204e··ts·the·PAE·and·N 
00000590:·5820·6665·6174·7572·6573·2061·730a·6465··X·features·as.de 
000005a0:·7465·726d·696e·6564·2069·6e20·7468·6520··termined·in·the· 
000005b0:·7072·6576·696f·7573·2073·6563·7469·6f6e··previous·section 
000005c0:·2c20·7468·6520·6b65·726e·656c·2d50·4145··,·the·kernel-PAE 
000005d0:·2070·6163·6b61·6765·2073·686f·756c·640a···package·should. 
000005e0:·6265·2069·6e73·7461·6c6c·6564·2074·6f20··be·installed·to· 
000005f0:·656e·6162·6c65·2058·4420·6f72·204e·5820··enable·XD·or·NX· 
00000600:·7375·7070·6f72·742e·0a54·6865·203c·636f··support..The·<co 
00000610:·6465·3e6b·6572·6e65·6c2d·5041·453c·2f63··de>kernel-PAE</c 
00000620:·6f64·653e·2070·6163·6b61·6765·2063·616e··ode>·package·can 
00000630:·2062·6520·696e·7374·616c·6c65·6420·7769···be·installed·wi 
00000640:·7468·2074·6865·2066·6f6c·6c6f·7769·6e67··th·the·following 
00000650:·2063·6f6d·6d61·6e64·3a0a·3c70·7265·3e0a···command:.<pre>. 
00000660:·2420·7375·646f·2079·756d·2069·6e73·7461··$·sudo·yum·insta 
00000670:·6c6c·206b·6572·6e65·6c2d·5041·453c·2f70··ll·kernel-PAE</p 
00000680:·7265·3e0a·5468·6520·696e·7374·616c·6c61··re>.The·installa 
00000690:·7469·6f6e·2070·726f·6365·7373·2073·686f··tion·process·sho 
000006a0:·756c·6420·616c·736f·2068·6176·6520·636f··uld·also·have·co 
000006b0:·6e66·6967·7572·6564·2074·6865·0a62·6f6f··nfigured·the.boo 
000006c0:·746c·6f61·6465·7220·746f·206c·6f61·6420··tloader·to·load· 
000006d0:·7468·6520·6e65·7720·6b65·726e·656c·2061··the·new·kernel·a 
000006e0:·7420·626f·6f74·2e20·5665·7269·6679·2074··t·boot.·Verify·t 
000006f0:·6869·7320·6166·7465·7220·7265·626f·6f74··his·after·reboot 
00000700:·0a61·6e64·206d·6f64·6966·7920·3c74·743e··.and·modify·<tt> 
00000710:·2f65·7463·2f64·6566·6175·6c74·2f67·7275··/etc/default/gru 
00000720:·623c·2f74·743e·2069·6620·6e65·6365·7373··b</tt>·if·necess 
00000730:·6172·792e·0a20·2020·2020·203c·2f74·643e··ary..······</td> 
00000740:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l00000480:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l
00000750:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···00000490:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···
00000760:·2020·2020·204f·6e20·3332·2d62·6974·2073·······On·32-bit·s 
00000770:·7973·7465·6d73·2074·6861·7420·7375·7070··ystems·that·supp 
00000780:·6f72·7420·7468·6520·5844·206f·7220·4e58··ort·the·XD·or·NX 
00000790:·2062·6974·2c20·7468·6520·7665·6e64·6f72···bit,·the·vendor 
000007a0:·2d73·7570·706c·6965·640a·5041·4520·6b65··-supplied.PAE·ke 
000007b0:·726e·656c·2069·7320·7265·7175·6972·6564··rnel·is·required 
000007c0:·2074·6f20·656e·6162·6c65·2065·6974·6865···to·enable·eithe 
000007d0:·7220·4578·6563·7574·6520·4469·7361·626c··r·Execute·Disabl 
000007e0:·6520·2858·4429·206f·7220·4e6f·2045·7865··e·(XD)·or·No·Exe 
000007f0:·6375·7465·2028·4e58·2920·7375·7070·6f72··cute·(NX)·suppor 
00000800:·742e·0a20·2020·2020·203c·2f74·643e·0a20··t..······</td>.· 
00000810:·2020·203c·2f74·723e·0a20·2020·203c·7472·····</tr>.····<tr 
00000820:·3e0a·2020·2020·2020·3c74·643e·5231·3c2f··>.······<td>R1</ 
00000830:·7464·3e0a·2020·2020·2020·3c74·643e·5072··td>.······<td>Pr 
00000840:·6566·6572·2074·6f20·7573·6520·6120·3634··efer·to·use·a·64 
00000850:·2d62·6974·204f·7065·7261·7469·6e67·2053··-bit·Operating·S 
00000860:·7973·7465·6d20·7768·656e·2073·7570·706f··ystem·when·suppo 
00000870:·7274·6564·3c2f·7464·3e0a·2020·2020·2020··rted</td>.······ 
00000880:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en 
00000890:·2d55·5322·3e0a·2020·2020·2020·2020·5072··-US">.········Pr 
000008a0:·6566·6572·2069·6e73·7461·6c6c·6174·696f··efer·installatio 
000008b0:·6e20·6f66·2036·342d·6269·7420·6f70·6572··n·of·64-bit·oper 
000008c0:·6174·696e·6720·7379·7374·656d·7320·7768··ating·systems·wh 
000008d0:·656e·2074·6865·2043·5055·2073·7570·706f··en·the·CPU·suppo 
000008e0:·7274·7320·6974·2e0a·2020·2020·2020·3c2f··rts·it..······</ 
000008f0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm 
00000900:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">. 
00000910:·2020·2020·2020·2020·5573·6520·6f66·2061··········Use·of·a 
00000920:·2036·342d·6269·7420·6f70·6572·6174·696e···64-bit·operatin 
00000930:·6720·7379·7374·656d·206f·6666·6572·7320··g·system·offers· 
00000940:·6120·6665·7720·6164·7661·6e74·6167·6573··a·few·advantages 
00000950:·2c20·6c69·6b65·2061·206c·6172·6765·7220··,·like·a·larger· 
00000960:·6164·6472·6573·7320·7370·6163·6520·7261··address·space·ra 
00000970:·6e67·6520·666f·720a·4164·6472·6573·7320··nge·for.Address· 
00000980:·5370·6163·6520·4c61·796f·7574·2052·616e··Space·Layout·Ran 
00000990:·646f·6d69·7a61·7469·6f6e·2028·4153·4c52··domization·(ASLR 
000009a0:·2920·616e·6420·7379·7374·656d·6174·6963··)·and·systematic 
000009b0:·2070·7265·7365·6e63·6520·6f66·204e·6f20···presence·of·No· 
000009c0:·6558·6563·7574·6520·616e·6420·4578·6563··eXecute·and·Exec 
000009d0:·7574·6520·4469·7361·626c·6520·284e·582f··ute·Disable·(NX/ 
000009e0:·5844·2920·7072·6f74·6563·7469·6f6e·2062··XD)·protection·b 
000009f0:·6974·732e·0a20·2020·2020·203c·2f74·643e··its..······</td> 
00000a00:·0a20·2020·203c·2f74·723e·0a20·2020·203c··.····</tr>.····< 
00000a10:·7472·3e0a·2020·2020·2020·3c74·643e·5231··tr>.······<td>R1 
00000a20:·3c2f·7464·3e0a·2020·2020·2020·3c74·643e··</td>.······<td> 
00000a30:·456e·7375·7265·2053·4d45·5020·6973·206e··Ensure·SMEP·is·n 
00000a40:·6f74·2064·6973·6162·6c65·6420·6475·7269··ot·disabled·duri 
00000a50:·6e67·2062·6f6f·743c·2f74·643e·0a20·2020··ng·boot</td>.··· 
00000a60:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang= 
00000a70:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.······· 
00000a80:·2054·6865·2053·4d45·5020·6973·2075·7365···The·SMEP·is·use000004a0:·2020·2020·2054·6865·2053·4d41·5020·6973·······The·SMAP·is
00000a90:·6420·746f·2070·7265·7665·6e74·2074·6865··d·to·prevent·the000004b0:·2075·7365·6420·746f·2070·7265·7665·6e74···used·to·prevent
00000aa0:·2073·7570·6572·7669·736f·7220·6d6f·6465···supervisor·mode000004c0:·2074·6865·2073·7570·6572·7669·736f·7220···the·supervisor·
00000ab0:·2066·726f·6d20·6578·6563·7574·696e·6720···from·executing· 
00000ac0:·7573·6572·2073·7061·6365·2063·6f64·652c··user·space·code,000004d0:·6d6f·6465·2066·726f·6d20·756e·696e·7465··mode·from·uninte
 000004e0:·6e74·696f·6e61·6c6c·7920·7265·6164·696e··ntionally·readin
 000004f0:·672f·7772·6974·696e·6720·696e·746f·0a6d··g/writing·into.m
 00000500:·656d·6f72·7920·7061·6765·7320·696e·2074··emory·pages·in·t
 00000510:·6865·2075·7365·7220·7370·6163·652c·2069··he·user·space,·i
00000ad0:·0a69·7420·6973·2065·6e61·626c·6564·2062··.it·is·enabled·b00000520:·7420·6973·2065·6e61·626c·6564·2062·7920··t·is·enabled·by·
00000ae0:·7920·6465·6661·756c·7420·7369·6e63·6520··y·default·since·00000530:·6465·6661·756c·7420·7369·6e63·6520·4c69··default·since·Li
00000af0:·4c69·6e75·7820·6b65·726e·656c·2033·2e30··Linux·kernel·3.000000540:·6e75·7820·6b65·726e·656c·2033·2e37·2e0a··nux·kernel·3.7..
00000b00:·2e20·4275·7420·6974·2063·6f75·6c64·2062··.·But·it·could·b00000550:·4275·7420·6974·2063·6f75·6c64·2062·6520··But·it·could·be·
00000b10:·6520·6469·7361·626c·6564·2074·6872·6f75··e·disabled·throu00000560:·6469·7361·626c·6564·2074·6872·6f75·6768··disabled·through
00000b20:·6768·0a6b·6572·6e65·6c20·626f·6f74·2070··gh.kernel·boot·p00000570:·206b·6572·6e65·6c20·626f·6f74·2070·6172···kernel·boot·par
00000b30:·6172·616d·6574·6572·732e·0a0a·456e·7375··arameters...Ensu00000580:·616d·6574·6572·732e·0a0a·456e·7375·7265··ameters...Ensure
00000b40:·7265·2074·6861·7420·5375·7065·7276·6973··re·that·Supervis00000590:·2074·6861·7420·5375·7065·7276·6973·6f72···that·Supervisor
00000b50:·6f72·204d·6f64·6520·4578·6563·7574·696f··or·Mode·Executio 
Max diff block lines reached; 2977300/3013616 bytes (98.79%) of diff not shown.
670 KB
html2text {}
Max HTML report size reached
1.26 MB
./usr/share/doc/ssg-nondebian/table-ol8-cuirefs.html
Ordering differences only
    
Offset 41, 78 lines modifiedOffset 41, 30 lines modified
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td>47 ······<td>3.1.1<br/>3.1.5</td>
 48 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td>
48 ······<td>Verify·Only·Root·Has·UID·0</td> 
49 ······<td·xml:lang="en-US"> 
50 ········If·any·account·other·than·root·has·a·UID·of·0,·this·misconfiguration·should 
51 be·investigated·and·the·accounts·other·than·root·should·be·removed·or·have 
52 their·UID·changed. 
53 <br·/> 
54 If·the·account·is·associated·with·system·commands·or·applications·the·UID 
55 should·be·changed·to·one·greater·than·"0"·but·less·than·"1000." 
56 Otherwise·assign·a·UID·greater·than·"1000"·that·has·not·already·been 
57 assigned. 
58 ······</td> 
59 ······<td·xml:lang="en-US"> 
60 ········An·account·has·root·authority·if·it·has·a·UID·of·0.·Multiple·accounts 
61 with·a·UID·of·0·afford·more·opportunity·for·potential·intruders·to 
62 guess·a·password·for·a·privileged·account.·Proper·configuration·of 
63 sudo·is·recommended·to·afford·multiple·system·administrators 
64 access·to·root·privileges·in·an·accountable·manner. 
65 ······</td> 
66 ····</tr> 
67 ····<tr> 
68 ······<td>3.1.1<br/>3.1.6</td> 
69 ······<td>Direct·root·Logins·Not·Allowed</td> 
70 ······<td·xml:lang="en-US"> 
71 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators 
72 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file. 
73 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does 
74 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the 
75 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous 
76 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in 
77 plain·text·over·the·network.·By·default,·Oracle·Linux·8's 
78 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console 
79 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the 
80 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this 
81 file·by·typing·the·following·command: 
82 <pre> 
83 $·sudo·echo·&gt;·/etc/securetty 
84 </pre> 
85 ······</td> 
86 ······<td·xml:lang="en-US"> 
87 ········Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor 
88 authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate 
89 to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low 
90 and·FISMA·Moderate·systems. 
91 ······</td> 
92 ····</tr> 
93 ····<tr> 
94 ······<td>3.1.1<br/>3.1.5</td> 
95 ······<td>Disable·SSH·Root·Login</td> 
96 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
97 ········The·root·user·should·never·be·allowed·to·login·to·a 
98 system·directly·over·a·network. 
99 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
 50 ········If·an·account·is·configured·for·password·authentication
 51 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log
 52 into·the·account·without·authentication.·Remove·any·instances·of·the
 53 <tt>nullok</tt>·in
  
100 <tt>/etc/ssh/sshd_config</tt>:54 <tt>/etc/pam.d/system-auth</tt>·and
 55 <tt>/etc/pam.d/password-auth</tt>
  
101 <pre>PermitRootLogin·no</pre>56 to·prevent·logins·with·empty·passwords.
102 ······</td>57 ······</td>
103 ······<td·xml:lang="en-US">58 ······<td·xml:lang="en-US">
 59 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and
 60 run·commands·with·the·privileges·of·that·account.·Accounts·with
 61 empty·passwords·should·never·be·used·in·operational·environments.
104 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
105 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
106 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
107 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
108 direct·attack·attempts·on·root's·password. 
109 ······</td>62 ······</td>
110 ····</tr>63 ····</tr>
111 ····<tr>64 ····<tr>
112 ······<td>3.1.1</td>65 ······<td>3.1.1</td>
113 ······<td>Disable·GDM·Automatic·Login</td>66 ······<td>Disable·GDM·Automatic·Login</td>
114 ······<td·xml:lang="en-US">67 ······<td·xml:lang="en-US">
115 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without68 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without
Offset 125, 63 lines modifiedOffset 77, 28 lines modified
125 ······</td>77 ······</td>
126 ······<td·xml:lang="en-US">78 ······<td·xml:lang="en-US">
127 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating79 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
128 system·security.80 system·security.
129 ······</td>81 ······</td>
130 ····</tr>82 ····</tr>
131 ····<tr>83 ····<tr>
132 ······<td>3.1.1<br/>3.1.5</td>84 ······<td>3.1.1<br/>3.4.5</td>
 85 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td>
133 ······<td>Restrict·Virtual·Console·Root·Logins</td> 
134 ······<td·xml:lang="en-US"> 
135 ········To·restrict·root·logins·through·the·(deprecated)·virtual·console·devices, 
136 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
137 <pre>vc/1 
138 vc/2 
139 vc/3 
140 vc/4</pre> 
141 ······</td> 
142 ······<td·xml:lang="en-US"> 
143 ········Preventing·direct·root·login·to·virtual·console·devices 
144 helps·ensure·accountability·for·actions·taken·on·the·system 
145 using·the·root·account. 
146 ······</td> 
147 ····</tr> 
148 ····<tr> 
149 ······<td>3.1.1<br/>3.1.5</td> 
150 ······<td>Restrict·Serial·Port·Root·Logins</td> 
151 ······<td·xml:lang="en-US"> 
152 ········To·restrict·root·logins·on·serial·ports, 
153 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
154 <pre>ttyS0 
155 ttyS1</pre> 
156 ······</td> 
157 ······<td·xml:lang="en-US"> 
158 ········Preventing·direct·root·login·to·serial·port·interfaces 
159 helps·ensure·accountability·for·actions·taken·on·the·systems 
160 using·the·root·account. 
161 ······</td> 
162 ····</tr> 
163 ····<tr> 
Max diff block lines reached; 463060/468436 bytes (98.85%) of diff not shown.
828 KB
html2text {}
Max HTML report size reached
3.21 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-ospp.html
    
Offset 4133, 15 lines modifiedOffset 4133, 15 lines modified
4133 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>4133 <pre>RekeyLimit·<tt>1G</tt>·<tt>1hour</tt></pre>
4134 ··</td>4134 ··</td>
4135 ··<td·xml:lang="en-US">4135 ··<td·xml:lang="en-US">
4136 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling4136 By·decreasing·the·limit·based·on·the·amount·of·data·and·enabling
4137 time-based·limit,·effects·of·potential·attacks·against4137 time-based·limit,·effects·of·potential·attacks·against
4138 encryption·keys·are·limited.4138 encryption·keys·are·limited.
4139 ··</td>4139 ··</td>
4140 ··<td>var_rekey_limit_time=1hour<br/>var_rekey_limit_size=1G</td>4140 ··<td>var_rekey_limit_size=1G<br/>var_rekey_limit_time=1hour</td>
4141 </tr>4141 </tr>
4142 <tr>4142 <tr>
4143 ··<td></td>4143 ··<td></td>
4144 ··<td>N/A</td>4144 ··<td>N/A</td>
4145 ··<td>SSH·server·uses·strong·entropy·to·seed</td>4145 ··<td>SSH·server·uses·strong·entropy·to·seed</td>
4146 ··<td·xml:lang="en-US">4146 ··<td·xml:lang="en-US">
4147 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.4147 To·set·up·SSH·server·to·use·entropy·from·a·high-quality·source,·edit·the·<tt>/etc/sysconfig/sshd</tt>·file.
2.48 KB
html2text {}
    
Offset 3401, 16 lines modifiedOffset 3401, 16 lines modified
3401 ··················································································································generator·used·by3401 ··················································································································generator·used·by
3402 ··················································································································SSH·would·be·known3402 ··················································································································SSH·would·be·known
3403 ··················································································································to·potential3403 ··················································································································to·potential
3404 ··················································································································attackers.3404 ··················································································································attackers.
3405 ··················································································································By·decreasing·the3405 ··················································································································By·decreasing·the
3406 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the3406 ·························The·RekeyLimit·parameter·specifies·how·often·the·session·key·of·the·is·renegotiated,·····limit·based·on·the
3407 ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and3407 ········Force·frequent···both·in·terms·of·amount·of·data·that·may·be·transmitted·and·the·time·elapsed.············amount·of·data·and
3408 ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_time=1hour3408 ·····N/·session·key······To·decrease·the·default·limits,·add·or·correct·the·following·line·in·/etc/ssh/···········enabling·time-based·var_rekey_limit_size=1G
3409 ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_size=1G3409 ·····A··renegotiation····sshd_config:·············································································limit,·effects·of···var_rekey_limit_time=1hour
3410 ·························RekeyLimit·1G·1hour······································································potential·attacks3410 ·························RekeyLimit·1G·1hour······································································potential·attacks
3411 ··················································································································against·encryption3411 ··················································································································against·encryption
3412 ··················································································································keys·are·limited.3412 ··················································································································keys·are·limited.
3413 ··················································································································SSH·implementation3413 ··················································································································SSH·implementation
3414 ··················································································································in·Oracle·Linux·83414 ··················································································································in·Oracle·Linux·8
3415 ··················································································································uses·the·openssl3415 ··················································································································uses·the·openssl
3416 ··················································································································library,·which3416 ··················································································································library,·which
3.49 KB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs-stig.html
    
Offset 24427, 17 lines modifiedOffset 24427, 17 lines modified
0005f6a0:·6e67·0a74·696d·652d·6261·7365·6420·6c69··ng.time-based·li0005f6a0:·6e67·0a74·696d·652d·6261·7365·6420·6c69··ng.time-based·li
0005f6b0:·6d69·742c·2065·6666·6563·7473·206f·6620··mit,·effects·of·0005f6b0:·6d69·742c·2065·6666·6563·7473·206f·6620··mit,·effects·of·
0005f6c0:·706f·7465·6e74·6961·6c20·6174·7461·636b··potential·attack0005f6c0:·706f·7465·6e74·6961·6c20·6174·7461·636b··potential·attack
0005f6d0:·7320·6167·6169·6e73·740a·656e·6372·7970··s·against.encryp0005f6d0:·7320·6167·6169·6e73·740a·656e·6372·7970··s·against.encryp
0005f6e0:·7469·6f6e·206b·6579·7320·6172·6520·6c69··tion·keys·are·li0005f6e0:·7469·6f6e·206b·6579·7320·6172·6520·6c69··tion·keys·are·li
0005f6f0:·6d69·7465·642e·0a20·203c·2f74·643e·0a20··mited..··</td>.·0005f6f0:·6d69·7465·642e·0a20·203c·2f74·643e·0a20··mited..··</td>.·
0005f700:·203c·7464·3e76·6172·5f72·656b·6579·5f6c···<td>var_rekey_l0005f700:·203c·7464·3e76·6172·5f72·656b·6579·5f6c···<td>var_rekey_l
0005f710:·696d·6974·5f73·697a·653d·3147·3c62·722f··imit_size=1G<br/ 
0005f720:·3e76·6172·5f72·656b·6579·5f6c·696d·6974··>var_rekey_limit 
0005f730:·5f74·696d·653d·3168·6f75·723c·2f74·643e··_time=1hour</td>0005f710:·696d·6974·5f74·696d·653d·3168·6f75·723c··imit_time=1hour<
 0005f720:·6272·2f3e·7661·725f·7265·6b65·795f·6c69··br/>var_rekey_li
 0005f730:·6d69·745f·7369·7a65·3d31·473c·2f74·643e··mit_size=1G</td>
0005f740:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t0005f740:·0a3c·2f74·723e·0a3c·7472·3e0a·2020·3c74··.</tr>.<tr>.··<t
0005f750:·643e·3c2f·7464·3e0a·2020·3c74·643e·4e2f··d></td>.··<td>N/0005f750:·643e·3c2f·7464·3e0a·2020·3c74·643e·4e2f··d></td>.··<td>N/
0005f760:·413c·2f74·643e·0a20·203c·7464·3e53·5348··A</td>.··<td>SSH0005f760:·413c·2f74·643e·0a20·203c·7464·3e53·5348··A</td>.··<td>SSH
0005f770:·2073·6572·7665·7220·7573·6573·2073·7472···server·uses·str0005f770:·2073·6572·7665·7220·7573·6573·2073·7472···server·uses·str
0005f780:·6f6e·6720·656e·7472·6f70·7920·746f·2073··ong·entropy·to·s0005f780:·6f6e·6720·656e·7472·6f70·7920·746f·2073··ong·entropy·to·s
0005f790:·6565·643c·2f74·643e·0a20·203c·7464·2078··eed</td>.··<td·x0005f790:·6565·643c·2f74·643e·0a20·203c·7464·2078··eed</td>.··<td·x
0005f7a0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">0005f7a0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
2.0 KB
html2text {}
    
Offset 7774, 16 lines modifiedOffset 7774, 16 lines modified
7774 ·································private·key.··········································system·where·the7774 ·································private·key.··········································system·where·the
7775 ·······················································································associated·public7775 ·······················································································associated·public
7776 ·······················································································key·has·been7776 ·······················································································key·has·been
7777 ·······················································································installed.7777 ·······················································································installed.
7778 ·································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the7778 ·································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the
7779 ·································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the7779 ·································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the
7780 ···········Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and7780 ···········Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and
7781 ········N/·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_size=1G7781 ········N/·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_time=1hour
7782 ········A··renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_time=1hour7782 ········A··renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_size=1G
7783 ·································following·line·in·/etc/ssh/sshd_config:···············potential·attacks7783 ·································following·line·in·/etc/ssh/sshd_config:···············potential·attacks
7784 ·································RekeyLimit·1G·1hour···································against·encryption7784 ·································RekeyLimit·1G·1hour···································against·encryption
7785 ·······················································································keys·are·limited.7785 ·······················································································keys·are·limited.
7786 ·······················································································SSH·implementation7786 ·······················································································SSH·implementation
7787 ·······················································································in·Oracle·Linux·87787 ·······················································································in·Oracle·Linux·8
7788 ·······················································································uses·the·openssl7788 ·······················································································uses·the·openssl
7789 ·······················································································library,·which7789 ·······················································································library,·which
9.65 MB
./usr/share/doc/ssg-nondebian/table-ol8-nistrefs.html
    
Offset 64, 14948 lines modifiedOffset 64, 14948 lines modified
000003f0:·6c65·3c2f·7468·3e0a·2020·2020·3c74·683e··le</th>.····<th>000003f0:·6c65·3c2f·7468·3e0a·2020·2020·3c74·683e··le</th>.····<th>
00000400:·4465·7363·7269·7074·696f·6e3c·2f74·683e··Description</th>00000400:·4465·7363·7269·7074·696f·6e3c·2f74·683e··Description</th>
00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa00000410:·0a20·2020·203c·7468·3e52·6174·696f·6e61··.····<th>Rationa
00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea00000420:·6c65·3c2f·7468·3e0a·2020·3c2f·7468·6561··le</th>.··</thea
00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<00000430:·643e·0a20·203c·7462·6f64·793e·0a20·203c··d>.··<tbody>.··<
00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU00000440:·7472·3e0a·2020·2020·2020·3c74·643e·4155··tr>.······<td>AU
Diff chunk too large, falling back to line-by-line diff (14934 lines added, 14934 lines removed)
00000450:·2d32·2864·293c·6272·2f3e·4155·2d31·3228··-2(d)<br/>AU-12(00000450:·2d32·2864·293c·6272·2f3e·4155·2d31·3228··-2(d)<br/>AU-12(
00000460:·6329·3c62·722f·3e43·4d2d·3628·6129·3c2f··c)<br/>CM-6(a)</00000460:·6329·3c62·722f·3e41·432d·3628·3929·3c62··c)<br/>AC-6(9)<b
00000470:·7464·3e0a·2020·2020·2020·3c74·643e·5265··td>.······<td>Re00000470:·722f·3e43·4d2d·3628·6129·3c2f·7464·3e0a··r/>CM-6(a)</td>.
00000480:·636f·7264·2045·7665·6e74·7320·7468·6174··cord·Events·that00000480:·2020·2020·2020·3c74·643e·456e·7375·7265········<td>Ensure
00000490:·204d·6f64·6966·7920·7468·6520·5379·7374···Modify·the·Syst00000490:·2061·7564·6974·6420·436f·6c6c·6563·7473···auditd·Collects
000004a0:·656d·2773·2044·6973·6372·6574·696f·6e61··em's·Discretiona000004a0:·2049·6e66·6f72·6d61·7469·6f6e·206f·6e20···Information·on·
000004b0:·7279·2041·6363·6573·7320·436f·6e74·726f··ry·Access·Contro000004b0:·7468·6520·5573·6520·6f66·2050·7269·7669··the·Use·of·Privi
000004c0:·6c73·202d·2063·686d·6f64·3c2f·7464·3e0a··ls·-·chmod</td>.000004c0:·6c65·6765·6420·436f·6d6d·616e·6473·202d··leged·Commands·-
000004d0:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la000004d0:·2075·6d6f·756e·743c·2f74·643e·0a20·2020···umount</td>.···
000004e0:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.····000004e0:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=
000004f0:·2020·2020·4174·2061·206d·696e·696d·756d······At·a·minimum000004f0:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······
00000500:·2c20·7468·6520·6175·6469·7420·7379·7374··,·the·audit·syst00000500:·2041·7420·6120·6d69·6e69·6d75·6d2c·2074···At·a·minimum,·t
00000510:·656d·2073·686f·756c·6420·636f·6c6c·6563··em·should·collec00000510:·6865·2061·7564·6974·2073·7973·7465·6d20··he·audit·system·
00000520:·7420·6669·6c65·2070·6572·6d69·7373·696f··t·file·permissio00000520:·7368·6f75·6c64·2063·6f6c·6c65·6374·2074··should·collect·t
00000530:·6e0a·6368·616e·6765·7320·666f·7220·616c··n.changes·for·al00000530:·6865·2065·7865·6375·7469·6f6e·206f·660a··he·execution·of.
00000540:·6c20·7573·6572·7320·616e·6420·726f·6f74··l·users·and·root00000540:·7072·6976·696c·6567·6564·2063·6f6d·6d61··privileged·comma
00000550:·2e20·4966·2074·6865·203c·7474·3e61·7564··.·If·the·<tt>aud00000550:·6e64·7320·666f·7220·616c·6c20·7573·6572··nds·for·all·user
00000560:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·00000560:·7320·616e·6420·726f·6f74·2e20·4966·2074··s·and·root.·If·t
00000570:·6973·2063·6f6e·6669·6775·7265·6420·746f··is·configured·to00000570:·6865·203c·7474·3e61·7564·6974·643c·2f74··he·<tt>auditd</t
00000580:·0a75·7365·2074·6865·203c·7474·3e61·7567··.use·the·<tt>aug00000580:·743e·2064·6165·6d6f·6e20·6973·0a63·6f6e··t>·daemon·is.con
00000590:·656e·7275·6c65·733c·2f74·743e·2070·726f··enrules</tt>·pro00000590:·6669·6775·7265·6420·746f·2075·7365·2074··figured·to·use·t
000005a0:·6772·616d·2074·6f20·7265·6164·2061·7564··gram·to·read·aud000005a0:·6865·203c·7474·3e61·7567·656e·7275·6c65··he·<tt>augenrule
000005b0:·6974·2072·756c·6573·2064·7572·696e·6720··it·rules·during·000005b0:·733c·2f74·743e·2070·726f·6772·616d·2074··s</tt>·program·t
000005c0:·6461·656d·6f6e·2073·7461·7274·7570·0a28··daemon·startup.(000005c0:·6f20·7265·6164·2061·7564·6974·2072·756c··o·read·audit·rul
000005d0:·7468·6520·6465·6661·756c·7429·2c20·6164··the·default),·ad000005d0:·6573·2064·7572·696e·670a·6461·656d·6f6e··es·during.daemon
000005e0:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·000005e0:·2073·7461·7274·7570·2028·7468·6520·6465···startup·(the·de
000005f0:·6c69·6e65·2074·6f20·6120·6669·6c65·2077··line·to·a·file·w000005f0:·6661·756c·7429·2c20·6164·6420·6120·6c69··fault),·add·a·li
00000600:·6974·6820·7375·6666·6978·203c·7474·3e2e··ith·suffix·<tt>.00000600:·6e65·206f·6620·7468·6520·666f·6c6c·6f77··ne·of·the·follow
00000610:·7275·6c65·733c·2f74·743e·2069·6e0a·7468··rules</tt>·in.th00000610:·696e·6720·666f·726d·2074·6f20·6120·6669··ing·form·to·a·fi
00000620:·6520·6469·7265·6374·6f72·7920·3c74·743e··e·directory·<tt>00000620:·6c65·2077·6974·680a·7375·6666·6978·203c··le·with.suffix·<
00000630:·2f65·7463·2f61·7564·6974·2f72·756c·6573··/etc/audit/rules00000630:·7474·3e2e·7275·6c65·733c·2f74·743e·2069··tt>.rules</tt>·i
00000640:·2e64·3c2f·7474·3e3a·0a3c·7072·653e·2d61··.d</tt>:.<pre>-a00000640:·6e20·7468·6520·6469·7265·6374·6f72·7920··n·the·directory·
00000650:·2061·6c77·6179·732c·6578·6974·202d·4620···always,exit·-F·00000650:·3c74·743e·2f65·7463·2f61·7564·6974·2f72··<tt>/etc/audit/r
00000660:·6172·6368·3d62·3332·202d·5320·6368·6d6f··arch=b32·-S·chmo00000660:·756c·6573·2e64·3c2f·7474·3e3a·0a3c·7072··ules.d</tt>:.<pr
00000670:·6420·2d46·2061·7569·6426·6774·3b3d·3130··d·-F·auid&gt;=1000000670:·653e·2d61·2061·6c77·6179·732c·6578·6974··e>-a·always,exit
00000680:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse00000680:·202d·4620·7061·7468·3d2f·7573·722f·6269···-F·path=/usr/bi
00000690:·7420·2d46·206b·6579·3d70·6572·6d5f·6d6f··t·-F·key=perm_mo00000690:·6e2f·756d·6f75·6e74·202d·4620·7065·726d··n/umount·-F·perm
000006a0:·643c·2f70·7265·3e0a·4966·2074·6865·2073··d</pre>.If·the·s000006a0:·3d78·202d·4620·6175·6964·2667·743b·3d31··=x·-F·auid&gt;=1
000006b0:·7973·7465·6d20·6973·2036·3420·6269·7420··ystem·is·64·bit·000006b0:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns
000006c0:·7468·656e·2061·6c73·6f20·6164·6420·7468··then·also·add·th000006c0:·6574·202d·4620·6b65·793d·7072·6976·696c··et·-F·key=privil
000006d0:·6520·666f·6c6c·6f77·696e·6720·6c69·6e65··e·following·line000006d0:·6567·6564·3c2f·7072·653e·0a49·6620·7468··eged</pre>.If·th
000006e0:·3a0a·3c70·7265·3e2d·6120·616c·7761·7973··:.<pre>-a·always000006e0:·6520·3c74·743e·6175·6469·7464·3c2f·7474··e·<tt>auditd</tt
000006f0:·2c65·7869·7420·2d46·2061·7263·683d·6236··,exit·-F·arch=b6000006f0:·3e20·6461·656d·6f6e·2069·7320·636f·6e66··>·daemon·is·conf
00000700:·3420·2d53·2063·686d·6f64·202d·4620·6175··4·-S·chmod·-F·au00000700:·6967·7572·6564·2074·6f20·7573·6520·7468··igured·to·use·th
00000710:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a00000710:·6520·3c74·743e·6175·6469·7463·746c·3c2f··e·<tt>auditctl</
00000720:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke00000720:·7474·3e0a·7574·696c·6974·7920·746f·2072··tt>.utility·to·r
00000730:·793d·7065·726d·5f6d·6f64·3c2f·7072·653e··y=perm_mod</pre>00000730:·6561·6420·6175·6469·7420·7275·6c65·7320··ead·audit·rules·
00000740:·0a49·6620·7468·6520·3c74·743e·6175·6469··.If·the·<tt>audi00000740:·6475·7269·6e67·2064·6165·6d6f·6e20·7374··during·daemon·st
00000750:·7464·3c2f·7474·3e20·6461·656d·6f6e·2069··td</tt>·daemon·i00000750:·6172·7475·702c·2061·6464·2061·206c·696e··artup,·add·a·lin
00000760:·7320·636f·6e66·6967·7572·6564·2074·6f20··s·configured·to·00000760:·6520·6f66·2074·6865·2066·6f6c·6c6f·7769··e·of·the·followi
00000770:·7573·6520·7468·6520·3c74·743e·6175·6469··use·the·<tt>audi00000770:·6e67·0a66·6f72·6d20·746f·203c·7474·3e2f··ng.form·to·<tt>/
00000780:·7463·746c·3c2f·7474·3e0a·7574·696c·6974··tctl</tt>.utilit00000780:·6574·632f·6175·6469·742f·6175·6469·742e··etc/audit/audit.
00000790:·7920·746f·2072·6561·6420·6175·6469·7420··y·to·read·audit·00000790:·7275·6c65·733c·2f74·743e·3a0a·3c70·7265··rules</tt>:.<pre
000007a0:·7275·6c65·7320·6475·7269·6e67·2064·6165··rules·during·dae000007a0:·3e2d·6120·616c·7761·7973·2c65·7869·7420··>-a·always,exit·
000007b0:·6d6f·6e20·7374·6172·7475·702c·2061·6464··mon·startup,·add000007b0:·2d46·2070·6174·683d·2f75·7372·2f62·696e··-F·path=/usr/bin
000007c0:·2074·6865·2066·6f6c·6c6f·7769·6e67·206c···the·following·l000007c0:·2f75·6d6f·756e·7420·2d46·2070·6572·6d3d··/umount·-F·perm=
000007d0:·696e·6520·746f·0a3c·7474·3e2f·6574·632f··ine·to.<tt>/etc/000007d0:·7820·2d46·2061·7569·6426·6774·3b3d·3130··x·-F·auid&gt;=10
000007e0:·6175·6469·742f·6175·6469·742e·7275·6c65··audit/audit.rule000007e0:·3030·202d·4620·6175·6964·213d·756e·7365··00·-F·auid!=unse
000007f0:·733c·2f74·743e·2066·696c·653a·0a3c·7072··s</tt>·file:.<pr000007f0:·7420·2d46·206b·6579·3d70·7269·7669·6c65··t·-F·key=privile
00000800:·653e·2d61·2061·6c77·6179·732c·6578·6974··e>-a·always,exit00000800:·6765·643c·2f70·7265·3e0a·2020·2020·2020··ged</pre>.······
00000810:·202d·4620·6172·6368·3d62·3332·202d·5320···-F·arch=b32·-S·00000810:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·
00000820:·6368·6d6f·6420·2d46·2061·7569·6426·6774··chmod·-F·auid&gt00000820:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"
00000830:·3b3d·3130·3030·202d·4620·6175·6964·213d··;=1000·-F·auid!=00000830:·3e0a·2020·2020·2020·2020·4d69·7375·7365··>.········Misuse
00000840:·756e·7365·7420·2d46·206b·6579·3d70·6572··unset·-F·key=per00000840:·206f·6620·7072·6976·696c·6567·6564·2066···of·privileged·f
00000850:·6d5f·6d6f·643c·2f70·7265·3e0a·4966·2074··m_mod</pre>.If·t00000850:·756e·6374·696f·6e73·2c20·6569·7468·6572··unctions,·either
00000860:·6865·2073·7973·7465·6d20·6973·2036·3420··he·system·is·64·00000860:·2069·6e74·656e·7469·6f6e·616c·6c79·206f···intentionally·o
00000870:·6269·7420·7468·656e·2061·6c73·6f20·6164··bit·then·also·ad00000870:·7220·756e·696e·7465·6e74·696f·6e61·6c6c··r·unintentionall
00000880:·6420·7468·6520·666f·6c6c·6f77·696e·6720··d·the·following·00000880:·7920·6279·0a61·7574·686f·7269·7a65·6420··y·by.authorized·
00000890:·6c69·6e65·3a0a·3c70·7265·3e2d·6120·616c··line:.<pre>-a·al00000890:·7573·6572·732c·206f·7220·6279·2075·6e61··users,·or·by·una
000008a0:·7761·7973·2c65·7869·7420·2d46·2061·7263··ways,exit·-F·arc000008a0:·7574·686f·7269·7a65·6420·6578·7465·726e··uthorized·extern
000008b0:·683d·6236·3420·2d53·2063·686d·6f64·202d··h=b64·-S·chmod·-000008b0:·616c·2065·6e74·6974·6965·7320·7468·6174··al·entities·that
000008c0:·4620·6175·6964·2667·743b·3d31·3030·3020··F·auid&gt;=1000·000008c0:·2068·6176·6520·636f·6d70·726f·6d69·7365···have·compromise
000008d0:·2d46·2061·7569·6421·3d75·6e73·6574·202d··-F·auid!=unset·-000008d0:·6420·7379·7374·656d·2061·6363·6f75·6e74··d·system·account
000008e0:·4620·6b65·793d·7065·726d·5f6d·6f64·3c2f··F·key=perm_mod</000008e0:·732c·0a69·7320·6120·7365·7269·6f75·7320··s,.is·a·serious·
000008f0:·7072·653e·0a20·2020·2020·203c·2f74·643e··pre>.······</td>000008f0:·616e·6420·6f6e·676f·696e·6720·636f·6e63··and·ongoing·conc
00000900:·0a20·2020·2020·203c·7464·2078·6d6c·3a6c··.······<td·xml:l00000900:·6572·6e20·616e·6420·6361·6e20·6861·7665··ern·and·can·have
00000910:·616e·673d·2265·6e2d·5553·223e·0a20·2020··ang="en-US">.···00000910:·2073·6967·6e69·6669·6361·6e74·2061·6476···significant·adv
00000920:·2020·2020·2054·6865·2063·6861·6e67·696e·······The·changin00000920:·6572·7365·2069·6d70·6163·7473·206f·6e20··erse·impacts·on·
00000930:·6720·6f66·2066·696c·6520·7065·726d·6973··g·of·file·permis00000930:·6f72·6761·6e69·7a61·7469·6f6e·732e·0a41··organizations..A
00000940:·7369·6f6e·7320·636f·756c·6420·696e·6469··sions·could·indi00000940:·7564·6974·696e·6720·7468·6520·7573·6520··uditing·the·use·
00000950:·6361·7465·2074·6861·7420·6120·7573·6572··cate·that·a·user00000950:·6f66·2070·7269·7669·6c65·6765·6420·6675··of·privileged·fu
00000960:·2069·7320·6174·7465·6d70·7469·6e67·2074···is·attempting·t00000960:·6e63·7469·6f6e·7320·6973·206f·6e65·2077··nctions·is·one·w
00000970:·6f0a·6761·696e·2061·6363·6573·7320·746f··o.gain·access·to00000970:·6179·2074·6f20·6465·7465·6374·2073·7563··ay·to·detect·suc
00000980:·2069·6e66·6f72·6d61·7469·6f6e·2074·6861···information·tha00000980:·6820·6d69·7375·7365·2061·6e64·2069·6465··h·misuse·and·ide
00000990:·7420·776f·756c·6420·6f74·6865·7277·6973··t·would·otherwis00000990:·6e74·6966·790a·7468·6520·7269·736b·2066··ntify.the·risk·f
000009a0:·6520·6265·2064·6973·616c·6c6f·7765·642e··e·be·disallowed.000009a0:·726f·6d20·696e·7369·6465·7220·616e·6420··rom·insider·and·
000009b0:·2041·7564·6974·696e·6720·4441·4320·6d6f···Auditing·DAC·mo000009b0:·6164·7661·6e63·6564·2070·6572·7369·7374··advanced·persist
000009c0:·6469·6669·6361·7469·6f6e·730a·6361·6e20··difications.can·000009c0:·656e·7420·7468·7265·6174·732e·0a3c·6272··ent·threats..<br
000009d0:·6661·6369·6c69·7461·7465·2074·6865·2069··facilitate·the·i000009d0:·202f·3e3c·6272·202f·3e0a·5072·6976·696c···/><br·/>.Privil
000009e0:·6465·6e74·6966·6963·6174·696f·6e20·6f66··dentification·of000009e0:·6567·6564·2070·726f·6772·616d·7320·6172··eged·programs·ar
000009f0:·2070·6174·7465·726e·7320·6f66·2061·6275···patterns·of·abu000009f0:·6520·7375·626a·6563·7420·746f·2065·7363··e·subject·to·esc
00000a00:·7365·2061·6d6f·6e67·2062·6f74·6820·6175··se·among·both·au00000a00:·616c·6174·696f·6e2d·6f66·2d70·7269·7669··alation-of-privi
00000a10:·7468·6f72·697a·6564·2061·6e64·0a75·6e61··thorized·and.una00000a10:·6c65·6765·2061·7474·6163·6b73·2c0a·7768··lege·attacks,.wh
00000a20:·7574·686f·7269·7a65·6420·7573·6572·732e··uthorized·users.00000a20:·6963·6820·6174·7465·6d70·7420·746f·2073··ich·attempt·to·s
00000a30:·0a20·2020·2020·203c·2f74·643e·0a20·2020··.······</td>.···00000a30:·7562·7665·7274·2074·6865·6972·206e·6f72··ubvert·their·nor
00000a40:·203c·2f74·723e·0a20·2020·203c·7472·3e0a···</tr>.····<tr>.00000a40:·6d61·6c20·726f·6c65·206f·6620·7072·6f76··mal·role·of·prov
00000a50:·2020·2020·2020·3c74·643e·4155·2d32·2864········<td>AU-2(d00000a50:·6964·696e·6720·736f·6d65·206e·6563·6573··iding·some·neces
00000a60:·293c·6272·2f3e·4155·2d31·3228·6329·3c62··)<br/>AU-12(c)<b00000a60:·7361·7279·2062·7574·0a6c·696d·6974·6564··sary·but.limited
00000a70:·722f·3e41·432d·3628·3929·3c62·722f·3e43··r/>AC-6(9)<br/>C00000a70:·2063·6170·6162·696c·6974·792e·2041·7320···capability.·As·
00000a80:·4d2d·3628·6129·3c2f·7464·3e0a·2020·2020··M-6(a)</td>.····00000a80:·7375·6368·2c20·6d6f·7469·7661·7469·6f6e··such,·motivation
00000a90:·2020·3c74·643e·5265·636f·7264·2041·7474····<td>Record·Att00000a90:·2065·7869·7374·7320·746f·206d·6f6e·6974···exists·to·monit
00000aa0:·656d·7074·7320·746f·2041·6c74·6572·204c··empts·to·Alter·L00000aa0:·6f72·2074·6865·7365·2070·726f·6772·616d··or·these·program
00000ab0:·6f67·6f6e·2061·6e64·204c·6f67·6f75·7420··ogon·and·Logout·00000ab0:·7320·666f·720a·756e·7573·7561·6c20·6163··s·for.unusual·ac
00000ac0:·4576·656e·7473·202d·2074·616c·6c79·6c6f··Events·-·tallylo00000ac0:·7469·7669·7479·2e0a·2020·2020·2020·3c2f··tivity..······</
00000ad0:·673c·2f74·643e·0a20·2020·2020·203c·7464··g</td>.······<td00000ad0:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··
00000ae0:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US00000ae0:·2020·3c74·723e·0a20·2020·2020·203c·7464····<tr>.······<td
00000af0:·223e·0a20·2020·2020·2020·2054·6865·2061··">.········The·a00000af0:·3e41·552d·3228·6429·3c62·722f·3e41·552d··>AU-2(d)<br/>AU-
00000b00:·7564·6974·2073·7973·7465·6d20·616c·7265··udit·system·alre00000b00:·3132·2863·293c·6272·2f3e·4143·2d36·2839··12(c)<br/>AC-6(9
00000b10:·6164·7920·636f·6c6c·6563·7473·206c·6f67··ady·collects·log00000b10:·293c·6272·2f3e·434d·2d36·2861·293c·2f74··)<br/>CM-6(a)</t
00000b20:·696e·2069·6e66·6f72·6d61·7469·6f6e·2066··in·information·f00000b20:·643e·0a20·2020·2020·203c·7464·3e45·6e73··d>.······<td>Ens
00000b30:·6f72·2061·6c6c·2075·7365·7273·0a61·6e64··or·all·users.and00000b30:·7572·6520·6175·6469·7464·2043·6f6c·6c65··ure·auditd·Colle
00000b40:·2072·6f6f·742e·2049·6620·7468·6520·3c74···root.·If·the·<t00000b40:·6374·7320·496e·666f·726d·6174·696f·6e20··cts·Information·
00000b50:·743e·6175·6469·7464·3c2f·7474·3e20·6461··t>auditd</tt>·da00000b50:·6f6e·2074·6865·2055·7365·206f·6620·5072··on·the·Use·of·Pr
00000b60:·656d·6f6e·2069·7320·636f·6e66·6967·7572··emon·is·configur00000b60:·6976·696c·6567·6564·2043·6f6d·6d61·6e64··ivileged·Command
00000b70:·6564·2074·6f20·7573·6520·7468·650a·3c74··ed·to·use·the.<t00000b70:·7320·2d20·6d6f·756e·743c·2f74·643e·0a20··s·-·mount</td>.·
00000b80:·743e·6175·6765·6e72·756c·6573·3c2f·7474··t>augenrules</tt00000b80:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan
00000b90:·3e20·7072·6f67·7261·6d20·746f·2072·6561··>·program·to·rea00000b90:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····
00000ba0:·6420·6175·6469·7420·7275·6c65·7320·6475··d·audit·rules·du00000ba0:·2020·2041·7420·6120·6d69·6e69·6d75·6d2c·····At·a·minimum,
00000bb0:·7269·6e67·2064·6165·6d6f·6e20·7374·6172··ring·daemon·star00000bb0:·2074·6865·2061·7564·6974·2073·7973·7465···the·audit·syste
00000bc0:·7475·7020·2874·6865·0a64·6566·6175·6c74··tup·(the.default00000bc0:·6d20·7368·6f75·6c64·2063·6f6c·6c65·6374··m·should·collect
Max diff block lines reached; 5406306/7467776 bytes (72.40%) of diff not shown.
2.53 MB
html2text {}
Max HTML report size reached
795 KB
./usr/share/doc/ssg-nondebian/table-ol8-pcidssrefs.html
Ordering differences only
    
Offset 73, 28 lines modifiedOffset 73, 14 lines modified
73 is·the·only·place·that·loopback·network·traffic·should·be·seen,73 is·the·only·place·that·loopback·network·traffic·should·be·seen,
74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
75 anti-spoofing·measure.75 anti-spoofing·measure.
76 ······</td>76 ······</td>
77 ····</tr>77 ····</tr>
78 ····<tr>78 ····<tr>
79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
80 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td> 
81 ······<td·xml:lang="en-US"> 
82 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre> 
83 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre> 
84 ······</td> 
85 ······<td·xml:lang="en-US"> 
86 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange 
87 network·topology·information·with·other·routers.·If·this·capability·is·used·when 
88 not·required,·system·network·information·may·be·unnecessarily·transmitted·across 
89 the·network. 
90 ······</td> 
91 ····</tr> 
92 ····<tr> 
93 ······<td>Req-1.3.1<br/>Req-1.3.2</td> 
94 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>80 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>
95 ······<td·xml:lang="en-US">81 ······<td·xml:lang="en-US">
96 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,82 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,
97 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default83 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default
98 GRUB2·command·line·for·the·Linux·operating·system.84 GRUB2·command·line·for·the·Linux·operating·system.
99 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line85 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line
100 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the86 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the
Offset 105, 14 lines modifiedOffset 91, 28 lines modified
105 ······</td>91 ······</td>
106 ······<td·xml:lang="en-US">92 ······<td·xml:lang="en-US">
107 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce93 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce
108 the·vulnerability·to·exploitation.94 the·vulnerability·to·exploitation.
109 ······</td>95 ······</td>
110 ····</tr>96 ····</tr>
111 ····<tr>97 ····<tr>
 98 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
 99 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td>
 100 ······<td·xml:lang="en-US">
 101 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre>
 102 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre>
 103 ······</td>
 104 ······<td·xml:lang="en-US">
 105 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange
 106 network·topology·information·with·other·routers.·If·this·capability·is·used·when
 107 not·required,·system·network·information·may·be·unnecessarily·transmitted·across
 108 the·network.
 109 ······</td>
 110 ····</tr>
 111 ····<tr>
112 ······<td>Req-1.3.3</td>112 ······<td>Req-1.3.3</td>
113 ······<td>Deactivate·Wireless·Network·Interfaces</td>113 ······<td>Deactivate·Wireless·Network·Interfaces</td>
114 ······<td·xml:lang="en-US">114 ······<td·xml:lang="en-US">
115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless
116 capability.116 capability.
117 <br·/><br·/>117 <br·/><br·/>
  
Offset 157, 26 lines modifiedOffset 157, 26 lines modified
157 ······<td·xml:lang="en-US">157 ······<td·xml:lang="en-US">
158 ········Without·a·firewall·rule·configured·for·open·ports·default·firewall·policy·will·drop·all158 ········Without·a·firewall·rule·configured·for·open·ports·default·firewall·policy·will·drop·all
159 packets·to·these·ports.159 packets·to·these·ports.
160 ······</td>160 ······</td>
161 ····</tr>161 ····</tr>
162 ····<tr>162 ····<tr>
163 ······<td>Req-1.4.1</td>163 ······<td>Req-1.4.1</td>
164 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>164 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
165 ······<td·xml:lang="en-US">165 ······<td·xml:lang="en-US">
 166 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
 167 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
166 ········Configure·the·loopback·interface·to·accept·traffic. 
167 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback 
168 network. 
169 ······</td>168 ······</td>
170 ······<td·xml:lang="en-US">169 ······<td·xml:lang="en-US">
171 ········Loopback·traffic·is·generated·between·processes·on·machine·and·is 
172 typically·critical·to·operation·of·the·system.·The·loopback·interface 
173 is·the·only·place·that·loopback·network·traffic·should·be·seen, 
174 all·other·interfaces·should·ignore·traffic·on·this·network·as·an 
175 anti-spoofing·measure.170 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
 171 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state.
 172 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received,
 173 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
 174 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
 175 enables·the·system·to·continue·servicing·valid·connection·requests.
176 ······</td>176 ······</td>
177 ····</tr>177 ····</tr>
178 ····<tr>178 ····<tr>
179 ······<td>Req-1.4.1</td>179 ······<td>Req-1.4.1</td>
180 ······<td>Install·iptables·Package</td>180 ······<td>Install·iptables·Package</td>
181 ······<td·xml:lang="en-US">181 ······<td·xml:lang="en-US">
182 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command:182 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command:
Offset 187, 26 lines modifiedOffset 187, 26 lines modified
187 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering187 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
188 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP188 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
189 masquerading,·etc.189 masquerading,·etc.
190 ······</td>190 ······</td>
191 ····</tr>191 ····</tr>
192 ····<tr>192 ····<tr>
193 ······<td>Req-1.4.1</td>193 ······<td>Req-1.4.1</td>
194 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>194 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>
195 ······<td·xml:lang="en-US">195 ······<td·xml:lang="en-US">
196 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre> 
197 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>196 ········Configure·the·loopback·interface·to·accept·traffic.
 197 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback
 198 network.
198 ······</td>199 ······</td>
199 ······<td·xml:lang="en-US">200 ······<td·xml:lang="en-US">
 201 ········Loopback·traffic·is·generated·between·processes·on·machine·and·is
 202 typically·critical·to·operation·of·the·system.·The·loopback·interface
 203 is·the·only·place·that·loopback·network·traffic·should·be·seen,
 204 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
 205 anti-spoofing·measure.
200 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a 
201 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state. 
202 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received, 
203 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood 
204 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and 
205 enables·the·system·to·continue·servicing·valid·connection·requests. 
206 ······</td>206 ······</td>
207 ····</tr>207 ····</tr>
208 ····<tr>208 ····<tr>
209 ······<td>Req-1.4.2</td>209 ······<td>Req-1.4.2</td>
210 ······<td>Disable·SCTP·Support</td>210 ······<td>Disable·SCTP·Support</td>
211 ······<td·xml:lang="en-US">211 ······<td·xml:lang="en-US">
212 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a212 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
Offset 246, 41 lines modifiedOffset 246, 22 lines modified
246 ······<td·xml:lang="en-US">246 ······<td·xml:lang="en-US">
Max diff block lines reached; 300129/306711 bytes (97.85%) of diff not shown.
495 KB
html2text {}
Max HTML report size reached
17.3 MB
./usr/share/doc/ssg-nondebian/table-rhcos4-nistrefs.html
    
Offset 66, 14853 lines modifiedOffset 66, 14853 lines modified
00000410:·6c65·2054·6974·6c65·3c2f·7468·3e0a·2020··le·Title</th>.··00000410:·6c65·2054·6974·6c65·3c2f·7468·3e0a·2020··le·Title</th>.··
00000420:·2020·3c74·683e·4465·7363·7269·7074·696f····<th>Descriptio00000420:·2020·3c74·683e·4465·7363·7269·7074·696f····<th>Descriptio
00000430:·6e3c·2f74·683e·0a20·2020·203c·7468·3e52··n</th>.····<th>R00000430:·6e3c·2f74·683e·0a20·2020·203c·7468·3e52··n</th>.····<th>R
00000440:·6174·696f·6e61·6c65·3c2f·7468·3e0a·2020··ationale</th>.··00000440:·6174·696f·6e61·6c65·3c2f·7468·3e0a·2020··ationale</th>.··
00000450:·3c2f·7468·6561·643e·0a20·203c·7462·6f64··</thead>.··<tbod00000450:·3c2f·7468·6561·643e·0a20·203c·7462·6f64··</thead>.··<tbod
00000460:·793e·0a20·203c·7472·3e0a·2020·2020·2020··y>.··<tr>.······00000460:·793e·0a20·203c·7472·3e0a·2020·2020·2020··y>.··<tr>.······
Diff chunk too large, falling back to line-by-line diff (5049 lines added, 5049 lines removed)
00000470:·3c74·643e·4155·2d32·2864·293c·6272·2f3e··<td>AU-2(d)<br/>00000470:·3c74·643e·4155·2d32·2864·293c·6272·2f3e··<td>AU-2(d)<br/>
00000480:·4155·2d31·3228·6329·3c62·722f·3e43·4d2d··AU-12(c)<br/>CM-00000480:·4155·2d31·3228·6329·3c62·722f·3e41·432d··AU-12(c)<br/>AC-
00000490:·3628·6129·3c2f·7464·3e0a·2020·2020·2020··6(a)</td>.······00000490:·3628·3929·3c62·722f·3e43·4d2d·3628·6129··6(9)<br/>CM-6(a)
000004a0:·3c74·643e·5265·636f·7264·2045·7665·6e74··<td>Record·Event000004a0:·3c2f·7464·3e0a·2020·2020·2020·3c74·643e··</td>.······<td>
000004b0:·7320·7468·6174·204d·6f64·6966·7920·7468··s·that·Modify·th000004b0:·456e·7375·7265·2061·7564·6974·6420·436f··Ensure·auditd·Co
000004c0:·6520·5379·7374·656d·2773·2044·6973·6372··e·System's·Discr000004c0:·6c6c·6563·7473·2049·6e66·6f72·6d61·7469··llects·Informati
000004d0:·6574·696f·6e61·7279·2041·6363·6573·7320··etionary·Access·000004d0:·6f6e·206f·6e20·7468·6520·5573·6520·6f66··on·on·the·Use·of
000004e0:·436f·6e74·726f·6c73·202d·2063·686d·6f64··Controls·-·chmod000004e0:·2050·7269·7669·6c65·6765·6420·436f·6d6d···Privileged·Comm
000004f0:·3c2f·7464·3e0a·2020·2020·2020·3c74·6420··</td>.······<td·000004f0:·616e·6473·202d·2075·6d6f·756e·743c·2f74··ands·-·umount</t
00000500:·786d·6c3a·6c61·6e67·3d22·656e·2d55·5322··xml:lang="en-US"00000500:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
00000510:·3e0a·2020·2020·2020·2020·4174·2061·206d··>.········At·a·m00000510:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
00000520:·696e·696d·756d·2c20·7468·6520·6175·6469··inimum,·the·audi00000520:·2020·2020·2020·2041·7420·6120·6d69·6e69·········At·a·mini
00000530:·7420·7379·7374·656d·2073·686f·756c·6420··t·system·should·00000530:·6d75·6d2c·2074·6865·2061·7564·6974·2073··mum,·the·audit·s
00000540:·636f·6c6c·6563·7420·6669·6c65·2070·6572··collect·file·per00000540:·7973·7465·6d20·7368·6f75·6c64·2063·6f6c··ystem·should·col
00000550:·6d69·7373·696f·6e0a·6368·616e·6765·7320··mission.changes·00000550:·6c65·6374·2074·6865·2065·7865·6375·7469··lect·the·executi
00000560:·666f·7220·616c·6c20·7573·6572·7320·616e··for·all·users·an00000560:·6f6e·206f·660a·7072·6976·696c·6567·6564··on·of.privileged
00000570:·6420·726f·6f74·2e20·4966·2074·6865·203c··d·root.·If·the·<00000570:·2063·6f6d·6d61·6e64·7320·666f·7220·616c···commands·for·al
00000580:·7474·3e61·7564·6974·643c·2f74·743e·2064··tt>auditd</tt>·d00000580:·6c20·7573·6572·7320·616e·6420·726f·6f74··l·users·and·root
00000590:·6165·6d6f·6e20·6973·2063·6f6e·6669·6775··aemon·is·configu00000590:·2e20·4966·2074·6865·203c·7474·3e61·7564··.·If·the·<tt>aud
000005a0:·7265·6420·746f·0a75·7365·2074·6865·203c··red·to.use·the·<000005a0:·6974·643c·2f74·743e·2064·6165·6d6f·6e20··itd</tt>·daemon·
000005b0:·7474·3e61·7567·656e·7275·6c65·733c·2f74··tt>augenrules</t000005b0:·6973·0a63·6f6e·6669·6775·7265·6420·746f··is.configured·to
000005c0:·743e·2070·726f·6772·616d·2074·6f20·7265··t>·program·to·re000005c0:·2075·7365·2074·6865·203c·7474·3e61·7567···use·the·<tt>aug
000005d0:·6164·2061·7564·6974·2072·756c·6573·2064··ad·audit·rules·d000005d0:·656e·7275·6c65·733c·2f74·743e·2070·726f··enrules</tt>·pro
000005e0:·7572·696e·6720·6461·656d·6f6e·2073·7461··uring·daemon·sta000005e0:·6772·616d·2074·6f20·7265·6164·2061·7564··gram·to·read·aud
000005f0:·7274·7570·0a28·7468·6520·6465·6661·756c··rtup.(the·defaul000005f0:·6974·2072·756c·6573·2064·7572·696e·670a··it·rules·during.
00000600:·7429·2c20·6164·6420·7468·6520·666f·6c6c··t),·add·the·foll00000600:·6461·656d·6f6e·2073·7461·7274·7570·2028··daemon·startup·(
00000610:·6f77·696e·6720·6c69·6e65·2074·6f20·6120··owing·line·to·a·00000610:·7468·6520·6465·6661·756c·7429·2c20·6164··the·default),·ad
00000620:·6669·6c65·2077·6974·6820·7375·6666·6978··file·with·suffix00000620:·6420·6120·6c69·6e65·206f·6620·7468·6520··d·a·line·of·the·
00000630:·203c·7474·3e2e·7275·6c65·733c·2f74·743e···<tt>.rules</tt>00000630:·666f·6c6c·6f77·696e·6720·666f·726d·2074··following·form·t
00000640:·2069·6e0a·7468·6520·6469·7265·6374·6f72···in.the·director00000640:·6f20·6120·6669·6c65·2077·6974·680a·7375··o·a·file·with.su
00000650:·7920·3c74·743e·2f65·7463·2f61·7564·6974··y·<tt>/etc/audit00000650:·6666·6978·203c·7474·3e2e·7275·6c65·733c··ffix·<tt>.rules<
00000660:·2f72·756c·6573·2e64·3c2f·7474·3e3a·0a3c··/rules.d</tt>:.<00000660:·2f74·743e·2069·6e20·7468·6520·6469·7265··/tt>·in·the·dire
00000670:·7072·653e·2d61·2061·6c77·6179·732c·6578··pre>-a·always,ex00000670:·6374·6f72·7920·3c74·743e·2f65·7463·2f61··ctory·<tt>/etc/a
00000680:·6974·202d·4620·6172·6368·3d62·3332·202d··it·-F·arch=b32·-00000680:·7564·6974·2f72·756c·6573·2e64·3c2f·7474··udit/rules.d</tt
00000690:·5320·6368·6d6f·6420·2d46·2061·7569·6426··S·chmod·-F·auid&00000690:·3e3a·0a3c·7072·653e·2d61·2061·6c77·6179··>:.<pre>-a·alway
000006a0:·6774·3b3d·3130·3030·202d·4620·6175·6964··gt;=1000·-F·auid000006a0:·732c·6578·6974·202d·4620·7061·7468·3d2f··s,exit·-F·path=/
000006b0:·213d·756e·7365·7420·2d46·206b·6579·3d70··!=unset·-F·key=p000006b0:·7573·722f·6269·6e2f·756d·6f75·6e74·202d··usr/bin/umount·-
000006c0:·6572·6d5f·6d6f·643c·2f70·7265·3e0a·4966··erm_mod</pre>.If000006c0:·4620·7065·726d·3d78·202d·4620·6175·6964··F·perm=x·-F·auid
000006d0:·2074·6865·2073·7973·7465·6d20·6973·2036···the·system·is·6000006d0:·2667·743b·3d31·3030·3020·2d46·2061·7569··&gt;=1000·-F·aui
000006e0:·3420·6269·7420·7468·656e·2061·6c73·6f20··4·bit·then·also·000006e0:·6421·3d75·6e73·6574·202d·4620·6b65·793d··d!=unset·-F·key=
000006f0:·6164·6420·7468·6520·666f·6c6c·6f77·696e··add·the·followin000006f0:·7072·6976·696c·6567·6564·3c2f·7072·653e··privileged</pre>
00000700:·6720·6c69·6e65·3a0a·3c70·7265·3e2d·6120··g·line:.<pre>-a·00000700:·0a49·6620·7468·6520·3c74·743e·6175·6469··.If·the·<tt>audi
00000710:·616c·7761·7973·2c65·7869·7420·2d46·2061··always,exit·-F·a00000710:·7464·3c2f·7474·3e20·6461·656d·6f6e·2069··td</tt>·daemon·i
00000720:·7263·683d·6236·3420·2d53·2063·686d·6f64··rch=b64·-S·chmod00000720:·7320·636f·6e66·6967·7572·6564·2074·6f20··s·configured·to·
00000730:·202d·4620·6175·6964·2667·743b·3d31·3030···-F·auid&gt;=10000000730:·7573·6520·7468·6520·3c74·743e·6175·6469··use·the·<tt>audi
00000740:·3020·2d46·2061·7569·6421·3d75·6e73·6574··0·-F·auid!=unset00000740:·7463·746c·3c2f·7474·3e0a·7574·696c·6974··tctl</tt>.utilit
00000750:·202d·4620·6b65·793d·7065·726d·5f6d·6f64···-F·key=perm_mod00000750:·7920·746f·2072·6561·6420·6175·6469·7420··y·to·read·audit·
00000760:·3c2f·7072·653e·0a49·6620·7468·6520·3c74··</pre>.If·the·<t00000760:·7275·6c65·7320·6475·7269·6e67·2064·6165··rules·during·dae
00000770:·743e·6175·6469·7464·3c2f·7474·3e20·6461··t>auditd</tt>·da00000770:·6d6f·6e20·7374·6172·7475·702c·2061·6464··mon·startup,·add
00000780:·656d·6f6e·2069·7320·636f·6e66·6967·7572··emon·is·configur00000780:·2061·206c·696e·6520·6f66·2074·6865·2066···a·line·of·the·f
00000790:·6564·2074·6f20·7573·6520·7468·6520·3c74··ed·to·use·the·<t00000790:·6f6c·6c6f·7769·6e67·0a66·6f72·6d20·746f··ollowing.form·to
000007a0:·743e·6175·6469·7463·746c·3c2f·7474·3e0a··t>auditctl</tt>.000007a0:·203c·7474·3e2f·6574·632f·6175·6469·742f···<tt>/etc/audit/
000007b0:·7574·696c·6974·7920·746f·2072·6561·6420··utility·to·read·000007b0:·6175·6469·742e·7275·6c65·733c·2f74·743e··audit.rules</tt>
000007c0:·6175·6469·7420·7275·6c65·7320·6475·7269··audit·rules·duri000007c0:·3a0a·3c70·7265·3e2d·6120·616c·7761·7973··:.<pre>-a·always
000007d0:·6e67·2064·6165·6d6f·6e20·7374·6172·7475··ng·daemon·startu000007d0:·2c65·7869·7420·2d46·2070·6174·683d·2f75··,exit·-F·path=/u
000007e0:·702c·2061·6464·2074·6865·2066·6f6c·6c6f··p,·add·the·follo000007e0:·7372·2f62·696e·2f75·6d6f·756e·7420·2d46··sr/bin/umount·-F
000007f0:·7769·6e67·206c·696e·6520·746f·0a3c·7474··wing·line·to.<tt000007f0:·2070·6572·6d3d·7820·2d46·2061·7569·6426···perm=x·-F·auid&
00000800:·3e2f·6574·632f·6175·6469·742f·6175·6469··>/etc/audit/audi00000800:·6774·3b3d·3130·3030·202d·4620·6175·6964··gt;=1000·-F·auid
00000810:·742e·7275·6c65·733c·2f74·743e·2066·696c··t.rules</tt>·fil00000810:·213d·756e·7365·7420·2d46·206b·6579·3d70··!=unset·-F·key=p
00000820:·653a·0a3c·7072·653e·2d61·2061·6c77·6179··e:.<pre>-a·alway00000820:·7269·7669·6c65·6765·643c·2f70·7265·3e0a··rivileged</pre>.
00000830:·732c·6578·6974·202d·4620·6172·6368·3d62··s,exit·-F·arch=b00000830:·2020·2020·2020·3c2f·7464·3e0a·2020·2020········</td>.····
00000840:·3332·202d·5320·6368·6d6f·6420·2d46·2061··32·-S·chmod·-F·a00000840:·2020·3c74·6420·786d·6c3a·6c61·6e67·3d22····<td·xml:lang="
00000850:·7569·6426·6774·3b3d·3130·3030·202d·4620··uid&gt;=1000·-F·00000850:·656e·2d55·5322·3e0a·2020·2020·2020·2020··en-US">.········
00000860:·6175·6964·213d·756e·7365·7420·2d46·206b··auid!=unset·-F·k00000860:·4d69·7375·7365·206f·6620·7072·6976·696c··Misuse·of·privil
00000870:·6579·3d70·6572·6d5f·6d6f·643c·2f70·7265··ey=perm_mod</pre00000870:·6567·6564·2066·756e·6374·696f·6e73·2c20··eged·functions,·
00000880:·3e0a·4966·2074·6865·2073·7973·7465·6d20··>.If·the·system·00000880:·6569·7468·6572·2069·6e74·656e·7469·6f6e··either·intention
00000890:·6973·2036·3420·6269·7420·7468·656e·2061··is·64·bit·then·a00000890:·616c·6c79·206f·7220·756e·696e·7465·6e74··ally·or·unintent
000008a0:·6c73·6f20·6164·6420·7468·6520·666f·6c6c··lso·add·the·foll000008a0:·696f·6e61·6c6c·7920·6279·0a61·7574·686f··ionally·by.autho
000008b0:·6f77·696e·6720·6c69·6e65·3a0a·3c70·7265··owing·line:.<pre000008b0:·7269·7a65·6420·7573·6572·732c·206f·7220··rized·users,·or·
000008c0:·3e2d·6120·616c·7761·7973·2c65·7869·7420··>-a·always,exit·000008c0:·6279·2075·6e61·7574·686f·7269·7a65·6420··by·unauthorized·
000008d0:·2d46·2061·7263·683d·6236·3420·2d53·2063··-F·arch=b64·-S·c000008d0:·6578·7465·726e·616c·2065·6e74·6974·6965··external·entitie
000008e0:·686d·6f64·202d·4620·6175·6964·2667·743b··hmod·-F·auid&gt;000008e0:·7320·7468·6174·2068·6176·6520·636f·6d70··s·that·have·comp
000008f0:·3d31·3030·3020·2d46·2061·7569·6421·3d75··=1000·-F·auid!=u000008f0:·726f·6d69·7365·6420·7379·7374·656d·2061··romised·system·a
00000900:·6e73·6574·202d·4620·6b65·793d·7065·726d··nset·-F·key=perm00000900:·6363·6f75·6e74·732c·0a69·7320·6120·7365··ccounts,.is·a·se
00000910:·5f6d·6f64·3c2f·7072·653e·0a20·2020·2020··_mod</pre>.·····00000910:·7269·6f75·7320·616e·6420·6f6e·676f·696e··rious·and·ongoin
00000920:·203c·2f74·643e·0a20·2020·2020·203c·7464···</td>.······<td00000920:·6720·636f·6e63·6572·6e20·616e·6420·6361··g·concern·and·ca
00000930:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US00000930:·6e20·6861·7665·2073·6967·6e69·6669·6361··n·have·significa
00000940:·223e·0a20·2020·2020·2020·2054·6865·2063··">.········The·c00000940:·6e74·2061·6476·6572·7365·2069·6d70·6163··nt·adverse·impac
00000950:·6861·6e67·696e·6720·6f66·2066·696c·6520··hanging·of·file·00000950:·7473·206f·6e20·6f72·6761·6e69·7a61·7469··ts·on·organizati
00000960:·7065·726d·6973·7369·6f6e·7320·636f·756c··permissions·coul00000960:·6f6e·732e·0a41·7564·6974·696e·6720·7468··ons..Auditing·th
00000970:·6420·696e·6469·6361·7465·2074·6861·7420··d·indicate·that·00000970:·6520·7573·6520·6f66·2070·7269·7669·6c65··e·use·of·privile
00000980:·6120·7573·6572·2069·7320·6174·7465·6d70··a·user·is·attemp00000980:·6765·6420·6675·6e63·7469·6f6e·7320·6973··ged·functions·is
00000990:·7469·6e67·2074·6f0a·6761·696e·2061·6363··ting·to.gain·acc00000990:·206f·6e65·2077·6179·2074·6f20·6465·7465···one·way·to·dete
000009a0:·6573·7320·746f·2069·6e66·6f72·6d61·7469··ess·to·informati000009a0:·6374·2073·7563·6820·6d69·7375·7365·2061··ct·such·misuse·a
000009b0:·6f6e·2074·6861·7420·776f·756c·6420·6f74··on·that·would·ot000009b0:·6e64·2069·6465·6e74·6966·790a·7468·6520··nd·identify.the·
000009c0:·6865·7277·6973·6520·6265·2064·6973·616c··herwise·be·disal000009c0:·7269·736b·2066·726f·6d20·696e·7369·6465··risk·from·inside
000009d0:·6c6f·7765·642e·2041·7564·6974·696e·6720··lowed.·Auditing·000009d0:·7220·616e·6420·6164·7661·6e63·6564·2070··r·and·advanced·p
000009e0:·4441·4320·6d6f·6469·6669·6361·7469·6f6e··DAC·modification000009e0:·6572·7369·7374·656e·7420·7468·7265·6174··ersistent·threat
000009f0:·730a·6361·6e20·6661·6369·6c69·7461·7465··s.can·facilitate000009f0:·732e·0a3c·6272·202f·3e3c·6272·202f·3e0a··s..<br·/><br·/>.
00000a00:·2074·6865·2069·6465·6e74·6966·6963·6174···the·identificat00000a00:·5072·6976·696c·6567·6564·2070·726f·6772··Privileged·progr
00000a10:·696f·6e20·6f66·2070·6174·7465·726e·7320··ion·of·patterns·00000a10:·616d·7320·6172·6520·7375·626a·6563·7420··ams·are·subject·
00000a20:·6f66·2061·6275·7365·2061·6d6f·6e67·2062··of·abuse·among·b00000a20:·746f·2065·7363·616c·6174·696f·6e2d·6f66··to·escalation-of
00000a30:·6f74·6820·6175·7468·6f72·697a·6564·2061··oth·authorized·a00000a30:·2d70·7269·7669·6c65·6765·2061·7474·6163··-privilege·attac
00000a40:·6e64·0a75·6e61·7574·686f·7269·7a65·6420··nd.unauthorized·00000a40:·6b73·2c0a·7768·6963·6820·6174·7465·6d70··ks,.which·attemp
00000a50:·7573·6572·732e·0a20·2020·2020·203c·2f74··users..······</t00000a50:·7420·746f·2073·7562·7665·7274·2074·6865··t·to·subvert·the
00000a60:·643e·0a20·2020·203c·2f74·723e·0a20·2020··d>.····</tr>.···00000a60:·6972·206e·6f72·6d61·6c20·726f·6c65·206f··ir·normal·role·o
00000a70:·203c·7472·3e0a·2020·2020·2020·3c74·643e···<tr>.······<td>00000a70:·6620·7072·6f76·6964·696e·6720·736f·6d65··f·providing·some
00000a80:·4155·2d32·2864·293c·6272·2f3e·4155·2d31··AU-2(d)<br/>AU-100000a80:·206e·6563·6573·7361·7279·2062·7574·0a6c···necessary·but.l
00000a90:·3228·6329·3c62·722f·3e41·432d·3628·3929··2(c)<br/>AC-6(9)00000a90:·696d·6974·6564·2063·6170·6162·696c·6974··imited·capabilit
00000aa0:·3c62·722f·3e43·4d2d·3628·6129·3c2f·7464··<br/>CM-6(a)</td00000aa0:·792e·2041·7320·7375·6368·2c20·6d6f·7469··y.·As·such,·moti
00000ab0:·3e0a·2020·2020·2020·3c74·643e·5265·636f··>.······<td>Reco00000ab0:·7661·7469·6f6e·2065·7869·7374·7320·746f··vation·exists·to
00000ac0:·7264·2041·7474·656d·7074·7320·746f·2041··rd·Attempts·to·A00000ac0:·206d·6f6e·6974·6f72·2074·6865·7365·2070···monitor·these·p
00000ad0:·6c74·6572·204c·6f67·6f6e·2061·6e64·204c··lter·Logon·and·L00000ad0:·726f·6772·616d·7320·666f·720a·756e·7573··rograms·for.unus
00000ae0:·6f67·6f75·7420·4576·656e·7473·202d·2074··ogout·Events·-·t00000ae0:·7561·6c20·6163·7469·7669·7479·2e0a·2020··ual·activity..··
00000af0:·616c·6c79·6c6f·673c·2f74·643e·0a20·2020··allylog</td>.···00000af0:·2020·2020·3c2f·7464·3e0a·2020·2020·3c2f······</td>.····</
00000b00:·2020·203c·7464·2078·6d6c·3a6c·616e·673d·····<td·xml:lang=00000b00:·7472·3e0a·2020·2020·3c74·723e·0a20·2020··tr>.····<tr>.···
00000b10:·2265·6e2d·5553·223e·0a20·2020·2020·2020··"en-US">.·······00000b10:·2020·203c·7464·3e41·552d·3228·6429·3c62·····<td>AU-2(d)<b
00000b20:·2054·6865·2061·7564·6974·2073·7973·7465···The·audit·syste00000b20:·722f·3e41·552d·3132·2863·293c·6272·2f3e··r/>AU-12(c)<br/>
00000b30:·6d20·616c·7265·6164·7920·636f·6c6c·6563··m·already·collec00000b30:·4143·2d36·2839·293c·6272·2f3e·434d·2d36··AC-6(9)<br/>CM-6
00000b40:·7473·206c·6f67·696e·2069·6e66·6f72·6d61··ts·login·informa00000b40:·2861·293c·2f74·643e·0a20·2020·2020·203c··(a)</td>.······<
00000b50:·7469·6f6e·2066·6f72·2061·6c6c·2075·7365··tion·for·all·use00000b50:·7464·3e45·6e73·7572·6520·6175·6469·7464··td>Ensure·auditd
00000b60:·7273·0a61·6e64·2072·6f6f·742e·2049·6620··rs.and·root.·If·00000b60:·2043·6f6c·6c65·6374·7320·496e·666f·726d···Collects·Inform
00000b70:·7468·6520·3c74·743e·6175·6469·7464·3c2f··the·<tt>auditd</00000b70:·6174·696f·6e20·6f6e·2074·6865·2055·7365··ation·on·the·Use
00000b80:·7474·3e20·6461·656d·6f6e·2069·7320·636f··tt>·daemon·is·co00000b80:·206f·6620·5072·6976·696c·6567·6564·2043···of·Privileged·C
00000b90:·6e66·6967·7572·6564·2074·6f20·7573·6520··nfigured·to·use·00000b90:·6f6d·6d61·6e64·7320·2d20·6d6f·756e·743c··ommands·-·mount<
00000ba0:·7468·650a·3c74·743e·6175·6765·6e72·756c··the.<tt>augenrul00000ba0:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x
00000bb0:·6573·3c2f·7474·3e20·7072·6f67·7261·6d20··es</tt>·program·00000bb0:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
00000bc0:·746f·2072·6561·6420·6175·6469·7420·7275··to·read·audit·ru00000bc0:·0a20·2020·2020·2020·2041·7420·6120·6d69··.········At·a·mi
00000bd0:·6c65·7320·6475·7269·6e67·2064·6165·6d6f··les·during·daemo00000bd0:·6e69·6d75·6d2c·2074·6865·2061·7564·6974··nimum,·the·audit
00000be0:·6e20·7374·6172·7475·7020·2874·6865·0a64··n·startup·(the.d00000be0:·2073·7973·7465·6d20·7368·6f75·6c64·2063···system·should·c
Max diff block lines reached; 7176533/7873873 bytes (91.14%) of diff not shown.
9.77 MB
html2text {}
Max HTML report size reached
3.53 MB
./usr/share/doc/ssg-nondebian/table-rhel8-anssirefs.html
    
Offset 64, 274 lines modifiedOffset 64, 274 lines modified
000003f0:·3c74·683e·5275·6c65·2054·6974·6c65·3c2f··<th>Rule·Title</000003f0:·3c74·683e·5275·6c65·2054·6974·6c65·3c2f··<th>Rule·Title</
00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc00000400:·7468·3e0a·2020·2020·3c74·683e·4465·7363··th>.····<th>Desc
00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···00000410:·7269·7074·696f·6e3c·2f74·683e·0a20·2020··ription</th>.···
00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</00000420:·203c·7468·3e52·6174·696f·6e61·6c65·3c2f···<th>Rationale</
00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·00000430:·7468·3e0a·2020·3c2f·7468·6561·643e·0a20··th>.··</thead>.·
00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.00000440:·203c·7462·6f64·793e·0a20·203c·7472·3e0a···<tbody>.··<tr>.
00000450:·2020·2020·2020·3c74·643e·5231·3c2f·7464········<td>R1</td00000450:·2020·2020·2020·3c74·643e·5231·3c2f·7464········<td>R1</td
00000460:·3e0a·2020·2020·2020·3c74·643e·496e·7374··>.······<td>Inst00000460:·3e0a·2020·2020·2020·3c74·643e·456e·7375··>.······<td>Ensu
 00000470:·7265·2053·4d41·5020·6973·206e·6f74·2064··re·SMAP·is·not·d
 00000480:·6973·6162·6c65·6420·6475·7269·6e67·2062··isabled·during·b
00000470:·616c·6c20·5041·4520·4b65·726e·656c·206f··all·PAE·Kernel·o 
00000480:·6e20·5375·7070·6f72·7465·6420·3332·2d62··n·Supported·32-b 
00000490:·6974·2078·3836·2053·7973·7465·6d73·3c2f··it·x86·Systems</ 
000004a0:·7464·3e0a·2020·2020·2020·3c74·6420·786d··td>.······<td·xm 
000004b0:·6c3a·6c61·6e67·3d22·656e·2d55·5322·3e0a··l:lang="en-US">. 
000004c0:·2020·2020·2020·2020·5379·7374·656d·7320··········Systems· 
000004d0:·7468·6174·2061·7265·2075·7369·6e67·2074··that·are·using·t 
000004e0:·6865·2036·342d·6269·7420·7838·3620·6b65··he·64-bit·x86·ke 
000004f0:·726e·656c·2070·6163·6b61·6765·0a64·6f20··rnel·package.do· 
00000500:·6e6f·7420·6e65·6564·2074·6f20·696e·7374··not·need·to·inst 
00000510:·616c·6c20·7468·6520·6b65·726e·656c·2d50··all·the·kernel-P 
00000520:·4145·2070·6163·6b61·6765·2062·6563·6175··AE·package·becau 
00000530:·7365·2074·6865·2036·342d·6269·740a·7838··se·the·64-bit.x8 
00000540:·3620·6b65·726e·656c·2061·6c72·6561·6479··6·kernel·already 
00000550:·2069·6e63·6c75·6465·7320·7468·6973·2073···includes·this·s 
00000560:·7570·706f·7274·2e20·486f·7765·7665·722c··upport.·However, 
00000570:·2069·6620·7468·6520·7379·7374·656d·2069···if·the·system·i 
00000580:·730a·3332·2d62·6974·2061·6e64·2061·6c73··s.32-bit·and·als 
00000590:·6f20·7375·7070·6f72·7473·2074·6865·2050··o·supports·the·P 
000005a0:·4145·2061·6e64·204e·5820·6665·6174·7572··AE·and·NX·featur 
000005b0:·6573·2061·730a·6465·7465·726d·696e·6564··es·as.determined 
000005c0:·2069·6e20·7468·6520·7072·6576·696f·7573···in·the·previous 
000005d0:·2073·6563·7469·6f6e·2c20·7468·6520·6b65···section,·the·ke 
000005e0:·726e·656c·2d50·4145·2070·6163·6b61·6765··rnel-PAE·package 
000005f0:·2073·686f·756c·640a·6265·2069·6e73·7461···should.be·insta 
00000600:·6c6c·6564·2074·6f20·656e·6162·6c65·2058··lled·to·enable·X 
00000610:·4420·6f72·204e·5820·7375·7070·6f72·742e··D·or·NX·support. 
00000620:·0a54·6865·203c·636f·6465·3e6b·6572·6e65··.The·<code>kerne 
00000630:·6c2d·5041·453c·2f63·6f64·653e·2070·6163··l-PAE</code>·pac 
00000640:·6b61·6765·2063·616e·2062·6520·696e·7374··kage·can·be·inst 
00000650:·616c·6c65·6420·7769·7468·2074·6865·2066··alled·with·the·f 
00000660:·6f6c·6c6f·7769·6e67·2063·6f6d·6d61·6e64··ollowing·command 
00000670:·3a0a·3c70·7265·3e0a·2420·7375·646f·2079··:.<pre>.$·sudo·y 
00000680:·756d·2069·6e73·7461·6c6c·206b·6572·6e65··um·install·kerne 
00000690:·6c2d·5041·453c·2f70·7265·3e0a·5468·6520··l-PAE</pre>.The· 
000006a0:·696e·7374·616c·6c61·7469·6f6e·2070·726f··installation·pro 
000006b0:·6365·7373·2073·686f·756c·6420·616c·736f··cess·should·also 
000006c0:·2068·6176·6520·636f·6e66·6967·7572·6564···have·configured 
000006d0:·2074·6865·0a62·6f6f·746c·6f61·6465·7220···the.bootloader· 
000006e0:·746f·206c·6f61·6420·7468·6520·6e65·7720··to·load·the·new· 
000006f0:·6b65·726e·656c·2061·7420·626f·6f74·2e20··kernel·at·boot.· 
00000700:·5665·7269·6679·2074·6869·7320·6166·7465··Verify·this·afte 
00000710:·7220·7265·626f·6f74·0a61·6e64·206d·6f64··r·reboot.and·mod 
00000720:·6966·7920·3c74·743e·2f65·7463·2f64·6566··ify·<tt>/etc/def 
00000730:·6175·6c74·2f67·7275·623c·2f74·743e·2069··ault/grub</tt>·i 
00000740:·6620·6e65·6365·7373·6172·792e·0a20·2020··f·necessary..··· 
00000750:·2020·203c·2f74·643e·0a20·2020·2020·203c·····</td>.······<00000490:·6f6f·743c·2f74·643e·0a20·2020·2020·203c··oot</td>.······<
00000760:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-000004a0:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-
00000770:·5553·223e·0a20·2020·2020·2020·204f·6e20··US">.········On·000004b0:·5553·223e·0a20·2020·2020·2020·2054·6865··US">.········The
00000780:·3332·2d62·6974·2073·7973·7465·6d73·2074··32-bit·systems·t 
00000790:·6861·7420·7375·7070·6f72·7420·7468·6520··hat·support·the· 
000007a0:·5844·206f·7220·4e58·2062·6974·2c20·7468··XD·or·NX·bit,·th 
000007b0:·6520·7665·6e64·6f72·2d73·7570·706c·6965··e·vendor-supplie 
000007c0:·640a·5041·4520·6b65·726e·656c·2069·7320··d.PAE·kernel·is· 
000007d0:·7265·7175·6972·6564·2074·6f20·656e·6162··required·to·enab 
000007e0:·6c65·2065·6974·6865·7220·4578·6563·7574··le·either·Execut 
000007f0:·6520·4469·7361·626c·6520·2858·4429·206f··e·Disable·(XD)·o 
00000800:·7220·4e6f·2045·7865·6375·7465·2028·4e58··r·No·Execute·(NX 
00000810:·2920·7375·7070·6f72·742e·0a20·2020·2020··)·support..····· 
00000820:·203c·2f74·643e·0a20·2020·203c·2f74·723e···</td>.····</tr>000004c0:·2053·4d41·5020·6973·2075·7365·6420·746f···SMAP·is·used·to
 000004d0:·2070·7265·7665·6e74·2074·6865·2073·7570···prevent·the·sup
 000004e0:·6572·7669·736f·7220·6d6f·6465·2066·726f··ervisor·mode·fro
 000004f0:·6d20·756e·696e·7465·6e74·696f·6e61·6c6c··m·unintentionall
 00000500:·7920·7265·6164·696e·672f·7772·6974·696e··y·reading/writin
 00000510:·6720·696e·746f·0a6d·656d·6f72·7920·7061··g·into.memory·pa
 00000520:·6765·7320·696e·2074·6865·2075·7365·7220··ges·in·the·user·
 00000530:·7370·6163·652c·2069·7420·6973·2065·6e61··space,·it·is·ena
 00000540:·626c·6564·2062·7920·6465·6661·756c·7420··bled·by·default·
 00000550:·7369·6e63·6520·4c69·6e75·7820·6b65·726e··since·Linux·kern
 00000560:·656c·2033·2e37·2e0a·4275·7420·6974·2063··el·3.7..But·it·c
 00000570:·6f75·6c64·2062·6520·6469·7361·626c·6564··ould·be·disabled
 00000580:·2074·6872·6f75·6768·206b·6572·6e65·6c20···through·kernel·
 00000590:·626f·6f74·2070·6172·616d·6574·6572·732e··boot·parameters.
 000005a0:·0a0a·456e·7375·7265·2074·6861·7420·5375··..Ensure·that·Su
 000005b0:·7065·7276·6973·6f72·204d·6f64·6520·4163··pervisor·Mode·Ac
 000005c0:·6365·7373·2050·7265·7665·6e74·696f·6e20··cess·Prevention·
 000005d0:·2853·4d41·5029·2069·7320·6e6f·7420·6469··(SMAP)·is·not·di
 000005e0:·7361·626c·6564·2062·790a·7468·6520·3c74··sabled·by.the·<t
 000005f0:·743e·6e6f·736d·6170·3c2f·7474·3e20·626f··t>nosmap</tt>·bo
 00000600:·6f74·2070·6172·616d·656e·7465·7220·6f70··ot·paramenter·op
 00000610:·7469·6f6e·2e0a·0a43·6865·636b·2074·6861··tion...Check·tha
 00000620:·7420·7468·6520·6c69·6e65·203c·7072·653e··t·the·line·<pre>
 00000630:·4752·5542·5f43·4d44·4c49·4e45·5f4c·494e··GRUB_CMDLINE_LIN
 00000640:·5558·3d22·2e2e·2e22·3c2f·7072·653e·2077··UX="..."</pre>·w
 00000650:·6974·6869·6e20·3c74·743e·2f65·7463·2f64··ithin·<tt>/etc/d
 00000660:·6566·6175·6c74·2f67·7275·623c·2f74·743e··efault/grub</tt>
 00000670:·0a64·6f65·736e·2774·2063·6f6e·7461·696e··.doesn't·contain
 00000680:·2074·6865·2061·7267·756d·656e·7420·3c74···the·argument·<t
 00000690:·743e·6e6f·736d·6170·3c2f·7474·3e2e·0a52··t>nosmap</tt>..R
 000006a0:·756e·2074·6865·2066·6f6c·6c6f·7769·6e67··un·the·following
 000006b0:·2063·6f6d·6d61·6e64·2074·6f20·7570·6461···command·to·upda
 000006c0:·7465·2063·6f6d·6d61·6e64·206c·696e·6520··te·command·line·
 000006d0:·666f·7220·616c·7265·6164·7920·696e·7374··for·already·inst
 000006e0:·616c·6c65·6420·6b65·726e·656c·733a·0a3c··alled·kernels:.<
 000006f0:·7072·653e·2320·6772·7562·6279·202d·2d75··pre>#·grubby·--u
 00000700:·7064·6174·652d·6b65·726e·656c·3d41·4c4c··pdate-kernel=ALL
 00000710:·202d·2d72·656d·6f76·652d·6172·6773·3d22···--remove-args="
 00000720:·6e6f·736d·6170·223c·2f70·7265·3e0a·2020··nosmap"</pre>.··
00000830:·0a20·2020·203c·7472·3e0a·2020·2020·2020··.····<tr>.······00000730:·2020·2020·3c2f·7464·3e0a·2020·2020·2020······</td>.······
 00000740:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
 00000750:·2d55·5322·3e0a·2020·2020·2020·2020·4469··-US">.········Di
 00000760:·7361·626c·696e·6720·534d·4150·2063·616e··sabling·SMAP·can
 00000770:·2066·6163·696c·6974·6174·6520·6578·706c···facilitate·expl
 00000780:·6f69·7461·7469·6f6e·206f·6620·7675·6c6e··oitation·of·vuln
 00000790:·6572·6162·696c·6974·6965·7320·6361·7573··erabilities·caus
 000007a0:·6564·2062·7920·756e·696e·7465·6e64·6564··ed·by·unintended
 000007b0:·2061·6363·6573·7320·616e·640a·6d61·6e69···access·and.mani
 000007c0:·7075·6c61·7469·6f6e·206f·6620·6461·7461··pulation·of·data
 000007d0:·2069·6e20·7468·6520·7573·6572·2073·7061···in·the·user·spa
 000007e0:·6365·2e0a·2020·2020·2020·3c2f·7464·3e0a··ce..······</td>.
 000007f0:·2020·2020·3c2f·7472·3e0a·2020·2020·3c74······</tr>.····<t
 00000800:·723e·0a20·2020·2020·203c·7464·3e52·313c··r>.······<td>R1<
 00000810:·2f74·643e·0a20·2020·2020·203c·7464·3e49··/td>.······<td>I
 00000820:·6e73·7461·6c6c·2074·6865·2064·7261·6375··nstall·the·dracu
 00000830:·742d·6669·7073·2d61·6573·6e69·2050·6163··t-fips-aesni·Pac
 00000840:·6b61·6765·3c2f·7464·3e0a·2020·2020·2020··kage</td>.······
 00000850:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en
Max diff block lines reached; 2979097/3015551 bytes (98.79%) of diff not shown.
671 KB
html2text {}
Max HTML report size reached
1.45 MB
./usr/share/doc/ssg-nondebian/table-rhel8-cisrefs.html
    
Offset 1623, 138 lines modifiedOffset 1623, 138 lines modified
00006560:·6520·7468·6520·7379·7374·656d·2074·6f20··e·the·system·to·00006560:·6520·7468·6520·7379·7374·656d·2074·6f20··e·the·system·to·
00006570:·706f·7465·6e74·6961·6c20·636f·6d70·726f··potential·compro00006570:·706f·7465·6e74·6961·6c20·636f·6d70·726f··potential·compro
00006580:·6d69·7365·2e0a·2020·2020·2020·3c2f·7464··mise..······</td00006580:·6d69·7365·2e0a·2020·2020·2020·3c2f·7464··mise..······</td
00006590:·3e0a·2020·2020·3c2f·7472·3e0a·2020·2020··>.····</tr>.····00006590:·3e0a·2020·2020·3c2f·7472·3e0a·2020·2020··>.····</tr>.····
000065a0:·3c74·723e·0a20·2020·2020·203c·7464·3e31··<tr>.······<td>1000065a0:·3c74·723e·0a20·2020·2020·203c·7464·3e31··<tr>.······<td>1
000065b0:·2e32·2e32·3c2f·7464·3e0a·2020·2020·2020··.2.2</td>.······000065b0:·2e32·2e32·3c2f·7464·3e0a·2020·2020·2020··.2.2</td>.······
000065c0:·3c74·643e·456e·7375·7265·2067·7067·6368··<td>Ensure·gpgch000065c0:·3c74·643e·456e·7375·7265·2067·7067·6368··<td>Ensure·gpgch
000065d0:·6563·6b20·456e·6162·6c65·6420·666f·7220··eck·Enabled·for·000065d0:·6563·6b20·456e·6162·6c65·6420·496e·204d··eck·Enabled·In·M
 000065e0:·6169·6e20·7975·6d20·436f·6e66·6967·7572··ain·yum·Configur
 000065f0:·6174·696f·6e3c·2f74·643e·0a20·2020·2020··ation</td>.·····
 00006600:·203c·7464·2078·6d6c·3a6c·616e·673d·2265···<td·xml:lang="e
000065e0:·416c·6c20·7975·6d20·5061·636b·6167·6520··All·yum·Package· 
000065f0:·5265·706f·7369·746f·7269·6573·3c2f·7464··Repositories</td 
00006600:·3e0a·2020·2020·2020·3c74·6420·786d·6c3a··>.······<td·xml: 
00006610:·6c61·6e67·3d22·656e·2d55·5322·3e0a·2020··lang="en-US">.·· 
00006620:·2020·2020·2020·546f·2065·6e73·7572·6520········To·ensure· 
00006630:·7369·676e·6174·7572·6520·6368·6563·6b69··signature·checki 
00006640:·6e67·2069·7320·6e6f·7420·6469·7361·626c··ng·is·not·disabl 
00006650:·6564·2066·6f72·0a61·6e79·2072·6570·6f73··ed·for.any·repos 
00006660:·2c20·7265·6d6f·7665·2061·6e79·206c·696e··,·remove·any·lin 
00006670:·6573·2066·726f·6d20·6669·6c65·7320·696e··es·from·files·in 
00006680:·203c·7474·3e2f·6574·632f·7975·6d2e·7265···<tt>/etc/yum.re 
00006690:·706f·732e·643c·2f74·743e·206f·6620·7468··pos.d</tt>·of·th 
000066a0:·6520·666f·726d·3a0a·3c70·7265·3e67·7067··e·form:.<pre>gpg 
000066b0:·6368·6563·6b3d·303c·2f70·7265·3e0a·2020··check=0</pre>.·· 
000066c0:·2020·2020·3c2f·7464·3e0a·2020·2020·2020······</td>.······ 
000066d0:·3c74·6420·786d·6c3a·6c61·6e67·3d22·656e··<td·xml:lang="en 
000066e0:·2d55·5322·3e0a·2020·2020·2020·2020·5665··-US">.········Ve00006610:·6e2d·5553·223e·0a20·2020·2020·2020·2054··n-US">.········T
000066f0:·7269·6679·696e·6720·7468·6520·6175·7468··rifying·the·auth 
00006700:·656e·7469·6369·7479·206f·6620·7468·6520··enticity·of·the· 
00006710:·736f·6674·7761·7265·2070·7269·6f72·2074··software·prior·t00006620:·6865·203c·7474·3e67·7067·6368·6563·6b3c··he·<tt>gpgcheck<
 00006630:·2f74·743e·206f·7074·696f·6e20·636f·6e74··/tt>·option·cont
 00006640:·726f·6c73·2077·6865·7468·6572·0a52·504d··rols·whether.RPM
 00006650:·2070·6163·6b61·6765·7327·2073·6967·6e61···packages'·signa
 00006660:·7475·7265·7320·6172·6520·616c·7761·7973··tures·are·always
 00006670:·2063·6865·636b·6564·2070·7269·6f72·2074···checked·prior·t
00006720:·6f20·696e·7374·616c·6c61·7469·6f6e·2076··o·installation·v00006680:·6f20·696e·7374·616c·6c61·7469·6f6e·2e0a··o·installation..
 00006690:·546f·2063·6f6e·6669·6775·7265·2079·756d··To·configure·yum
 000066a0:·2074·6f20·6368·6563·6b20·7061·636b·6167···to·check·packag
 000066b0:·6520·7369·676e·6174·7572·6573·2062·6566··e·signatures·bef
 000066c0:·6f72·6520·696e·7374·616c·6c69·6e67·0a74··ore·installing.t
 000066d0:·6865·6d2c·2065·6e73·7572·6520·7468·6520··hem,·ensure·the·
 000066e0:·666f·6c6c·6f77·696e·6720·6c69·6e65·2061··following·line·a
 000066f0:·7070·6561·7273·2069·6e20·3c74·743e·2f65··ppears·in·<tt>/e
 00006700:·7463·2f79·756d·2e63·6f6e·663c·2f74·743e··tc/yum.conf</tt>
 00006710:·2069·6e0a·7468·6520·3c74·743e·5b6d·6169···in.the·<tt>[mai
 00006720:·6e5d·3c2f·7474·3e20·7365·6374·696f·6e3a··n]</tt>·section:
 00006730:·0a3c·7072·653e·6770·6763·6865·636b·3d31··.<pre>gpgcheck=1
 00006740:·3c2f·7072·653e·0a20·2020·2020·203c·2f74··</pre>.······</t
 00006750:·643e·0a20·2020·2020·203c·7464·2078·6d6c··d>.······<td·xml
 00006760:·3a6c·616e·673d·2265·6e2d·5553·223e·0a20··:lang="en-US">.·
 00006770:·2020·2020·2020·2043·6861·6e67·6573·2074·········Changes·t
 00006780:·6f20·616e·7920·736f·6674·7761·7265·2063··o·any·software·c
 00006790:·6f6d·706f·6e65·6e74·7320·6361·6e20·6861··omponents·can·ha
 000067a0:·7665·2073·6967·6e69·6669·6361·6e74·2065··ve·significant·e
 000067b0:·6666·6563·7473·206f·6e20·7468·650a·6f76··ffects·on·the.ov
 000067c0:·6572·616c·6c20·7365·6375·7269·7479·206f··erall·security·o
 000067d0:·6620·7468·6520·6f70·6572·6174·696e·6720··f·the·operating·
 000067e0:·7379·7374·656d·2e20·5468·6973·2072·6571··system.·This·req
 000067f0:·7569·7265·6d65·6e74·2065·6e73·7572·6573··uirement·ensures
 00006800:·2074·6865·0a73·6f66·7477·6172·6520·6861···the.software·ha
 00006810:·7320·6e6f·7420·6265·656e·2074·616d·7065··s·not·been·tampe
 00006820:·7265·6420·7769·7468·2061·6e64·2074·6861··red·with·and·tha
 00006830:·7420·6974·2068·6173·2062·6565·6e20·7072··t·it·has·been·pr
 00006840:·6f76·6964·6564·2062·7920·610a·7472·7573··ovided·by·a.trus
 00006850:·7465·6420·7665·6e64·6f72·2e0a·3c62·7220··ted·vendor..<br·
 00006860:·2f3e·0a41·6363·6f72·6469·6e67·6c79·2c20··/>.Accordingly,·
 00006870:·7061·7463·6865·732c·2073·6572·7669·6365··patches,·service
 00006880:·2070·6163·6b73·2c20·6465·7669·6365·2064···packs,·device·d
 00006890:·7269·7665·7273·2c20·6f72·206f·7065·7261··rivers,·or·opera
 000068a0:·7469·6e67·2073·7973·7465·6d0a·636f·6d70··ting·system.comp
 000068b0:·6f6e·656e·7473·206d·7573·7420·6265·2073··onents·must·be·s
 000068c0:·6967·6e65·6420·7769·7468·2061·2063·6572··igned·with·a·cer
 000068d0:·7469·6669·6361·7465·2072·6563·6f67·6e69··tificate·recogni
 000068e0:·7a65·6420·616e·6420·6170·7072·6f76·6564··zed·and·approved
 000068f0:·2062·7920·7468·650a·6f72·6761·6e69·7a61···by·the.organiza
 00006900:·7469·6f6e·2e0a·3c62·7220·2f3e·5665·7269··tion..<br·/>Veri
 00006910:·6679·696e·6720·7468·6520·6175·7468·656e··fying·the·authen
 00006920:·7469·6369·7479·206f·6620·7468·6520·736f··ticity·of·the·so
 00006930:·6674·7761·7265·2070·7269·6f72·2074·6f20··ftware·prior·to·
 00006940:·696e·7374·616c·6c61·7469·6f6e·0a76·616c··installation.val
00006730:·616c·6964·6174·6573·0a74·6865·2069·6e74··alidates.the·int00006950:·6964·6174·6573·2074·6865·2069·6e74·6567··idates·the·integ
00006740:·6567·7269·7479·206f·6620·7468·6520·7061··egrity·of·the·pa00006960:·7269·7479·206f·6620·7468·6520·7061·7463··rity·of·the·patc
00006750:·7463·6820·6f72·2075·7067·7261·6465·2072··tch·or·upgrade·r00006970:·6820·6f72·2075·7067·7261·6465·2072·6563··h·or·upgrade·rec
00006760:·6563·6569·7665·6420·6672·6f6d·2061·2076··eceived·from·a·v00006980:·6569·7665·6420·6672·6f6d·2061·2076·656e··eived·from·a·ven
00006770:·656e·646f·722e·2054·6869·7320·656e·7375··endor.·This·ensu00006990:·646f·722e·0a54·6869·7320·656e·7375·7265··dor..This·ensure
00006780:·7265·730a·7468·6520·736f·6674·7761·7265··res.the·software000069a0:·7320·7468·6520·736f·6674·7761·7265·2068··s·the·software·h
00006790:·2068·6173·206e·6f74·2062·6565·6e20·7461···has·not·been·ta000069b0:·6173·206e·6f74·2062·6565·6e20·7461·6d70··as·not·been·tamp
000067a0:·6d70·6572·6564·2077·6974·6820·616e·6420··mpered·with·and·000069c0:·6572·6564·2077·6974·6820·616e·6420·7468··ered·with·and·th
000067b0:·7468·6174·2069·7420·6861·7320·6265·656e··that·it·has·been000069d0:·6174·2069·7420·6861·7320·6265·656e·0a70··at·it·has·been.p
000067c0:·2070·726f·7669·6465·6420·6279·2061·0a74···provided·by·a.t000069e0:·726f·7669·6465·6420·6279·2061·2074·7275··rovided·by·a·tru
000067d0:·7275·7374·6564·2076·656e·646f·722e·2053··rusted·vendor.·S000069f0:·7374·6564·2076·656e·646f·722e·2053·656c··sted·vendor.·Sel
000067e0:·656c·662d·7369·676e·6564·2063·6572·7469··elf-signed·certi00006a00:·662d·7369·676e·6564·2063·6572·7469·6669··f-signed·certifi
000067f0:·6669·6361·7465·7320·6172·6520·6469·7361··ficates·are·disa00006a10:·6361·7465·7320·6172·6520·6469·7361·6c6c··cates·are·disall
00006800:·6c6c·6f77·6564·2062·7920·7468·6973·0a72··llowed·by·this.r00006a20:·6f77·6564·2062·790a·7468·6973·2072·6571··owed·by.this·req
00006810:·6571·7569·7265·6d65·6e74·2e20·4365·7274··equirement.·Cert00006a30:·7569·7265·6d65·6e74·2e20·4365·7274·6966··uirement.·Certif
00006820:·6966·6963·6174·6573·2075·7365·6420·746f··ificates·used·to00006a40:·6963·6174·6573·2075·7365·6420·746f·2076··icates·used·to·v
00006830:·2076·6572·6966·7920·7468·6520·736f·6674···verify·the·soft00006a50:·6572·6966·7920·7468·6520·736f·6674·7761··erify·the·softwa
00006840:·7761·7265·206d·7573·7420·6265·2066·726f··ware·must·be·fro00006a60:·7265·206d·7573·7420·6265·2066·726f·6d20··re·must·be·from·
00006850:·6d20·616e·0a61·7070·726f·7665·6420·4365··m·an.approved·Ce00006a70:·616e·0a61·7070·726f·7665·6420·4365·7274··an.approved·Cert
00006860:·7274·6966·6963·6174·6520·4175·7468·6f72··rtificate·Author00006a80:·6966·6963·6174·6520·4175·7468·6f72·6974··ificate·Authorit
00006870:·6974·7920·2843·4129·2e22·0a20·2020·2020··ity·(CA).".·····00006a90:·7920·2843·4129·2e0a·2020·2020·2020·3c2f··y·(CA)..······</
 00006aa0:·7464·3e0a·2020·2020·3c2f·7472·3e0a·2020··td>.····</tr>.··
00006880:·203c·2f74·643e·0a20·2020·203c·2f74·723e···</td>.····</tr> 
00006890:·0a20·2020·203c·7472·3e0a·2020·2020·2020··.····<tr>.······ 
000068a0:·3c74·643e·312e·322e·323c·2f74·643e·0a20··<td>1.2.2</td>.· 
000068b0:·2020·2020·203c·7464·3e45·6e73·7572·6520·······<td>Ensure· 
000068c0:·6770·6763·6865·636b·2045·6e61·626c·6564··gpgcheck·Enabled 
000068d0:·2049·6e20·4d61·696e·2079·756d·2043·6f6e···In·Main·yum·Con 
000068e0:·6669·6775·7261·7469·6f6e·3c2f·7464·3e0a··figuration</td>. 
000068f0:·2020·2020·2020·3c74·6420·786d·6c3a·6c61········<td·xml:la 
00006900:·6e67·3d22·656e·2d55·5322·3e0a·2020·2020··ng="en-US">.···· 
00006910:·2020·2020·5468·6520·3c74·743e·6770·6763······The·<tt>gpgc 
00006920:·6865·636b·3c2f·7474·3e20·6f70·7469·6f6e··heck</tt>·option 
00006930:·2063·6f6e·7472·6f6c·7320·7768·6574·6865···controls·whethe 
00006940:·720a·5250·4d20·7061·636b·6167·6573·2720··r.RPM·packages'· 
00006950:·7369·676e·6174·7572·6573·2061·7265·2061··signatures·are·a 
00006960:·6c77·6179·7320·6368·6563·6b65·6420·7072··lways·checked·pr 
00006970:·696f·7220·746f·2069·6e73·7461·6c6c·6174··ior·to·installat 
00006980:·696f·6e2e·0a54·6f20·636f·6e66·6967·7572··ion..To·configur 
00006990:·6520·7975·6d20·746f·2063·6865·636b·2070··e·yum·to·check·p 
000069a0:·6163·6b61·6765·2073·6967·6e61·7475·7265··ackage·signature 
000069b0:·7320·6265·666f·7265·2069·6e73·7461·6c6c··s·before·install 
000069c0:·696e·670a·7468·656d·2c20·656e·7375·7265··ing.them,·ensure 
000069d0:·2074·6865·2066·6f6c·6c6f·7769·6e67·206c···the·following·l 
000069e0:·696e·6520·6170·7065·6172·7320·696e·203c··ine·appears·in·< 
000069f0:·7474·3e2f·6574·632f·7975·6d2e·636f·6e66··tt>/etc/yum.conf 
Max diff block lines reached; 1140555/1158245 bytes (98.47%) of diff not shown.
349 KB
html2text {}
    
Offset 367, 37 lines modifiedOffset 367, 14 lines modified
367 ··················Add·noexec·Option···binaries·from·being·executed·out·of·/var/log/audit.····files·such·as·/var/367 ··················Add·noexec·Option···binaries·from·being·executed·out·of·/var/log/audit.····files·such·as·/var/
368 1.1.2.7.4·········to·/var/log/audit···Add·the·noexec·option·to·the·fourth·column·of·/etc/····log/audit·should368 1.1.2.7.4·········to·/var/log/audit···Add·the·noexec·option·to·the·fourth·column·of·/etc/····log/audit·should
369 ······································fstab·for·the·line·which·controls·mounting·of·/var/····never·be·necessary369 ······································fstab·for·the·line·which·controls·mounting·of·/var/····never·be·necessary
370 ······································log/audit.·············································in·normal·operation370 ······································log/audit.·············································in·normal·operation
371 ·····························································································and·can·expose·the371 ·····························································································and·can·expose·the
372 ·····························································································system·to·potential372 ·····························································································system·to·potential
373 ·····························································································compromise.373 ·····························································································compromise.
374 ·····························································································Verifying·the 
375 ·····························································································authenticity·of·the 
376 ·····························································································software·prior·to 
377 ·····························································································installation 
378 ·····························································································validates·the 
379 ·····························································································integrity·of·the 
380 ·····························································································patch·or·upgrade 
381 ·····························································································received·from·a 
382 ·····························································································vendor.·This·ensures 
383 ··················Ensure·gpgcheck·····To·ensure·signature·checking·is·not·disabled·for·any···the·software·has·not 
384 ··················Enabled·for·All·yum·repos,·remove·any·lines·from·files·in·/etc/yum.repos.d·been·tampered·with 
385 1.2.2·············Package·············of·the·form:···········································and·that·it·has·been 
386 ··················Repositories········gpgcheck=0·············································provided·by·a 
387 ·····························································································trusted·vendor. 
388 ·····························································································Self-signed 
389 ·····························································································certificates·are 
390 ·····························································································disallowed·by·this 
391 ·····························································································requirement. 
392 ·····························································································Certificates·used·to 
393 ·····························································································verify·the·software 
394 ·····························································································must·be·from·an 
395 ·····························································································approved·Certificate 
396 ·····························································································Authority·(CA)." 
397 ·····························································································Changes·to·any374 ·····························································································Changes·to·any
398 ·····························································································software·components375 ·····························································································software·components
399 ·····························································································can·have·significant376 ·····························································································can·have·significant
400 ·····························································································effects·on·the377 ·····························································································effects·on·the
401 ·····························································································overall·security·of378 ·····························································································overall·security·of
402 ·····························································································the·operating379 ·····························································································the·operating
403 ·····························································································system.·This380 ·····························································································system.·This
Offset 437, 14 lines modifiedOffset 414, 37 lines modified
437 ·····························································································disallowed·by·this414 ·····························································································disallowed·by·this
438 ·····························································································requirement.415 ·····························································································requirement.
439 ·····························································································Certificates·used·to416 ·····························································································Certificates·used·to
440 ·····························································································verify·the·software417 ·····························································································verify·the·software
441 ·····························································································must·be·from·an418 ·····························································································must·be·from·an
442 ·····························································································approved·Certificate419 ·····························································································approved·Certificate
443 ·····························································································Authority·(CA).420 ·····························································································Authority·(CA).
 421 ·····························································································Verifying·the
 422 ·····························································································authenticity·of·the
 423 ·····························································································software·prior·to
 424 ·····························································································installation
 425 ·····························································································validates·the
 426 ·····························································································integrity·of·the
 427 ·····························································································patch·or·upgrade
 428 ·····························································································received·from·a
 429 ·····························································································vendor.·This·ensures
 430 ··················Ensure·gpgcheck·····To·ensure·signature·checking·is·not·disabled·for·any···the·software·has·not
 431 ··················Enabled·for·All·yum·repos,·remove·any·lines·from·files·in·/etc/yum.repos.d·been·tampered·with
 432 1.2.2·············Package·············of·the·form:···········································and·that·it·has·been
 433 ··················Repositories········gpgcheck=0·············································provided·by·a
 434 ·····························································································trusted·vendor.
 435 ·····························································································Self-signed
 436 ·····························································································certificates·are
 437 ·····························································································disallowed·by·this
 438 ·····························································································requirement.
 439 ·····························································································Certificates·used·to
 440 ·····························································································verify·the·software
 441 ·····························································································must·be·from·an
 442 ·····························································································approved·Certificate
 443 ·····························································································Authority·(CA)."
444 ·····························································································Password·protection444 ·····························································································Password·protection
445 ······································The·grub2·boot·loader·should·have·a·superuser·account··on·the·boot·loader445 ······································The·grub2·boot·loader·should·have·a·superuser·account··on·the·boot·loader
446 ······································and·password·protection·enabled·to·protect·boot-time···configuration446 ······································and·password·protection·enabled·to·protect·boot-time···configuration
447 ······································settings.··············································ensures·users·with447 ······································settings.··············································ensures·users·with
448 ·····························································································physical·access448 ·····························································································physical·access
449 1.3.1·············Set·Boot·Loader·····Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially449 1.3.1·············Set·Boot·Loader·····Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially
450 ··················Password·in·grub2···generate·a·hash·for·the·password·by·running·the········alter·important450 ··················Password·in·grub2···generate·a·hash·for·the·password·by·running·the········alter·important
Offset 461, 36 lines modifiedOffset 461, 26 lines modified
461 1.3.1·············Set·the·UEFI·Boot···Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially461 1.3.1·············Set·the·UEFI·Boot···Since·plaintext·passwords·are·a·security·risk,·········cannot·trivially
462 ··················Loader·Password·····generate·a·hash·for·the·password·by·running·the········alter·important462 ··················Loader·Password·····generate·a·hash·for·the·password·by·running·the········alter·important
463 ······································following·command:·····································bootloader·settings.463 ······································following·command:·····································bootloader·settings.
464 ······································#·grub2-setpassword····································These·include·which464 ······································#·grub2-setpassword····································These·include·which
465 ······································When·prompted,·enter·the·password·that·was·selected.···kernel·to·use,·and465 ······································When·prompted,·enter·the·password·that·was·selected.···kernel·to·use,·and
466 ·····························································································whether·to·enter466 ·····························································································whether·to·enter
467 ·····························································································single-user·mode.467 ·····························································································single-user·mode.
468 ······································File·permissions·for·/boot/grub2/grub.cfg·should·be····Proper·permissions 
469 ··················Verify·/boot/grub2/·set·to·600.·To·properly·set·the·permissions·of·/boot/··ensure·that·only·the 
470 1.3.2·············grub.cfg············grub2/grub.cfg,·run·the·command:·······················root·user·can·modify 
471 ··················Permissions·········$·sudo·chmod·600·/boot/grub2/grub.cfg··················important·boot468 ······································The·file·/boot/efi/EFI/redhat/grub.cfg·should·be·······The·root·group·is·a
 469 ··················Verify·the·UEFI·····group-owned·by·the·root·group·to·prevent·destruction···highly-privileged
 470 ··················Boot·Loader·········or·modification·of·the·file.·To·properly·set·the·group·group.·Furthermore,
 471 1.3.2·············grub.cfg·Group······owner·of·/boot/efi/EFI/redhat/grub.cfg,·run·the········the·group-owner·of
 472 ··················Ownership···········command:···············································this·file·should·not
 473 ······································$·sudo·chgrp·root·/boot/efi/EFI/redhat/grub.cfg········have·any·access
472 ·····························································································parameters.474 ·····························································································privileges·anyway.
473 ······································The·file·/boot/grub2/grub.cfg·should·be·owned·by·the···Only·root·should·be475 ······································The·file·/boot/grub2/grub.cfg·should·be·owned·by·the···Only·root·should·be
474 ··················Verify·/boot/grub2/·root·user·to·prevent·destruction·or·modification·of····able·to·modify476 ··················Verify·/boot/grub2/·root·user·to·prevent·destruction·or·modification·of····able·to·modify
475 1.3.2·············grub.cfg·User·······the·file.·To·properly·set·the·owner·of·/boot/grub2/····important·boot477 1.3.2·············grub.cfg·User·······the·file.·To·properly·set·the·owner·of·/boot/grub2/····important·boot
476 ··················Ownership···········grub.cfg,·run·the·command:·····························parameters.478 ··················Ownership···········grub.cfg,·run·the·command:·····························parameters.
477 ······································$·sudo·chown·root·/boot/grub2/grub.cfg479 ······································$·sudo·chown·root·/boot/grub2/grub.cfg
478 ·····························································································Only·root·should·be 
479 ·····························································································able·to·modify 
480 ·····························································································important·boot 
481 ······································The·file·/boot/grub2/user.cfg·should·be·owned·by·the···parameters.·Also, 
482 ··················Verify·/boot/grub2/·root·user·to·prevent·reading·or·modification·of·the····non-root·users·who 
483 1.3.2·············user.cfg·User·······file.·To·properly·set·the·owner·of·/boot/grub2/········read·the·boot 
484 ··················Ownership···········user.cfg,·run·the·command:·····························parameters·may·be 
485 ······································$·sudo·chown·root·/boot/grub2/user.cfg·················able·to·identify 
486 ·····························································································weaknesses·in 
487 ·····························································································security·upon·boot 
488 ·····························································································and·be·able·to 
489 ·····························································································exploit·them. 
490 ·····························································································The·root·group·is·a480 ·····························································································The·root·group·is·a
491 ·····························································································highly-privileged481 ·····························································································highly-privileged
492 ·····························································································group.·Furthermore,482 ·····························································································group.·Furthermore,
493 ·····························································································the·group-owner·of483 ·····························································································the·group-owner·of
494 ·····························································································this·file·should·not484 ·····························································································this·file·should·not
495 ······································The·file·/boot/grub2/user.cfg·should·be·group-owned·by·have·any·access485 ······································The·file·/boot/grub2/user.cfg·should·be·group-owned·by·have·any·access
496 ··················Verify·/boot/grub2/·the·root·group·to·prevent·reading·or·modification·of···privileges·anyway.486 ··················Verify·/boot/grub2/·the·root·group·to·prevent·reading·or·modification·of···privileges·anyway.
Offset 498, 29 lines modifiedOffset 488, 60 lines modified
498 ··················Ownership···········grub2/user.cfg,·run·the·command:·······················read·the·boot488 ··················Ownership···········grub2/user.cfg,·run·the·command:·······················read·the·boot
499 ······································$·sudo·chgrp·root·/boot/grub2/user.cfg·················parameters·may·be489 ······································$·sudo·chgrp·root·/boot/grub2/user.cfg·················parameters·may·be
500 ·····························································································able·to·identify490 ·····························································································able·to·identify
501 ·····························································································weaknesses·in491 ·····························································································weaknesses·in
502 ·····························································································security·upon·boot492 ·····························································································security·upon·boot
503 ·····························································································and·be·able·to493 ·····························································································and·be·able·to
504 ·····························································································exploit·them.494 ·····························································································exploit·them.
505 ··················Verify·the·UEFI·····The·file·/boot/efi/EFI/redhat/grub.cfg·should·be·owned·Only·root·should·be 
506 ··················Boot·Loader·········by·the·root·user·to·prevent·destruction·or·············able·to·modify 
Max diff block lines reached; 342528/357824 bytes (95.73%) of diff not shown.
1.26 MB
./usr/share/doc/ssg-nondebian/table-rhel8-cuirefs.html
Ordering differences only
    
Offset 41, 78 lines modifiedOffset 41, 30 lines modified
41 ····<th>Rule·Title</th>41 ····<th>Rule·Title</th>
42 ····<th>Description</th>42 ····<th>Description</th>
43 ····<th>Rationale</th>43 ····<th>Rationale</th>
44 ··</thead>44 ··</thead>
45 ··<tbody>45 ··<tbody>
46 ··<tr>46 ··<tr>
47 ······<td>3.1.1<br/>3.1.5</td>47 ······<td>3.1.1<br/>3.1.5</td>
 48 ······<td>Prevent·Login·to·Accounts·With·Empty·Password</td>
48 ······<td>Verify·Only·Root·Has·UID·0</td> 
49 ······<td·xml:lang="en-US"> 
50 ········If·any·account·other·than·root·has·a·UID·of·0,·this·misconfiguration·should 
51 be·investigated·and·the·accounts·other·than·root·should·be·removed·or·have 
52 their·UID·changed. 
53 <br·/> 
54 If·the·account·is·associated·with·system·commands·or·applications·the·UID 
55 should·be·changed·to·one·greater·than·"0"·but·less·than·"1000." 
56 Otherwise·assign·a·UID·greater·than·"1000"·that·has·not·already·been 
57 assigned. 
58 ······</td> 
59 ······<td·xml:lang="en-US"> 
60 ········An·account·has·root·authority·if·it·has·a·UID·of·0.·Multiple·accounts 
61 with·a·UID·of·0·afford·more·opportunity·for·potential·intruders·to 
62 guess·a·password·for·a·privileged·account.·Proper·configuration·of 
63 sudo·is·recommended·to·afford·multiple·system·administrators 
64 access·to·root·privileges·in·an·accountable·manner. 
65 ······</td> 
66 ····</tr> 
67 ····<tr> 
68 ······<td>3.1.1<br/>3.1.6</td> 
69 ······<td>Direct·root·Logins·Not·Allowed</td> 
70 ······<td·xml:lang="en-US"> 
71 ········To·further·limit·access·to·the·<tt>root</tt>·account,·administrators 
72 can·disable·root·logins·at·the·console·by·editing·the·<tt>/etc/securetty</tt>·file. 
73 This·file·lists·all·devices·the·root·user·is·allowed·to·login·to.·If·the·file·does 
74 not·exist·at·all,·the·root·user·can·login·through·any·communication·device·on·the 
75 system,·whether·via·the·console·or·via·a·raw·network·interface.·This·is·dangerous 
76 as·user·can·login·to·the·system·as·root·via·Telnet,·which·sends·the·password·in 
77 plain·text·over·the·network.·By·default,·Red·Hat·Enterprise·Linux·8's 
78 <tt>/etc/securetty</tt>·file·only·allows·the·root·user·to·login·at·the·console 
79 physically·attached·to·the·system.·To·prevent·root·from·logging·in,·remove·the 
80 contents·of·this·file.·To·prevent·direct·root·logins,·remove·the·contents·of·this 
81 file·by·typing·the·following·command: 
82 <pre> 
83 $·sudo·echo·&gt;·/etc/securetty 
84 </pre> 
85 ······</td> 
86 ······<td·xml:lang="en-US"> 
87 ········Disabling·direct·root·logins·ensures·proper·accountability·and·multifactor 
88 authentication·to·privileged·accounts.·Users·will·first·login,·then·escalate 
89 to·privileged·(root)·access·via·su·/·sudo.·This·is·required·for·FISMA·Low 
90 and·FISMA·Moderate·systems. 
91 ······</td> 
92 ····</tr> 
93 ····<tr> 
94 ······<td>3.1.1<br/>3.1.5</td> 
95 ······<td>Disable·SSH·Root·Login</td> 
96 ······<td·xml:lang="en-US">49 ······<td·xml:lang="en-US">
97 ········The·root·user·should·never·be·allowed·to·login·to·a 
98 system·directly·over·a·network. 
99 To·disable·root·login·via·SSH,·add·or·correct·the·following·line·in 
 50 ········If·an·account·is·configured·for·password·authentication
 51 but·does·not·have·an·assigned·password,·it·may·be·possible·to·log
 52 into·the·account·without·authentication.·Remove·any·instances·of·the
 53 <tt>nullok</tt>·in
  
100 <tt>/etc/ssh/sshd_config</tt>:54 <tt>/etc/pam.d/system-auth</tt>·and
 55 <tt>/etc/pam.d/password-auth</tt>
  
101 <pre>PermitRootLogin·no</pre>56 to·prevent·logins·with·empty·passwords.
102 ······</td>57 ······</td>
103 ······<td·xml:lang="en-US">58 ······<td·xml:lang="en-US">
 59 ········If·an·account·has·an·empty·password,·anyone·could·log·in·and
 60 run·commands·with·the·privileges·of·that·account.·Accounts·with
 61 empty·passwords·should·never·be·used·in·operational·environments.
104 ········Even·though·the·communications·channel·may·be·encrypted,·an·additional·layer·of 
105 security·is·gained·by·extending·the·policy·of·not·logging·directly·on·as·root. 
106 In·addition,·logging·in·with·a·user-specific·account·provides·individual 
107 accountability·of·actions·performed·on·the·system·and·also·helps·to·minimize 
108 direct·attack·attempts·on·root's·password. 
109 ······</td>62 ······</td>
110 ····</tr>63 ····</tr>
111 ····<tr>64 ····<tr>
112 ······<td>3.1.1</td>65 ······<td>3.1.1</td>
113 ······<td>Disable·GDM·Automatic·Login</td>66 ······<td>Disable·GDM·Automatic·Login</td>
114 ······<td·xml:lang="en-US">67 ······<td·xml:lang="en-US">
115 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without68 ········The·GNOME·Display·Manager·(GDM)·can·allow·users·to·automatically·login·without
Offset 125, 63 lines modifiedOffset 77, 28 lines modified
125 ······</td>77 ······</td>
126 ······<td·xml:lang="en-US">78 ······<td·xml:lang="en-US">
127 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating79 ········Failure·to·restrict·system·access·to·authenticated·users·negatively·impacts·operating
128 system·security.80 system·security.
129 ······</td>81 ······</td>
130 ····</tr>82 ····</tr>
131 ····<tr>83 ····<tr>
132 ······<td>3.1.1<br/>3.1.5</td>84 ······<td>3.1.1<br/>3.4.5</td>
 85 ······<td>Require·Authentication·for·Emergency·Systemd·Target</td>
133 ······<td>Restrict·Virtual·Console·Root·Logins</td> 
134 ······<td·xml:lang="en-US"> 
135 ········To·restrict·root·logins·through·the·(deprecated)·virtual·console·devices, 
136 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
137 <pre>vc/1 
138 vc/2 
139 vc/3 
140 vc/4</pre> 
141 ······</td> 
142 ······<td·xml:lang="en-US"> 
143 ········Preventing·direct·root·login·to·virtual·console·devices 
144 helps·ensure·accountability·for·actions·taken·on·the·system 
145 using·the·root·account. 
146 ······</td> 
147 ····</tr> 
148 ····<tr> 
149 ······<td>3.1.1<br/>3.1.5</td> 
150 ······<td>Restrict·Serial·Port·Root·Logins</td> 
151 ······<td·xml:lang="en-US"> 
152 ········To·restrict·root·logins·on·serial·ports, 
153 ensure·lines·of·this·form·do·not·appear·in·<tt>/etc/securetty</tt>: 
154 <pre>ttyS0 
155 ttyS1</pre> 
156 ······</td> 
157 ······<td·xml:lang="en-US"> 
158 ········Preventing·direct·root·login·to·serial·port·interfaces 
159 helps·ensure·accountability·for·actions·taken·on·the·systems 
160 using·the·root·account. 
161 ······</td> 
162 ····</tr> 
163 ····<tr> 
Max diff block lines reached; 464430/469818 bytes (98.85%) of diff not shown.
829 KB
html2text {}
Max HTML report size reached
3.56 KB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs-stig.html
    
Offset 24277, 17 lines modifiedOffset 24277, 17 lines modified
0005ed40:·696e·670a·7469·6d65·2d62·6173·6564·206c··ing.time-based·l0005ed40:·696e·670a·7469·6d65·2d62·6173·6564·206c··ing.time-based·l
0005ed50:·696d·6974·2c20·6566·6665·6374·7320·6f66··imit,·effects·of0005ed50:·696d·6974·2c20·6566·6665·6374·7320·6f66··imit,·effects·of
0005ed60:·2070·6f74·656e·7469·616c·2061·7474·6163···potential·attac0005ed60:·2070·6f74·656e·7469·616c·2061·7474·6163···potential·attac
0005ed70:·6b73·2061·6761·696e·7374·0a65·6e63·7279··ks·against.encry0005ed70:·6b73·2061·6761·696e·7374·0a65·6e63·7279··ks·against.encry
0005ed80:·7074·696f·6e20·6b65·7973·2061·7265·206c··ption·keys·are·l0005ed80:·7074·696f·6e20·6b65·7973·2061·7265·206c··ption·keys·are·l
0005ed90:·696d·6974·6564·2e0a·2020·3c2f·7464·3e0a··imited..··</td>.0005ed90:·696d·6974·6564·2e0a·2020·3c2f·7464·3e0a··imited..··</td>.
0005eda0:·2020·3c74·643e·7661·725f·7265·6b65·795f····<td>var_rekey_0005eda0:·2020·3c74·643e·7661·725f·7265·6b65·795f····<td>var_rekey_
0005edb0:·6c69·6d69·745f·7469·6d65·3d31·686f·7572··limit_time=1hour0005edb0:·6c69·6d69·745f·7369·7a65·3d31·473c·6272··limit_size=1G<br
0005edc0:·3c62·722f·3e76·6172·5f72·656b·6579·5f6c··<br/>var_rekey_l 
0005edd0:·696d·6974·5f73·697a·653d·3147·3c2f·7464··imit_size=1G</td0005edc0:·2f3e·7661·725f·7265·6b65·795f·6c69·6d69··/>var_rekey_limi
 0005edd0:·745f·7469·6d65·3d31·686f·7572·3c2f·7464··t_time=1hour</td
0005ede0:·3e0a·3c2f·7472·3e0a·3c74·723e·0a20·203c··>.</tr>.<tr>.··<0005ede0:·3e0a·3c2f·7472·3e0a·3c74·723e·0a20·203c··>.</tr>.<tr>.··<
0005edf0:·7464·3e3c·2f74·643e·0a20·203c·7464·3e43··td></td>.··<td>C0005edf0:·7464·3e3c·2f74·643e·0a20·203c·7464·3e43··td></td>.··<td>C
0005ee00:·4345·2d38·3234·3632·2d33·3c2f·7464·3e0a··CE-82462-3</td>.0005ee00:·4345·2d38·3234·3632·2d33·3c2f·7464·3e0a··CE-82462-3</td>.
0005ee10:·2020·3c74·643e·5353·4820·7365·7276·6572····<td>SSH·server0005ee10:·2020·3c74·643e·5353·4820·7365·7276·6572····<td>SSH·server
0005ee20:·2075·7365·7320·7374·726f·6e67·2065·6e74···uses·strong·ent0005ee20:·2075·7365·7320·7374·726f·6e67·2065·6e74···uses·strong·ent
0005ee30:·726f·7079·2074·6f20·7365·6564·3c2f·7464··ropy·to·seed</td0005ee30:·726f·7079·2074·6f20·7365·6564·3c2f·7464··ropy·to·seed</td
0005ee40:·3e0a·2020·3c74·6420·786d·6c3a·6c61·6e67··>.··<td·xml:lang0005ee40:·3e0a·2020·3c74·6420·786d·6c3a·6c61·6e67··>.··<td·xml:lang
2.07 KB
html2text {}
    
Offset 7644, 16 lines modifiedOffset 7644, 16 lines modified
7644 ·····································corresponding·private·key.····························system·where·the7644 ·····································corresponding·private·key.····························system·where·the
7645 ···························································································associated·public7645 ···························································································associated·public
7646 ···························································································key·has·been7646 ···························································································key·has·been
7647 ···························································································installed.7647 ···························································································installed.
7648 ·····································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the7648 ·····································The·RekeyLimit·parameter·specifies·how·often·the······By·decreasing·the
7649 ·····································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the7649 ·····································session·key·of·the·is·renegotiated,·both·in·terms·of··limit·based·on·the
7650 ········CCE-···Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and7650 ········CCE-···Force·frequent········amount·of·data·that·may·be·transmitted·and·the·time···amount·of·data·and
7651 ········82177-·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_time=1hour7651 ········82177-·session·key···········elapsed.··············································enabling·time-based·var_rekey_limit_size=1G
7652 ········7······renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_size=1G7652 ········7······renegotiation·········To·decrease·the·default·limits,·add·or·correct·the····limit,·effects·of···var_rekey_limit_time=1hour
7653 ·····································following·line·in·/etc/ssh/sshd_config:···············potential·attacks7653 ·····································following·line·in·/etc/ssh/sshd_config:···············potential·attacks
7654 ·····································RekeyLimit·1G·1hour···································against·encryption7654 ·····································RekeyLimit·1G·1hour···································against·encryption
7655 ···························································································keys·are·limited.7655 ···························································································keys·are·limited.
7656 ···························································································SSH·implementation7656 ···························································································SSH·implementation
7657 ···························································································in·Red·Hat7657 ···························································································in·Red·Hat
7658 ···························································································Enterprise·Linux·87658 ···························································································Enterprise·Linux·8
7659 ···························································································uses·the·openssl7659 ···························································································uses·the·openssl
9.66 MB
./usr/share/doc/ssg-nondebian/table-rhel8-nistrefs.html
    
Offset 65, 14948 lines modifiedOffset 65, 14948 lines modified
00000400:·5275·6c65·2054·6974·6c65·3c2f·7468·3e0a··Rule·Title</th>.00000400:·5275·6c65·2054·6974·6c65·3c2f·7468·3e0a··Rule·Title</th>.
00000410:·2020·2020·3c74·683e·4465·7363·7269·7074······<th>Descript00000410:·2020·2020·3c74·683e·4465·7363·7269·7074······<th>Descript
00000420:·696f·6e3c·2f74·683e·0a20·2020·203c·7468··ion</th>.····<th00000420:·696f·6e3c·2f74·683e·0a20·2020·203c·7468··ion</th>.····<th
00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.00000430:·3e52·6174·696f·6e61·6c65·3c2f·7468·3e0a··>Rationale</th>.
00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb00000440:·2020·3c2f·7468·6561·643e·0a20·203c·7462····</thead>.··<tb
00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····00000450:·6f64·793e·0a20·203c·7472·3e0a·2020·2020··ody>.··<tr>.····
Diff chunk too large, falling back to line-by-line diff (9554 lines added, 9554 lines removed)
00000460:·2020·3c74·643e·4155·2d32·2864·293c·6272····<td>AU-2(d)<br00000460:·2020·3c74·643e·4155·2d32·2864·293c·6272····<td>AU-2(d)<br
00000470:·2f3e·4155·2d31·3228·6329·3c62·722f·3e43··/>AU-12(c)<br/>C00000470:·2f3e·4155·2d31·3228·6329·3c62·722f·3e41··/>AU-12(c)<br/>A
00000480:·4d2d·3628·6129·3c2f·7464·3e0a·2020·2020··M-6(a)</td>.····00000480:·432d·3628·3929·3c62·722f·3e43·4d2d·3628··C-6(9)<br/>CM-6(
00000490:·2020·3c74·643e·5265·636f·7264·2045·7665····<td>Record·Eve00000490:·6129·3c2f·7464·3e0a·2020·2020·2020·3c74··a)</td>.······<t
000004a0:·6e74·7320·7468·6174·204d·6f64·6966·7920··nts·that·Modify·000004a0:·643e·456e·7375·7265·2061·7564·6974·6420··d>Ensure·auditd·
000004b0:·7468·6520·5379·7374·656d·2773·2044·6973··the·System's·Dis000004b0:·436f·6c6c·6563·7473·2049·6e66·6f72·6d61··Collects·Informa
000004c0:·6372·6574·696f·6e61·7279·2041·6363·6573··cretionary·Acces000004c0:·7469·6f6e·206f·6e20·7468·6520·5573·6520··tion·on·the·Use·
000004d0:·7320·436f·6e74·726f·6c73·202d·2063·686d··s·Controls·-·chm000004d0:·6f66·2050·7269·7669·6c65·6765·6420·436f··of·Privileged·Co
000004e0:·6f64·3c2f·7464·3e0a·2020·2020·2020·3c74··od</td>.······<t000004e0:·6d6d·616e·6473·202d·2075·6d6f·756e·743c··mmands·-·umount<
000004f0:·6420·786d·6c3a·6c61·6e67·3d22·656e·2d55··d·xml:lang="en-U000004f0:·2f74·643e·0a20·2020·2020·203c·7464·2078··/td>.······<td·x
00000500:·5322·3e0a·2020·2020·2020·2020·4174·2061··S">.········At·a00000500:·6d6c·3a6c·616e·673d·2265·6e2d·5553·223e··ml:lang="en-US">
00000510:·206d·696e·696d·756d·2c20·7468·6520·6175···minimum,·the·au00000510:·0a20·2020·2020·2020·2041·7420·6120·6d69··.········At·a·mi
00000520:·6469·7420·7379·7374·656d·2073·686f·756c··dit·system·shoul00000520:·6e69·6d75·6d2c·2074·6865·2061·7564·6974··nimum,·the·audit
00000530:·6420·636f·6c6c·6563·7420·6669·6c65·2070··d·collect·file·p00000530:·2073·7973·7465·6d20·7368·6f75·6c64·2063···system·should·c
00000540:·6572·6d69·7373·696f·6e0a·6368·616e·6765··ermission.change00000540:·6f6c·6c65·6374·2074·6865·2065·7865·6375··ollect·the·execu
00000550:·7320·666f·7220·616c·6c20·7573·6572·7320··s·for·all·users·00000550:·7469·6f6e·206f·660a·7072·6976·696c·6567··tion·of.privileg
00000560:·616e·6420·726f·6f74·2e20·4966·2074·6865··and·root.·If·the00000560:·6564·2063·6f6d·6d61·6e64·7320·666f·7220··ed·commands·for·
00000570:·203c·7474·3e61·7564·6974·643c·2f74·743e···<tt>auditd</tt>00000570:·616c·6c20·7573·6572·7320·616e·6420·726f··all·users·and·ro
00000580:·2064·6165·6d6f·6e20·6973·2063·6f6e·6669···daemon·is·confi00000580:·6f74·2e20·4966·2074·6865·203c·7474·3e61··ot.·If·the·<tt>a
00000590:·6775·7265·6420·746f·0a75·7365·2074·6865··gured·to.use·the00000590:·7564·6974·643c·2f74·743e·2064·6165·6d6f··uditd</tt>·daemo
000005a0:·203c·7474·3e61·7567·656e·7275·6c65·733c···<tt>augenrules<000005a0:·6e20·6973·0a63·6f6e·6669·6775·7265·6420··n·is.configured·
000005b0:·2f74·743e·2070·726f·6772·616d·2074·6f20··/tt>·program·to·000005b0:·746f·2075·7365·2074·6865·203c·7474·3e61··to·use·the·<tt>a
000005c0:·7265·6164·2061·7564·6974·2072·756c·6573··read·audit·rules000005c0:·7567·656e·7275·6c65·733c·2f74·743e·2070··ugenrules</tt>·p
000005d0:·2064·7572·696e·6720·6461·656d·6f6e·2073···during·daemon·s000005d0:·726f·6772·616d·2074·6f20·7265·6164·2061··rogram·to·read·a
000005e0:·7461·7274·7570·0a28·7468·6520·6465·6661··tartup.(the·defa000005e0:·7564·6974·2072·756c·6573·2064·7572·696e··udit·rules·durin
000005f0:·756c·7429·2c20·6164·6420·7468·6520·666f··ult),·add·the·fo000005f0:·670a·6461·656d·6f6e·2073·7461·7274·7570··g.daemon·startup
00000600:·6c6c·6f77·696e·6720·6c69·6e65·2074·6f20··llowing·line·to·00000600:·2028·7468·6520·6465·6661·756c·7429·2c20···(the·default),·
00000610:·6120·6669·6c65·2077·6974·6820·7375·6666··a·file·with·suff00000610:·6164·6420·6120·6c69·6e65·206f·6620·7468··add·a·line·of·th
00000620:·6978·203c·7474·3e2e·7275·6c65·733c·2f74··ix·<tt>.rules</t00000620:·6520·666f·6c6c·6f77·696e·6720·666f·726d··e·following·form
00000630:·743e·2069·6e0a·7468·6520·6469·7265·6374··t>·in.the·direct00000630:·2074·6f20·6120·6669·6c65·2077·6974·680a···to·a·file·with.
00000640:·6f72·7920·3c74·743e·2f65·7463·2f61·7564··ory·<tt>/etc/aud00000640:·7375·6666·6978·203c·7474·3e2e·7275·6c65··suffix·<tt>.rule
00000650:·6974·2f72·756c·6573·2e64·3c2f·7474·3e3a··it/rules.d</tt>:00000650:·733c·2f74·743e·2069·6e20·7468·6520·6469··s</tt>·in·the·di
00000660:·0a3c·7072·653e·2d61·2061·6c77·6179·732c··.<pre>-a·always,00000660:·7265·6374·6f72·7920·3c74·743e·2f65·7463··rectory·<tt>/etc
00000670:·6578·6974·202d·4620·6172·6368·3d62·3332··exit·-F·arch=b3200000670:·2f61·7564·6974·2f72·756c·6573·2e64·3c2f··/audit/rules.d</
00000680:·202d·5320·6368·6d6f·6420·2d46·2061·7569···-S·chmod·-F·aui00000680:·7474·3e3a·0a3c·7072·653e·2d61·2061·6c77··tt>:.<pre>-a·alw
00000690:·6426·6774·3b3d·3130·3030·202d·4620·6175··d&gt;=1000·-F·au00000690:·6179·732c·6578·6974·202d·4620·7061·7468··ays,exit·-F·path
000006a0:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key000006a0:·3d2f·7573·722f·6269·6e2f·756d·6f75·6e74··=/usr/bin/umount
000006b0:·3d70·6572·6d5f·6d6f·643c·2f70·7265·3e0a··=perm_mod</pre>.000006b0:·202d·4620·7065·726d·3d78·202d·4620·6175···-F·perm=x·-F·au
000006c0:·4966·2074·6865·2073·7973·7465·6d20·6973··If·the·system·is000006c0:·6964·2667·743b·3d31·3030·3020·2d46·2061··id&gt;=1000·-F·a
000006d0:·2036·3420·6269·7420·7468·656e·2061·6c73···64·bit·then·als000006d0:·7569·6421·3d75·6e73·6574·202d·4620·6b65··uid!=unset·-F·ke
000006e0:·6f20·6164·6420·7468·6520·666f·6c6c·6f77··o·add·the·follow000006e0:·793d·7072·6976·696c·6567·6564·3c2f·7072··y=privileged</pr
000006f0:·696e·6720·6c69·6e65·3a0a·3c70·7265·3e2d··ing·line:.<pre>-000006f0:·653e·0a49·6620·7468·6520·3c74·743e·6175··e>.If·the·<tt>au
00000700:·6120·616c·7761·7973·2c65·7869·7420·2d46··a·always,exit·-F00000700:·6469·7464·3c2f·7474·3e20·6461·656d·6f6e··ditd</tt>·daemon
00000710:·2061·7263·683d·6236·3420·2d53·2063·686d···arch=b64·-S·chm00000710:·2069·7320·636f·6e66·6967·7572·6564·2074···is·configured·t
00000720:·6f64·202d·4620·6175·6964·2667·743b·3d31··od·-F·auid&gt;=100000720:·6f20·7573·6520·7468·6520·3c74·743e·6175··o·use·the·<tt>au
00000730:·3030·3020·2d46·2061·7569·6421·3d75·6e73··000·-F·auid!=uns00000730:·6469·7463·746c·3c2f·7474·3e0a·7574·696c··ditctl</tt>.util
00000740:·6574·202d·4620·6b65·793d·7065·726d·5f6d··et·-F·key=perm_m00000740:·6974·7920·746f·2072·6561·6420·6175·6469··ity·to·read·audi
00000750:·6f64·3c2f·7072·653e·0a49·6620·7468·6520··od</pre>.If·the·00000750:·7420·7275·6c65·7320·6475·7269·6e67·2064··t·rules·during·d
00000760:·3c74·743e·6175·6469·7464·3c2f·7474·3e20··<tt>auditd</tt>·00000760:·6165·6d6f·6e20·7374·6172·7475·702c·2061··aemon·startup,·a
00000770:·6461·656d·6f6e·2069·7320·636f·6e66·6967··daemon·is·config00000770:·6464·2061·206c·696e·6520·6f66·2074·6865··dd·a·line·of·the
00000780:·7572·6564·2074·6f20·7573·6520·7468·6520··ured·to·use·the·00000780:·2066·6f6c·6c6f·7769·6e67·0a66·6f72·6d20···following.form·
00000790:·3c74·743e·6175·6469·7463·746c·3c2f·7474··<tt>auditctl</tt00000790:·746f·203c·7474·3e2f·6574·632f·6175·6469··to·<tt>/etc/audi
000007a0:·3e0a·7574·696c·6974·7920·746f·2072·6561··>.utility·to·rea000007a0:·742f·6175·6469·742e·7275·6c65·733c·2f74··t/audit.rules</t
000007b0:·6420·6175·6469·7420·7275·6c65·7320·6475··d·audit·rules·du000007b0:·743e·3a0a·3c70·7265·3e2d·6120·616c·7761··t>:.<pre>-a·alwa
000007c0:·7269·6e67·2064·6165·6d6f·6e20·7374·6172··ring·daemon·star000007c0:·7973·2c65·7869·7420·2d46·2070·6174·683d··ys,exit·-F·path=
000007d0:·7475·702c·2061·6464·2074·6865·2066·6f6c··tup,·add·the·fol000007d0:·2f75·7372·2f62·696e·2f75·6d6f·756e·7420··/usr/bin/umount·
000007e0:·6c6f·7769·6e67·206c·696e·6520·746f·0a3c··lowing·line·to.<000007e0:·2d46·2070·6572·6d3d·7820·2d46·2061·7569··-F·perm=x·-F·aui
000007f0:·7474·3e2f·6574·632f·6175·6469·742f·6175··tt>/etc/audit/au000007f0:·6426·6774·3b3d·3130·3030·202d·4620·6175··d&gt;=1000·-F·au
00000800:·6469·742e·7275·6c65·733c·2f74·743e·2066··dit.rules</tt>·f00000800:·6964·213d·756e·7365·7420·2d46·206b·6579··id!=unset·-F·key
00000810:·696c·653a·0a3c·7072·653e·2d61·2061·6c77··ile:.<pre>-a·alw00000810:·3d70·7269·7669·6c65·6765·643c·2f70·7265··=privileged</pre
00000820:·6179·732c·6578·6974·202d·4620·6172·6368··ays,exit·-F·arch00000820:·3e0a·2020·2020·2020·3c2f·7464·3e0a·2020··>.······</td>.··
00000830:·3d62·3332·202d·5320·6368·6d6f·6420·2d46··=b32·-S·chmod·-F00000830:·2020·2020·3c74·6420·786d·6c3a·6c61·6e67······<td·xml:lang
00000840:·2061·7569·6426·6774·3b3d·3130·3030·202d···auid&gt;=1000·-00000840:·3d22·656e·2d55·5322·3e0a·2020·2020·2020··="en-US">.······
00000850:·4620·6175·6964·213d·756e·7365·7420·2d46··F·auid!=unset·-F00000850:·2020·4d69·7375·7365·206f·6620·7072·6976····Misuse·of·priv
00000860:·206b·6579·3d70·6572·6d5f·6d6f·643c·2f70···key=perm_mod</p00000860:·696c·6567·6564·2066·756e·6374·696f·6e73··ileged·functions
00000870:·7265·3e0a·4966·2074·6865·2073·7973·7465··re>.If·the·syste00000870:·2c20·6569·7468·6572·2069·6e74·656e·7469··,·either·intenti
00000880:·6d20·6973·2036·3420·6269·7420·7468·656e··m·is·64·bit·then00000880:·6f6e·616c·6c79·206f·7220·756e·696e·7465··onally·or·uninte
00000890:·2061·6c73·6f20·6164·6420·7468·6520·666f···also·add·the·fo00000890:·6e74·696f·6e61·6c6c·7920·6279·0a61·7574··ntionally·by.aut
000008a0:·6c6c·6f77·696e·6720·6c69·6e65·3a0a·3c70··llowing·line:.<p000008a0:·686f·7269·7a65·6420·7573·6572·732c·206f··horized·users,·o
000008b0:·7265·3e2d·6120·616c·7761·7973·2c65·7869··re>-a·always,exi000008b0:·7220·6279·2075·6e61·7574·686f·7269·7a65··r·by·unauthorize
000008c0:·7420·2d46·2061·7263·683d·6236·3420·2d53··t·-F·arch=b64·-S000008c0:·6420·6578·7465·726e·616c·2065·6e74·6974··d·external·entit
000008d0:·2063·686d·6f64·202d·4620·6175·6964·2667···chmod·-F·auid&g000008d0:·6965·7320·7468·6174·2068·6176·6520·636f··ies·that·have·co
000008e0:·743b·3d31·3030·3020·2d46·2061·7569·6421··t;=1000·-F·auid!000008e0:·6d70·726f·6d69·7365·6420·7379·7374·656d··mpromised·system
000008f0:·3d75·6e73·6574·202d·4620·6b65·793d·7065··=unset·-F·key=pe000008f0:·2061·6363·6f75·6e74·732c·0a69·7320·6120···accounts,.is·a·
00000900:·726d·5f6d·6f64·3c2f·7072·653e·0a20·2020··rm_mod</pre>.···00000900:·7365·7269·6f75·7320·616e·6420·6f6e·676f··serious·and·ongo
00000910:·2020·203c·2f74·643e·0a20·2020·2020·203c·····</td>.······<00000910:·696e·6720·636f·6e63·6572·6e20·616e·6420··ing·concern·and·
00000920:·7464·2078·6d6c·3a6c·616e·673d·2265·6e2d··td·xml:lang="en-00000920:·6361·6e20·6861·7665·2073·6967·6e69·6669··can·have·signifi
00000930:·5553·223e·0a20·2020·2020·2020·2054·6865··US">.········The00000930:·6361·6e74·2061·6476·6572·7365·2069·6d70··cant·adverse·imp
00000940:·2063·6861·6e67·696e·6720·6f66·2066·696c···changing·of·fil00000940:·6163·7473·206f·6e20·6f72·6761·6e69·7a61··acts·on·organiza
00000950:·6520·7065·726d·6973·7369·6f6e·7320·636f··e·permissions·co00000950:·7469·6f6e·732e·0a41·7564·6974·696e·6720··tions..Auditing·
00000960:·756c·6420·696e·6469·6361·7465·2074·6861··uld·indicate·tha00000960:·7468·6520·7573·6520·6f66·2070·7269·7669··the·use·of·privi
00000970:·7420·6120·7573·6572·2069·7320·6174·7465··t·a·user·is·atte00000970:·6c65·6765·6420·6675·6e63·7469·6f6e·7320··leged·functions·
00000980:·6d70·7469·6e67·2074·6f0a·6761·696e·2061··mpting·to.gain·a00000980:·6973·206f·6e65·2077·6179·2074·6f20·6465··is·one·way·to·de
00000990:·6363·6573·7320·746f·2069·6e66·6f72·6d61··ccess·to·informa00000990:·7465·6374·2073·7563·6820·6d69·7375·7365··tect·such·misuse
000009a0:·7469·6f6e·2074·6861·7420·776f·756c·6420··tion·that·would·000009a0:·2061·6e64·2069·6465·6e74·6966·790a·7468···and·identify.th
000009b0:·6f74·6865·7277·6973·6520·6265·2064·6973··otherwise·be·dis000009b0:·6520·7269·736b·2066·726f·6d20·696e·7369··e·risk·from·insi
000009c0:·616c·6c6f·7765·642e·2041·7564·6974·696e··allowed.·Auditin000009c0:·6465·7220·616e·6420·6164·7661·6e63·6564··der·and·advanced
000009d0:·6720·4441·4320·6d6f·6469·6669·6361·7469··g·DAC·modificati000009d0:·2070·6572·7369·7374·656e·7420·7468·7265···persistent·thre
000009e0:·6f6e·730a·6361·6e20·6661·6369·6c69·7461··ons.can·facilita000009e0:·6174·732e·0a3c·6272·202f·3e3c·6272·202f··ats..<br·/><br·/
000009f0:·7465·2074·6865·2069·6465·6e74·6966·6963··te·the·identific000009f0:·3e0a·5072·6976·696c·6567·6564·2070·726f··>.Privileged·pro
00000a00:·6174·696f·6e20·6f66·2070·6174·7465·726e··ation·of·pattern00000a00:·6772·616d·7320·6172·6520·7375·626a·6563··grams·are·subjec
00000a10:·7320·6f66·2061·6275·7365·2061·6d6f·6e67··s·of·abuse·among00000a10:·7420·746f·2065·7363·616c·6174·696f·6e2d··t·to·escalation-
00000a20:·2062·6f74·6820·6175·7468·6f72·697a·6564···both·authorized00000a20:·6f66·2d70·7269·7669·6c65·6765·2061·7474··of-privilege·att
00000a30:·2061·6e64·0a75·6e61·7574·686f·7269·7a65···and.unauthorize00000a30:·6163·6b73·2c0a·7768·6963·6820·6174·7465··acks,.which·atte
00000a40:·6420·7573·6572·732e·0a20·2020·2020·203c··d·users..······<00000a40:·6d70·7420·746f·2073·7562·7665·7274·2074··mpt·to·subvert·t
00000a50:·2f74·643e·0a20·2020·203c·2f74·723e·0a20··/td>.····</tr>.·00000a50:·6865·6972·206e·6f72·6d61·6c20·726f·6c65··heir·normal·role
00000a60:·2020·203c·7472·3e0a·2020·2020·2020·3c74·····<tr>.······<t00000a60:·206f·6620·7072·6f76·6964·696e·6720·736f···of·providing·so
00000a70:·643e·4155·2d32·2864·293c·6272·2f3e·4155··d>AU-2(d)<br/>AU00000a70:·6d65·206e·6563·6573·7361·7279·2062·7574··me·necessary·but
00000a80:·2d31·3228·6329·3c62·722f·3e41·432d·3628··-12(c)<br/>AC-6(00000a80:·0a6c·696d·6974·6564·2063·6170·6162·696c··.limited·capabil
00000a90:·3929·3c62·722f·3e43·4d2d·3628·6129·3c2f··9)<br/>CM-6(a)</00000a90:·6974·792e·2041·7320·7375·6368·2c20·6d6f··ity.·As·such,·mo
00000aa0:·7464·3e0a·2020·2020·2020·3c74·643e·5265··td>.······<td>Re00000aa0:·7469·7661·7469·6f6e·2065·7869·7374·7320··tivation·exists·
00000ab0:·636f·7264·2041·7474·656d·7074·7320·746f··cord·Attempts·to00000ab0:·746f·206d·6f6e·6974·6f72·2074·6865·7365··to·monitor·these
00000ac0:·2041·6c74·6572·204c·6f67·6f6e·2061·6e64···Alter·Logon·and00000ac0:·2070·726f·6772·616d·7320·666f·720a·756e···programs·for.un
00000ad0:·204c·6f67·6f75·7420·4576·656e·7473·202d···Logout·Events·-00000ad0:·7573·7561·6c20·6163·7469·7669·7479·2e0a··usual·activity..
00000ae0:·2074·616c·6c79·6c6f·673c·2f74·643e·0a20···tallylog</td>.·00000ae0:·2020·2020·2020·3c2f·7464·3e0a·2020·2020········</td>.····
00000af0:·2020·2020·203c·7464·2078·6d6c·3a6c·616e·······<td·xml:lan00000af0:·3c2f·7472·3e0a·2020·2020·3c74·723e·0a20··</tr>.····<tr>.·
00000b00:·673d·2265·6e2d·5553·223e·0a20·2020·2020··g="en-US">.·····00000b00:·2020·2020·203c·7464·3e41·552d·3228·6429·······<td>AU-2(d)
00000b10:·2020·2054·6865·2061·7564·6974·2073·7973·····The·audit·sys00000b10:·3c62·722f·3e41·552d·3132·2863·293c·6272··<br/>AU-12(c)<br
00000b20:·7465·6d20·616c·7265·6164·7920·636f·6c6c··tem·already·coll00000b20:·2f3e·4143·2d36·2839·293c·6272·2f3e·434d··/>AC-6(9)<br/>CM
00000b30:·6563·7473·206c·6f67·696e·2069·6e66·6f72··ects·login·infor00000b30:·2d36·2861·293c·2f74·643e·0a20·2020·2020··-6(a)</td>.·····
00000b40:·6d61·7469·6f6e·2066·6f72·2061·6c6c·2075··mation·for·all·u00000b40:·203c·7464·3e45·6e73·7572·6520·6175·6469···<td>Ensure·audi
00000b50:·7365·7273·0a61·6e64·2072·6f6f·742e·2049··sers.and·root.·I00000b50:·7464·2043·6f6c·6c65·6374·7320·496e·666f··td·Collects·Info
00000b60:·6620·7468·6520·3c74·743e·6175·6469·7464··f·the·<tt>auditd00000b60:·726d·6174·696f·6e20·6f6e·2074·6865·2055··rmation·on·the·U
00000b70:·3c2f·7474·3e20·6461·656d·6f6e·2069·7320··</tt>·daemon·is·00000b70:·7365·206f·6620·5072·6976·696c·6567·6564··se·of·Privileged
00000b80:·636f·6e66·6967·7572·6564·2074·6f20·7573··configured·to·us00000b80:·2043·6f6d·6d61·6e64·7320·2d20·6d6f·756e···Commands·-·moun
00000b90:·6520·7468·650a·3c74·743e·6175·6765·6e72··e·the.<tt>augenr00000b90:·743c·2f74·643e·0a20·2020·2020·203c·7464··t</td>.······<td
00000ba0:·756c·6573·3c2f·7474·3e20·7072·6f67·7261··ules</tt>·progra00000ba0:·2078·6d6c·3a6c·616e·673d·2265·6e2d·5553···xml:lang="en-US
00000bb0:·6d20·746f·2072·6561·6420·6175·6469·7420··m·to·read·audit·00000bb0:·223e·0a20·2020·2020·2020·2041·7420·6120··">.········At·a·
00000bc0:·7275·6c65·7320·6475·7269·6e67·2064·6165··rules·during·dae00000bc0:·6d69·6e69·6d75·6d2c·2074·6865·2061·7564··minimum,·the·aud
00000bd0:·6d6f·6e20·7374·6172·7475·7020·2874·6865··mon·startup·(the00000bd0:·6974·2073·7973·7465·6d20·7368·6f75·6c64··it·system·should
Max diff block lines reached; 6156405/7475435 bytes (82.36%) of diff not shown.
2.53 MB
html2text {}
Max HTML report size reached
796 KB
./usr/share/doc/ssg-nondebian/table-rhel8-pcidssrefs.html
Ordering differences only
    
Offset 73, 28 lines modifiedOffset 73, 14 lines modified
73 is·the·only·place·that·loopback·network·traffic·should·be·seen,73 is·the·only·place·that·loopback·network·traffic·should·be·seen,
74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an74 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
75 anti-spoofing·measure.75 anti-spoofing·measure.
76 ······</td>76 ······</td>
77 ····</tr>77 ····</tr>
78 ····<tr>78 ····<tr>
79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>79 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
80 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td> 
81 ······<td·xml:lang="en-US"> 
82 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre> 
83 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre> 
84 ······</td> 
85 ······<td·xml:lang="en-US"> 
86 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange 
87 network·topology·information·with·other·routers.·If·this·capability·is·used·when 
88 not·required,·system·network·information·may·be·unnecessarily·transmitted·across 
89 the·network. 
90 ······</td> 
91 ····</tr> 
92 ····<tr> 
93 ······<td>Req-1.3.1<br/>Req-1.3.2</td> 
94 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>80 ······<td>Ensure·IPv6·is·disabled·through·kernel·boot·parameter</td>
95 ······<td·xml:lang="en-US">81 ······<td·xml:lang="en-US">
96 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,82 ········To·disable·IPv6·protocol·support·in·the·Linux·kernel,
97 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default83 add·the·argument·<tt>ipv6.disable=1</tt>·to·the·default
98 GRUB2·command·line·for·the·Linux·operating·system.84 GRUB2·command·line·for·the·Linux·operating·system.
99 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line85 To·ensure·that·<tt>ipv6.disable=1</tt>·is·added·as·a·kernel·command·line
100 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the86 argument·to·newly·installed·kernels,·add·<tt>ipv6.disable=1</tt>·to·the
Offset 105, 14 lines modifiedOffset 91, 28 lines modified
105 ······</td>91 ······</td>
106 ······<td·xml:lang="en-US">92 ······<td·xml:lang="en-US">
107 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce93 ········Any·unnecessary·network·stacks,·including·IPv6,·should·be·disabled·to·reduce
108 the·vulnerability·to·exploitation.94 the·vulnerability·to·exploitation.
109 ······</td>95 ······</td>
110 ····</tr>96 ····</tr>
111 ····<tr>97 ····<tr>
 98 ······<td>Req-1.3.1<br/>Req-1.3.2</td>
 99 ······<td>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</td>
 100 ······<td·xml:lang="en-US">
 101 ········To·set·the·runtime·status·of·the·<code>net.ipv4.ip_forward</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.ip_forward=0</pre>
 102 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.ip_forward·=·0</pre>
 103 ······</td>
 104 ······<td·xml:lang="en-US">
 105 ········Routing·protocol·daemons·are·typically·used·on·routers·to·exchange
 106 network·topology·information·with·other·routers.·If·this·capability·is·used·when
 107 not·required,·system·network·information·may·be·unnecessarily·transmitted·across
 108 the·network.
 109 ······</td>
 110 ····</tr>
 111 ····<tr>
112 ······<td>Req-1.3.3</td>112 ······<td>Req-1.3.3</td>
113 ······<td>Deactivate·Wireless·Network·Interfaces</td>113 ······<td>Deactivate·Wireless·Network·Interfaces</td>
114 ······<td·xml:lang="en-US">114 ······<td·xml:lang="en-US">
115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless115 ········Deactivating·wireless·network·interfaces·should·prevent·normal·usage·of·the·wireless
116 capability.116 capability.
117 <br·/><br·/>117 <br·/><br·/>
  
Offset 157, 26 lines modifiedOffset 157, 26 lines modified
157 ······<td·xml:lang="en-US">157 ······<td·xml:lang="en-US">
158 ········Without·a·firewall·rule·configured·for·open·ports·default·firewall·policy·will·drop·all158 ········Without·a·firewall·rule·configured·for·open·ports·default·firewall·policy·will·drop·all
159 packets·to·these·ports.159 packets·to·these·ports.
160 ······</td>160 ······</td>
161 ····</tr>161 ····</tr>
162 ····<tr>162 ····<tr>
163 ······<td>Req-1.4.1</td>163 ······<td>Req-1.4.1</td>
164 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>164 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>
165 ······<td·xml:lang="en-US">165 ······<td·xml:lang="en-US">
 166 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre>
 167 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>
166 ········Configure·the·loopback·interface·to·accept·traffic. 
167 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback 
168 network. 
169 ······</td>168 ······</td>
170 ······<td·xml:lang="en-US">169 ······<td·xml:lang="en-US">
171 ········Loopback·traffic·is·generated·between·processes·on·machine·and·is 
172 typically·critical·to·operation·of·the·system.·The·loopback·interface 
173 is·the·only·place·that·loopback·network·traffic·should·be·seen, 
174 all·other·interfaces·should·ignore·traffic·on·this·network·as·an 
175 anti-spoofing·measure.170 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a
 171 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state.
 172 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received,
 173 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood
 174 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and
 175 enables·the·system·to·continue·servicing·valid·connection·requests.
176 ······</td>176 ······</td>
177 ····</tr>177 ····</tr>
178 ····<tr>178 ····<tr>
179 ······<td>Req-1.4.1</td>179 ······<td>Req-1.4.1</td>
180 ······<td>Install·iptables·Package</td>180 ······<td>Install·iptables·Package</td>
181 ······<td·xml:lang="en-US">181 ······<td·xml:lang="en-US">
182 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command:182 ········The·<code>iptables</code>·package·can·be·installed·with·the·following·command:
Offset 187, 26 lines modifiedOffset 187, 26 lines modified
187 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering187 ········<tt>iptables</tt>·controls·the·Linux·kernel·network·packet·filtering
188 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP188 code.·<tt>iptables</tt>·allows·system·operators·to·set·up·firewalls·and·IP
189 masquerading,·etc.189 masquerading,·etc.
190 ······</td>190 ······</td>
191 ····</tr>191 ····</tr>
192 ····<tr>192 ····<tr>
193 ······<td>Req-1.4.1</td>193 ······<td>Req-1.4.1</td>
194 ······<td>Enable·Kernel·Parameter·to·Use·TCP·Syncookies·on·Network·Interfaces</td>194 ······<td>Set·nftables·Configuration·for·Loopback·Traffic</td>
195 ······<td·xml:lang="en-US">195 ······<td·xml:lang="en-US">
196 ········To·set·the·runtime·status·of·the·<code>net.ipv4.tcp_syncookies</code>·kernel·parameter,·run·the·following·command:·<pre>$·sudo·sysctl·-w·net.ipv4.tcp_syncookies=1</pre> 
197 To·make·sure·that·the·setting·is·persistent,·add·the·following·line·to·a·file·in·the·directory·<tt>/etc/sysctl.d</tt>:·<pre>net.ipv4.tcp_syncookies·=·1</pre>196 ········Configure·the·loopback·interface·to·accept·traffic.
 197 Configure·all·other·interfaces·to·deny·traffic·to·the·loopback
 198 network.
198 ······</td>199 ······</td>
199 ······<td·xml:lang="en-US">200 ······<td·xml:lang="en-US">
 201 ········Loopback·traffic·is·generated·between·processes·on·machine·and·is
 202 typically·critical·to·operation·of·the·system.·The·loopback·interface
 203 is·the·only·place·that·loopback·network·traffic·should·be·seen,
 204 all·other·interfaces·should·ignore·traffic·on·this·network·as·an
 205 anti-spoofing·measure.
200 ········A·TCP·SYN·flood·attack·can·cause·a·denial·of·service·by·filling·a 
201 system's·TCP·connection·table·with·connections·in·the·SYN_RCVD·state. 
202 Syncookies·can·be·used·to·track·a·connection·when·a·subsequent·ACK·is·received, 
203 verifying·the·initiator·is·attempting·a·valid·connection·and·is·not·a·flood 
204 source.·This·feature·is·activated·when·a·flood·condition·is·detected,·and 
205 enables·the·system·to·continue·servicing·valid·connection·requests. 
206 ······</td>206 ······</td>
207 ····</tr>207 ····</tr>
208 ····<tr>208 ····<tr>
209 ······<td>Req-1.4.2</td>209 ······<td>Req-1.4.2</td>
210 ······<td>Disable·SCTP·Support</td>210 ······<td>Disable·SCTP·Support</td>
211 ······<td·xml:lang="en-US">211 ······<td·xml:lang="en-US">
212 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a212 ········The·Stream·Control·Transmission·Protocol·(SCTP)·is·a
Offset 246, 41 lines modifiedOffset 246, 22 lines modified
246 ······<td·xml:lang="en-US">246 ······<td·xml:lang="en-US">
Max diff block lines reached; 300947/307529 bytes (97.86%) of diff not shown.
496 KB
html2text {}
Max HTML report size reached
1.31 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
1.18 KB
./usr/share/scap-security-guide/tailoring/ol8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Oracle·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>7 DISA·STIG·for·Oracle·Linux·8·V2R3.</xccdf-1.2:description>
8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>8 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_have_homedir_login_defs"·selected="false"/>
9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>9 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_logon_fail_delay"·selected="false"/>
10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>10 ····<xccdf-1.2:select·idref="xccdf_org.ssgproject.content_rule_accounts_max_concurrent_login_sessions"·selected="false"/>
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel8_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·8</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·8·V2R2.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·8,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
1.12 KB
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
999 B
./usr/share/scap-security-guide/tailoring/rhel9_stig_delta_tailoring.xml
    
Offset 1, 10 lines modifiedOffset 1, 10 lines modified
1 <?xml·version="1.0"·encoding="utf-8"?>1 <?xml·version="1.0"·encoding="utf-8"?>
2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">2 <xccdf-1.2:Tailoring·xmlns:xccdf-1.2="http://checklists.nist.gov/xccdf/1.2"·id="xccdf_content-disa-delta_tailoring_default">
3 ··<xccdf-1.2:version·time="2025-02-28T20:08:00">1</xccdf-1.2:version>3 ··<xccdf-1.2:version·time="2025-03-01T22:08:00">1</xccdf-1.2:version>
4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">4 ··<xccdf-1.2:Profile·id="xccdf_org.ssgproject.content_profile_stig_delta_tailoring"·extends="xccdf_org.ssgproject.content_profile_stig">
5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>5 ····<xccdf-1.2:title·override="true">DISA·STIG·for·Red·Hat·Enterprise·Linux·9</xccdf-1.2:title>
6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the6 ····<xccdf-1.2:description·override="true">This·profile·contains·configuration·checks·that·align·to·the
7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.7 DISA·STIG·for·Red·Hat·Enterprise·Linux·9·V2R3.
  
8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this8 In·addition·to·being·applicable·to·Red·Hat·Enterprise·Linux·9,·this
9 configuration·baseline·is·applicable·to·the·operating·system·tier·of9 configuration·baseline·is·applicable·to·the·operating·system·tier·of
848 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
848 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ds.xml
Max HTML report size reached
720 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
720 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-ocil.xml
Max HTML report size reached
89.0 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-xccdf.xml
88.9 KB
./usr/share/xml/scap/ssg/content/ssg-al2023-xccdf.xml
Ordering differences only
    
Offset 72, 183 lines modifiedOffset 72, 183 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
 80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
 87 ······</cpe-lang:logical-test>
 88 ····</cpe-lang:platform>
79 ····<cpe-lang:platform·id="not_bootc">89 ····<cpe-lang:platform·id="not_aarch64_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="true">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
82 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
87 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="package_systemd">99 ····<cpe-lang:platform·id="package_systemd">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
92 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
 104 ····<cpe-lang:platform·id="package_postfix">
 105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
 107 ······</cpe-lang:logical-test>
 108 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">109 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
99 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="mount_home">116 ····<cpe-lang:platform·id="package_shadow-utils">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
104 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="mount_var-tmp">121 ····<cpe-lang:platform·id="mount_var">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
109 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="mount_var-log">126 ····<cpe-lang:platform·id="package_firewalld">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
114 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">131 ····<cpe-lang:platform·id="package_rsyslog">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
120 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
121 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
122 ····<cpe-lang:platform·id="service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel">136 ····<cpe-lang:platform·id="system_with_kernel">
123 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_iptables:def:1"/> 
125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/> 
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
127 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="mount_var">141 ····<cpe-lang:platform·id="package_chrony">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 144 ······</cpe-lang:logical-test>
 145 ····</cpe-lang:platform>
 146 ····<cpe-lang:platform·id="mount_tmp">
 147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
132 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">151 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
138 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
 157 ····<cpe-lang:platform·id="mount_var-log-audit">
 158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/>
 160 ······</cpe-lang:logical-test>
 161 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="package_rsh-server">162 ····<cpe-lang:platform·id="package_rsh-server">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
143 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="package_pam">167 ····<cpe-lang:platform·id="mount_var-log">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">168 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>
148 ······</cpe-lang:logical-test>170 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>171 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="package_audit">172 ····<cpe-lang:platform·id="not_bootc_and_not_container">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">173 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 174 ········<cpe-lang:logical-test·operator="AND"·negate="true">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>175 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 176 ········</cpe-lang:logical-test>
 177 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 178 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 179 ········</cpe-lang:logical-test>
153 ······</cpe-lang:logical-test>180 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>181 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="non-uefi">182 ····<cpe-lang:platform·id="non-uefi">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">183 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>184 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
158 ······</cpe-lang:logical-test>185 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>186 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="package_chrony">187 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">188 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>189 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>
 190 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
163 ······</cpe-lang:logical-test>191 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>192 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="ipv6_enabled">193 ····<cpe-lang:platform·id="grub2">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">194 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>195 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-al2023-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
Max diff block lines reached; 78480/90913 bytes (86.32%) of diff not shown.
994 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
993 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ds.xml
Max HTML report size reached
857 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
857 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-ocil.xml
Max HTML report size reached
91.6 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-xccdf.xml
91.5 KB
./usr/share/xml/scap/ssg/content/ssg-alinux2-xccdf.xml
Ordering differences only
    
Offset 71, 61 lines modifiedOffset 71, 85 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 85 ········</cpe-lang:logical-test>
81 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="not_bootc">88 ····<cpe-lang:platform·id="not_aarch64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="true">89 ······<cpe-lang:logical-test·operator="AND"·negate="true">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
86 ······</cpe-lang:logical-test> 
87 ····</cpe-lang:platform> 
88 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel"> 
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
92 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="system_with_kernel">93 ····<cpe-lang:platform·id="ipv6_enabled">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
97 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">98 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
103 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="package_systemd">104 ····<cpe-lang:platform·id="package_systemd">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
108 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">109 ····<cpe-lang:platform·id="package_postfix">
 110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
 112 ······</cpe-lang:logical-test>
 113 ····</cpe-lang:platform>
 114 ····<cpe-lang:platform·id="package_shadow-utils">
 115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
 117 ······</cpe-lang:logical-test>
 118 ····</cpe-lang:platform>
 119 ····<cpe-lang:platform·id="package_firewalld">
 120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
 122 ······</cpe-lang:logical-test>
 123 ····</cpe-lang:platform>
 124 ····<cpe-lang:platform·id="package_rsyslog">
 125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 127 ······</cpe-lang:logical-test>
 128 ····</cpe-lang:platform>
 129 ····<cpe-lang:platform·id="system_with_kernel">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
115 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">134 ····<cpe-lang:platform·id="package_chrony">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
120 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
121 ········</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
 138 ····</cpe-lang:platform>
 139 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
122 ········<cpe-lang:logical-test·operator="AND"·negate="true">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
123 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
124 ········</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
 144 ····</cpe-lang:platform>
 145 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 146 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
125 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
126 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
127 ····<cpe-lang:platform·id="x86_64_arch">151 ····<cpe-lang:platform·id="x86_64_arch">
128 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
130 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
Offset 136, 163 lines modifiedOffset 160, 139 lines modified
136 ········</cpe-lang:logical-test>160 ········</cpe-lang:logical-test>
137 ········<cpe-lang:logical-test·operator="AND"·negate="true">161 ········<cpe-lang:logical-test·operator="AND"·negate="true">
138 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>162 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
139 ········</cpe-lang:logical-test>163 ········</cpe-lang:logical-test>
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
141 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">167 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">168 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
147 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="package_pam">173 ····<cpe-lang:platform·id="package_iptables">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
152 ······</cpe-lang:logical-test>176 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>177 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="aarch64_arch">178 ····<cpe-lang:platform·id="not_bootc_and_not_container">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">179 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 180 ········<cpe-lang:logical-test·operator="AND"·negate="true">
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>181 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 182 ········</cpe-lang:logical-test>
 183 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 184 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 185 ········</cpe-lang:logical-test>
157 ······</cpe-lang:logical-test>186 ······</cpe-lang:logical-test>
158 ····</cpe-lang:platform>187 ····</cpe-lang:platform>
159 ····<cpe-lang:platform·id="package_audit">188 ····<cpe-lang:platform·id="non-uefi">
160 ······<cpe-lang:logical-test·operator="AND"·negate="false">189 ······<cpe-lang:logical-test·operator="AND"·negate="false">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>190 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux2-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
162 ······</cpe-lang:logical-test>191 ······</cpe-lang:logical-test>
Max diff block lines reached; 81387/93528 bytes (87.02%) of diff not shown.
990 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
990 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ds.xml
Max HTML report size reached
854 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
854 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-ocil.xml
Max HTML report size reached
89.9 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-xccdf.xml
89.8 KB
./usr/share/xml/scap/ssg/content/ssg-alinux3-xccdf.xml
Ordering differences only
    
Offset 71, 68 lines modifiedOffset 71, 92 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 85 ········</cpe-lang:logical-test>
81 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="not_bootc">88 ····<cpe-lang:platform·id="not_aarch64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="true">89 ······<cpe-lang:logical-test·operator="AND"·negate="true">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
86 ······</cpe-lang:logical-test> 
87 ····</cpe-lang:platform> 
88 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel"> 
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
92 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="system_with_kernel">93 ····<cpe-lang:platform·id="ipv6_enabled">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
97 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">98 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
103 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="package_systemd">104 ····<cpe-lang:platform·id="package_systemd">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
108 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">109 ····<cpe-lang:platform·id="package_postfix">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
115 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">114 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
122 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">121 ····<cpe-lang:platform·id="package_shadow-utils">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
127 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
128 ········</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
 125 ····</cpe-lang:platform>
 126 ····<cpe-lang:platform·id="package_firewalld">
129 ········<cpe-lang:logical-test·operator="AND"·negate="true">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
130 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
131 ········</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
 130 ····</cpe-lang:platform>
 131 ····<cpe-lang:platform·id="package_rsyslog">
 132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 134 ······</cpe-lang:logical-test>
 135 ····</cpe-lang:platform>
 136 ····<cpe-lang:platform·id="system_with_kernel">
 137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 139 ······</cpe-lang:logical-test>
 140 ····</cpe-lang:platform>
 141 ····<cpe-lang:platform·id="package_chrony">
 142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 144 ······</cpe-lang:logical-test>
 145 ····</cpe-lang:platform>
 146 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
 147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
 149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 150 ······</cpe-lang:logical-test>
 151 ····</cpe-lang:platform>
 152 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 153 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
132 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="x86_64_arch">158 ····<cpe-lang:platform·id="x86_64_arch">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
137 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
Offset 143, 147 lines modifiedOffset 167, 123 lines modified
143 ········</cpe-lang:logical-test>167 ········</cpe-lang:logical-test>
144 ········<cpe-lang:logical-test·operator="AND"·negate="true">168 ········<cpe-lang:logical-test·operator="AND"·negate="true">
145 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>169 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
146 ········</cpe-lang:logical-test>170 ········</cpe-lang:logical-test>
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
148 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="wifi-iface">174 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">175 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
153 ······</cpe-lang:logical-test>178 ······</cpe-lang:logical-test>
154 ····</cpe-lang:platform>179 ····</cpe-lang:platform>
155 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">180 ····<cpe-lang:platform·id="package_iptables">
156 ······<cpe-lang:logical-test·operator="AND"·negate="false">181 ······<cpe-lang:logical-test·operator="AND"·negate="false">
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
159 ······</cpe-lang:logical-test>183 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>184 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_pam">185 ····<cpe-lang:platform·id="not_bootc_and_not_container">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">186 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 187 ········<cpe-lang:logical-test·operator="AND"·negate="true">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>188 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-alinux3-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 189 ········</cpe-lang:logical-test>
 190 ········<cpe-lang:logical-test·operator="AND"·negate="true">
Max diff block lines reached; 79244/91865 bytes (86.26%) of diff not shown.
1.16 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
1.16 MB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ds.xml
Max HTML report size reached
996 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
996 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-ocil.xml
Max HTML report size reached
138 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-xccdf.xml
138 KB
./usr/share/xml/scap/ssg/content/ssg-almalinux9-xccdf.xml
Ordering differences only
    
Offset 72, 252 lines modifiedOffset 72, 252 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
82 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="not_bootc">89 ····<cpe-lang:platform·id="not_aarch64_arch">
85 ······<cpe-lang:logical-test·operator="AND"·negate="true">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
87 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
92 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">99 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
98 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
99 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
100 ····<cpe-lang:platform·id="selinux"> 
101 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/> 
103 ······</cpe-lang:logical-test> 
104 ····</cpe-lang:platform> 
105 ····<cpe-lang:platform·id="package_systemd">105 ····<cpe-lang:platform·id="package_systemd">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
108 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="uefi">110 ····<cpe-lang:platform·id="package_postfix">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
113 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
114 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
115 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">115 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
116 ······<cpe-lang:logical-test·operator="AND"·negate="false">116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
120 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
121 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
 122 ····<cpe-lang:platform·id="package_shadow-utils">
122 ····<cpe-lang:platform·id="mount_home"> 
123 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/> 
125 ······</cpe-lang:logical-test> 
126 ····</cpe-lang:platform> 
127 ····<cpe-lang:platform·id="mount_var-tmp"> 
128 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
130 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
132 ····<cpe-lang:platform·id="mount_var-log">127 ····<cpe-lang:platform·id="mount_var">
133 ······<cpe-lang:logical-test·operator="AND"·negate="false">128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
135 ······</cpe-lang:logical-test>130 ······</cpe-lang:logical-test>
136 ····</cpe-lang:platform>131 ····</cpe-lang:platform>
137 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">132 ····<cpe-lang:platform·id="package_firewalld">
138 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
139 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
140 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
141 ········</cpe-lang:logical-test> 
142 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
143 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
144 ········</cpe-lang:logical-test> 
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
146 ······</cpe-lang:logical-test>135 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>136 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="package_polkit">137 ····<cpe-lang:platform·id="package_rsyslog">
149 ······<cpe-lang:logical-test·operator="AND"·negate="false">138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
151 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">142 ····<cpe-lang:platform·id="system_with_kernel">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
155 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
156 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
157 ········</cpe-lang:logical-test> 
158 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
159 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/> 
160 ········</cpe-lang:logical-test> 
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
162 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
163 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
164 ····<cpe-lang:platform·id="wifi-iface">147 ····<cpe-lang:platform·id="package_chrony">
165 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
167 ······</cpe-lang:logical-test> 
168 ····</cpe-lang:platform> 
169 ····<cpe-lang:platform·id="service_disabled_iptables_and_service_disabled_ufw_and_system_with_kernel"> 
170 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_iptables:def:1"/> 
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
174 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="mount_var">152 ····<cpe-lang:platform·id="mount_tmp">
177 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
179 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
180 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
181 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">157 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
182 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
183 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
184 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
185 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
186 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
187 ····<cpe-lang:platform·id="package_rsh-server">163 ····<cpe-lang:platform·id="mount_var-log-audit">
188 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
189 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-almalinux9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/>
190 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
191 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
192 ····<cpe-lang:platform·id="package_pam">168 ····<cpe-lang:platform·id="selinux">
Max diff block lines reached; 128533/141268 bytes (90.99%) of diff not shown.
1.12 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
1.12 MB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ds.xml
Max HTML report size reached
983 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
983 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-ocil.xml
Max HTML report size reached
112 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-xccdf.xml
112 KB
./usr/share/xml/scap/ssg/content/ssg-anolis23-xccdf.xml
Ordering differences only
    
Offset 71, 74 lines modifiedOffset 71, 87 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 85 ········</cpe-lang:logical-test>
81 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="not_bootc">88 ····<cpe-lang:platform·id="not_aarch64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="true">89 ······<cpe-lang:logical-test·operator="AND"·negate="true">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
86 ······</cpe-lang:logical-test> 
87 ····</cpe-lang:platform> 
88 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel"> 
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
92 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="system_with_kernel">93 ····<cpe-lang:platform·id="ipv6_enabled">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
97 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">98 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
103 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="package_systemd">104 ····<cpe-lang:platform·id="package_systemd">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
108 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">109 ····<cpe-lang:platform·id="package_postfix">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
115 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="uefi">114 ····<cpe-lang:platform·id="package_shadow-utils">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
120 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
121 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
122 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">119 ····<cpe-lang:platform·id="package_firewalld">
123 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
124 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
126 ········</cpe-lang:logical-test> 
127 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
128 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
129 ········</cpe-lang:logical-test> 
130 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
132 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">124 ····<cpe-lang:platform·id="package_rsyslog">
133 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 127 ······</cpe-lang:logical-test>
 128 ····</cpe-lang:platform>
 129 ····<cpe-lang:platform·id="system_with_kernel">
 130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 132 ······</cpe-lang:logical-test>
 133 ····</cpe-lang:platform>
 134 ····<cpe-lang:platform·id="package_chrony">
 135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 137 ······</cpe-lang:logical-test>
 138 ····</cpe-lang:platform>
 139 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
 140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
136 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
 145 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 146 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 149 ······</cpe-lang:logical-test>
 150 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="x86_64_arch">151 ····<cpe-lang:platform·id="x86_64_arch">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
141 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">156 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 147, 168 lines modifiedOffset 160, 155 lines modified
147 ········</cpe-lang:logical-test>160 ········</cpe-lang:logical-test>
148 ········<cpe-lang:logical-test·operator="AND"·negate="true">161 ········<cpe-lang:logical-test·operator="AND"·negate="true">
149 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>162 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
150 ········</cpe-lang:logical-test>163 ········</cpe-lang:logical-test>
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
152 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="wifi-iface"> 
155 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
157 ······</cpe-lang:logical-test> 
158 ····</cpe-lang:platform> 
159 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">167 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
160 ······<cpe-lang:logical-test·operator="AND"·negate="false">168 ······<cpe-lang:logical-test·operator="AND"·negate="false">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
163 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="package_rsh-server">173 ····<cpe-lang:platform·id="package_rsh-server">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
168 ······</cpe-lang:logical-test>176 ······</cpe-lang:logical-test>
169 ····</cpe-lang:platform>177 ····</cpe-lang:platform>
170 ····<cpe-lang:platform·id="package_pam">178 ····<cpe-lang:platform·id="package_iptables">
171 ······<cpe-lang:logical-test·operator="AND"·negate="false">179 ······<cpe-lang:logical-test·operator="AND"·negate="false">
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis23-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
Max diff block lines reached; 102022/114134 bytes (89.39%) of diff not shown.
1.12 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
1.12 MB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ds.xml
Max HTML report size reached
984 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
984 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-ocil.xml
Max HTML report size reached
112 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-xccdf.xml
111 KB
./usr/share/xml/scap/ssg/content/ssg-anolis8-xccdf.xml
Ordering differences only
    
Offset 71, 74 lines modifiedOffset 71, 87 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 85 ········</cpe-lang:logical-test>
81 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="not_bootc">88 ····<cpe-lang:platform·id="not_aarch64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="true">89 ······<cpe-lang:logical-test·operator="AND"·negate="true">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
86 ······</cpe-lang:logical-test> 
87 ····</cpe-lang:platform> 
88 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel"> 
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
92 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="system_with_kernel">93 ····<cpe-lang:platform·id="ipv6_enabled">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
97 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">98 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
103 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="package_systemd">104 ····<cpe-lang:platform·id="package_systemd">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
108 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">109 ····<cpe-lang:platform·id="package_postfix">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
115 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="uefi">114 ····<cpe-lang:platform·id="package_shadow-utils">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
120 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
121 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
122 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">119 ····<cpe-lang:platform·id="package_firewalld">
123 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
124 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
126 ········</cpe-lang:logical-test> 
127 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
128 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
129 ········</cpe-lang:logical-test> 
130 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
132 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">124 ····<cpe-lang:platform·id="package_rsyslog">
133 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 127 ······</cpe-lang:logical-test>
 128 ····</cpe-lang:platform>
 129 ····<cpe-lang:platform·id="system_with_kernel">
 130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 132 ······</cpe-lang:logical-test>
 133 ····</cpe-lang:platform>
 134 ····<cpe-lang:platform·id="package_chrony">
 135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 137 ······</cpe-lang:logical-test>
 138 ····</cpe-lang:platform>
 139 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
 140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
136 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
 145 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 146 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 149 ······</cpe-lang:logical-test>
 150 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="x86_64_arch">151 ····<cpe-lang:platform·id="x86_64_arch">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
141 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">156 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 147, 168 lines modifiedOffset 160, 155 lines modified
147 ········</cpe-lang:logical-test>160 ········</cpe-lang:logical-test>
148 ········<cpe-lang:logical-test·operator="AND"·negate="true">161 ········<cpe-lang:logical-test·operator="AND"·negate="true">
149 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>162 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
150 ········</cpe-lang:logical-test>163 ········</cpe-lang:logical-test>
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
152 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="wifi-iface"> 
155 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
157 ······</cpe-lang:logical-test> 
158 ····</cpe-lang:platform> 
159 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">167 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
160 ······<cpe-lang:logical-test·operator="AND"·negate="false">168 ······<cpe-lang:logical-test·operator="AND"·negate="false">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
163 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="package_rsh-server">173 ····<cpe-lang:platform·id="package_rsh-server">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
168 ······</cpe-lang:logical-test>176 ······</cpe-lang:logical-test>
169 ····</cpe-lang:platform>177 ····</cpe-lang:platform>
170 ····<cpe-lang:platform·id="package_pam">178 ····<cpe-lang:platform·id="package_iptables">
171 ······<cpe-lang:logical-test·operator="AND"·negate="false">179 ······<cpe-lang:logical-test·operator="AND"·negate="false">
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-anolis8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
Max diff block lines reached; 101963/114036 bytes (89.41%) of diff not shown.
4.56 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
4.56 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-ds.xml
Max HTML report size reached
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-centos8-xccdf.xml
Max HTML report size reached
3.02 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
3.02 MB
./usr/share/xml/scap/ssg/content/ssg-cs10-ds.xml
Max HTML report size reached
879 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
879 KB
./usr/share/xml/scap/ssg/content/ssg-cs10-xccdf.xml
Max HTML report size reached
4.35 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
4.35 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-ds.xml
Max HTML report size reached
1.07 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
1.07 MB
./usr/share/xml/scap/ssg/content/ssg-cs9-xccdf.xml
Max HTML report size reached
2.89 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
2.89 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ds.xml
Max HTML report size reached
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-fedora-ocil.xml
Max HTML report size reached
840 KB
./usr/share/xml/scap/ssg/content/ssg-fedora-xccdf.xml
840 KB
./usr/share/xml/scap/ssg/content/ssg-fedora-xccdf.xml
Max HTML report size reached
276 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
276 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ds.xml
    
Offset 19, 15 lines modifiedOffset 19, 15 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-kylinserver10-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-kylinserver10-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">28 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP1:ga:server">
29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP1</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">32 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP2:ga:server">
33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>33 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP2</cpe-dict:title>
Offset 35, 15 lines modifiedOffset 35, 15 lines modified
35 ······</cpe-dict:cpe-item>35 ······</cpe-dict:cpe-item>
36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">36 ······<cpe-dict:cpe-item·name="cpe:/o:Kylin:Kylin:V10_SP3:ga:server">
37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>37 ········<cpe-dict:title·xml:lang="en-us">Kylin·V10·SP3</cpe-dict:title>
38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>38 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml">oval:ssg-installed_OS_is_kylinserver10:def:1</cpe-dict:check>
39 ······</cpe-dict:cpe-item>39 ······</cpe-dict:cpe-item>
40 ····</cpe-dict:cpe-list>40 ····</cpe-dict:cpe-list>
41 ··</ds:component>41 ··</ds:component>
42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-02-28T20:08:00">42 ··<ds:component·id="scap_org.open-scap_comp_ssg-kylinserver10-xccdf.xml"·timestamp="2025-03-01T22:08:00">
43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">43 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_KYLINSERVER10"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>44 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>45 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Kylin·Server·10</xccdf-1.2:title>
46 ······<xccdf-1.2:description>46 ······<xccdf-1.2:description>
47 ········This·guide·presents·a·catalog·of·security-relevant47 ········This·guide·presents·a·catalog·of·security-relevant
48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of48 configuration·settings·for·Kylin·Server·10.·It·is·a·rendering·of
49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)49 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 112, 83 lines modifiedOffset 112, 83 lines modified
112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>112 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
113 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>113 ······<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
114 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>114 ······<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
115 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>115 ······<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>116 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>117 ······<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
118 ······<cpe-lang:platform-specification>118 ······<cpe-lang:platform-specification>
119 ········<cpe-lang:platform·id="machine">119 ········<cpe-lang:platform·id="package_shadow-utils">
120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">120 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>121 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
122 ··········</cpe-lang:logical-test>122 ··········</cpe-lang:logical-test>
123 ········</cpe-lang:platform>123 ········</cpe-lang:platform>
124 ········<cpe-lang:platform·id="system_with_kernel">124 ········<cpe-lang:platform·id="package_firewalld">
125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">125 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>126 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
127 ··········</cpe-lang:logical-test>127 ··········</cpe-lang:logical-test>
128 ········</cpe-lang:platform>128 ········</cpe-lang:platform>
129 ········<cpe-lang:platform·id="uefi">129 ········<cpe-lang:platform·id="package_rsyslog">
130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">130 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>131 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
132 ··········</cpe-lang:logical-test>132 ··········</cpe-lang:logical-test>
133 ········</cpe-lang:platform>133 ········</cpe-lang:platform>
134 ········<cpe-lang:platform·id="grub2_and_system_with_kernel">134 ········<cpe-lang:platform·id="system_with_kernel">
135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">135 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/> 
137 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>136 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
138 ··········</cpe-lang:logical-test>137 ··········</cpe-lang:logical-test>
139 ········</cpe-lang:platform>138 ········</cpe-lang:platform>
140 ········<cpe-lang:platform·id="package_pam">139 ········<cpe-lang:platform·id="package_chrony">
141 ··········<cpe-lang:logical-test·operator="AND"·negate="false">140 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
142 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>141 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
143 ··········</cpe-lang:logical-test>142 ··········</cpe-lang:logical-test>
144 ········</cpe-lang:platform>143 ········</cpe-lang:platform>
145 ········<cpe-lang:platform·id="package_audit">144 ········<cpe-lang:platform·id="grub2_and_system_with_kernel">
146 ··········<cpe-lang:logical-test·operator="AND"·negate="false">145 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
 146 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>147 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
148 ··········</cpe-lang:logical-test>148 ··········</cpe-lang:logical-test>
149 ········</cpe-lang:platform>149 ········</cpe-lang:platform>
150 ········<cpe-lang:platform·id="non-uefi">150 ········<cpe-lang:platform·id="uefi">
151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">151 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>152 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
153 ··········</cpe-lang:logical-test>153 ··········</cpe-lang:logical-test>
154 ········</cpe-lang:platform>154 ········</cpe-lang:platform>
155 ········<cpe-lang:platform·id="package_gdm">155 ········<cpe-lang:platform·id="non-uefi">
156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">156 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>157 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
158 ··········</cpe-lang:logical-test>158 ··········</cpe-lang:logical-test>
159 ········</cpe-lang:platform>159 ········</cpe-lang:platform>
160 ········<cpe-lang:platform·id="package_chrony">160 ········<cpe-lang:platform·id="machine">
161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">161 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>162 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
163 ··········</cpe-lang:logical-test>163 ··········</cpe-lang:logical-test>
164 ········</cpe-lang:platform>164 ········</cpe-lang:platform>
165 ········<cpe-lang:platform·id="package_dnf">165 ········<cpe-lang:platform·id="package_dnf">
166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">166 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>167 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
168 ··········</cpe-lang:logical-test>168 ··········</cpe-lang:logical-test>
169 ········</cpe-lang:platform>169 ········</cpe-lang:platform>
170 ········<cpe-lang:platform·id="package_shadow-utils">170 ········<cpe-lang:platform·id="package_pam">
171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">171 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>172 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
173 ··········</cpe-lang:logical-test>173 ··········</cpe-lang:logical-test>
174 ········</cpe-lang:platform>174 ········</cpe-lang:platform>
175 ········<cpe-lang:platform·id="package_rsyslog">175 ········<cpe-lang:platform·id="package_bash">
176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">176 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>177 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
178 ··········</cpe-lang:logical-test>178 ··········</cpe-lang:logical-test>
179 ········</cpe-lang:platform>179 ········</cpe-lang:platform>
180 ········<cpe-lang:platform·id="package_firewalld">180 ········<cpe-lang:platform·id="package_gdm">
181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">181 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>182 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
183 ··········</cpe-lang:logical-test>183 ··········</cpe-lang:logical-test>
184 ········</cpe-lang:platform>184 ········</cpe-lang:platform>
185 ········<cpe-lang:platform·id="package_bash">185 ········<cpe-lang:platform·id="package_audit">
186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">186 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>187 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
188 ··········</cpe-lang:logical-test>188 ··········</cpe-lang:logical-test>
189 ········</cpe-lang:platform>189 ········</cpe-lang:platform>
190 ········<cpe-lang:platform·id="package_sudo">190 ········<cpe-lang:platform·id="package_sudo">
191 ··········<cpe-lang:logical-test·operator="AND"·negate="false">191 ··········<cpe-lang:logical-test·operator="AND"·negate="false">
192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>192 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
193 ··········</cpe-lang:logical-test>193 ··········</cpe-lang:logical-test>
194 ········</cpe-lang:platform>194 ········</cpe-lang:platform>
Offset 843, 17 lines modifiedOffset 843, 14 lines modified
843 ··················<xccdf-1.2:reference·href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-3</xccdf-1.2:reference>843 ··················<xccdf-1.2:reference·href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-3</xccdf-1.2:reference>
844 ··················<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>844 ··················<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>
845 ··················<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000445-GPOS-00199</xccdf-1.2:reference>845 ··················<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000445-GPOS-00199</xccdf-1.2:reference>
846 ··················<xccdf-1.2:reference·href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>846 ··················<xccdf-1.2:reference·href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>
847 ··················<xccdf-1.2:reference·href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R79</xccdf-1.2:reference>847 ··················<xccdf-1.2:reference·href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R79</xccdf-1.2:reference>
848 ··················<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>848 ··················<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>
849 ··················<xccdf-1.2:rationale>The·AIDE·package·must·be·installed·if·it·is·to·be·available·for·integrity·checking.</xccdf-1.2:rationale>849 ··················<xccdf-1.2:rationale>The·AIDE·package·must·be·installed·if·it·is·to·be·available·for·integrity·checking.</xccdf-1.2:rationale>
850 ··················<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="package_aide_installed">[[packages]] 
851 name·=·"aide" 
852 version·=·"*"</xccdf-1.2:fix> 
Max diff block lines reached; 268904/282500 bytes (95.19%) of diff not shown.
227 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
227 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-ocil.xml
Ordering differences only
    
Offset 3, 733 lines modifiedOffset 3, 733 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_unix_remember_ocil:questionnaire:1"> 
11 ······<ocil:title>Limit·Password·Reuse</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_unix_remember_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_ip_forward_ocil:questionnaire:1">
17 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·all·IPv4·Interfaces</ocil:title>11 ······<ocil:title>Disable·Kernel·Parameter·for·IP·Forwarding·on·IPv4·Interfaces</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_all_accept_source_route_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_ip_forward_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
22 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_etc_shadow_ocil:questionnaire:1">16 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">
23 ······<ocil:title>Verify·Permissions·on·shadow·File</ocil:title>17 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>
24 ······<ocil:actions>18 ······<ocil:actions>
25 ········<ocil:test_action_ref>ocil:ssg-file_permissions_etc_shadow_action:testaction:1</ocil:test_action_ref>19 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>
26 ······</ocil:actions>20 ······</ocil:actions>
27 ····</ocil:questionnaire>21 ····</ocil:questionnaire>
28 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_ocil:questionnaire:1"> 
29 ······<ocil:title>Configure·Kernel·Parameter·for·Accepting·Secure·Redirects·By·Default</ocil:title>22 ····<ocil:questionnaire·id="ocil:ssg-package_net-snmp_removed_ocil:questionnaire:1">
 23 ······<ocil:title>Uninstall·net-snmp·Package</ocil:title>
30 ······<ocil:actions>24 ······<ocil:actions>
31 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_secure_redirects_action:testaction:1</ocil:test_action_ref>25 ········<ocil:test_action_ref>ocil:ssg-package_net-snmp_removed_action:testaction:1</ocil:test_action_ref>
32 ······</ocil:actions>26 ······</ocil:actions>
33 ····</ocil:questionnaire>27 ····</ocil:questionnaire>
34 ····<ocil:questionnaire·id="ocil:ssg-ensure_gpgcheck_globally_activated_ocil:questionnaire:1"> 
35 ······<ocil:title>Ensure·gpgcheck·Enabled·In·Main·dnf·Configuration</ocil:title>28 ····<ocil:questionnaire·id="ocil:ssg-rsyslog_logging_configured_ocil:questionnaire:1">
 29 ······<ocil:title>Ensure·logging·is·configured</ocil:title>
36 ······<ocil:actions>30 ······<ocil:actions>
37 ········<ocil:test_action_ref>ocil:ssg-ensure_gpgcheck_globally_activated_action:testaction:1</ocil:test_action_ref>31 ········<ocil:test_action_ref>ocil:ssg-rsyslog_logging_configured_action:testaction:1</ocil:test_action_ref>
38 ······</ocil:actions>32 ······</ocil:actions>
39 ····</ocil:questionnaire>33 ····</ocil:questionnaire>
40 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">34 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_warn_age_login_defs_ocil:questionnaire:1">
41 ······<ocil:title>Set·Password·Warning·Age</ocil:title>35 ······<ocil:title>Set·Password·Warning·Age</ocil:title>
42 ······<ocil:actions>36 ······<ocil:actions>
43 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>37 ········<ocil:test_action_ref>ocil:ssg-accounts_password_warn_age_login_defs_action:testaction:1</ocil:test_action_ref>
44 ······</ocil:actions>38 ······</ocil:actions>
45 ····</ocil:questionnaire>39 ····</ocil:questionnaire>
46 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_root_login_ocil:questionnaire:1">40 ····<ocil:questionnaire·id="ocil:ssg-file_owner_etc_passwd_ocil:questionnaire:1">
47 ······<ocil:title>Disable·SSH·Root·Login</ocil:title>41 ······<ocil:title>Verify·User·Who·Owns·passwd·File</ocil:title>
48 ······<ocil:actions>42 ······<ocil:actions>
49 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_root_login_action:testaction:1</ocil:test_action_ref>43 ········<ocil:test_action_ref>ocil:ssg-file_owner_etc_passwd_action:testaction:1</ocil:test_action_ref>
50 ······</ocil:actions>44 ······</ocil:actions>
51 ····</ocil:questionnaire>45 ····</ocil:questionnaire>
52 ····<ocil:questionnaire·id="ocil:ssg-sudo_add_use_pty_ocil:questionnaire:1">46 ····<ocil:questionnaire·id="ocil:ssg-accounts_max_concurrent_login_sessions_ocil:questionnaire:1">
53 ······<ocil:title>Ensure·Only·Users·Logged·In·To·Real·tty·Can·Execute·Sudo·-·sudo·use_pty</ocil:title>47 ······<ocil:title>Limit·the·Number·of·Concurrent·Login·Sessions·Allowed·Per·User</ocil:title>
54 ······<ocil:actions>48 ······<ocil:actions>
55 ········<ocil:test_action_ref>ocil:ssg-sudo_add_use_pty_action:testaction:1</ocil:test_action_ref>49 ········<ocil:test_action_ref>ocil:ssg-accounts_max_concurrent_login_sessions_action:testaction:1</ocil:test_action_ref>
56 ······</ocil:actions>50 ······</ocil:actions>
57 ····</ocil:questionnaire>51 ····</ocil:questionnaire>
58 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">52 ····<ocil:questionnaire·id="ocil:ssg-sudoers_validate_passwd_ocil:questionnaire:1">
59 ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title>53 ······<ocil:title>Ensure·invoking·users·password·for·privilege·escalation·when·using·sudo</ocil:title>
60 ······<ocil:actions>54 ······<ocil:actions>
61 ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>55 ········<ocil:test_action_ref>ocil:ssg-sudoers_validate_passwd_action:testaction:1</ocil:test_action_ref>
62 ······</ocil:actions>56 ······</ocil:actions>
63 ····</ocil:questionnaire>57 ····</ocil:questionnaire>
64 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_ocil:questionnaire:1"> 
65 ······<ocil:title>Disable·Kernel·Parameter·for·Accepting·Source-Routed·Packets·on·IPv4·Interfaces·by·Default</ocil:title>58 ····<ocil:questionnaire·id="ocil:ssg-service_sshd_enabled_ocil:questionnaire:1">
 59 ······<ocil:title>Enable·the·OpenSSH·Service</ocil:title>
66 ······<ocil:actions>60 ······<ocil:actions>
67 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_accept_source_route_action:testaction:1</ocil:test_action_ref>61 ········<ocil:test_action_ref>ocil:ssg-service_sshd_enabled_action:testaction:1</ocil:test_action_ref>
68 ······</ocil:actions>62 ······</ocil:actions>
69 ····</ocil:questionnaire>63 ····</ocil:questionnaire>
70 ····<ocil:questionnaire·id="ocil:ssg-accounts_root_path_dirs_no_write_ocil:questionnaire:1">64 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_dcredit_ocil:questionnaire:1">
71 ······<ocil:title>Ensure·that·Root's·Path·Does·Not·Include·World·or·Group-Writable·Directories</ocil:title>65 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Digit·Characters</ocil:title>
72 ······<ocil:actions>66 ······<ocil:actions>
73 ········<ocil:test_action_ref>ocil:ssg-accounts_root_path_dirs_no_write_action:testaction:1</ocil:test_action_ref>67 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_dcredit_action:testaction:1</ocil:test_action_ref>
74 ······</ocil:actions>68 ······</ocil:actions>
75 ····</ocil:questionnaire>69 ····</ocil:questionnaire>
76 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_ocil:questionnaire:1">70 ····<ocil:questionnaire·id="ocil:ssg-package_ypbind_removed_ocil:questionnaire:1">
77 ······<ocil:title>Prevent·Login·to·Accounts·With·Empty·Password</ocil:title>71 ······<ocil:title>Remove·NIS·Client</ocil:title>
78 ······<ocil:actions>72 ······<ocil:actions>
79 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_action:testaction:1</ocil:test_action_ref>73 ········<ocil:test_action_ref>ocil:ssg-package_ypbind_removed_action:testaction:1</ocil:test_action_ref>
80 ······</ocil:actions>74 ······</ocil:actions>
81 ····</ocil:questionnaire>75 ····</ocil:questionnaire>
82 ····<ocil:questionnaire·id="ocil:ssg-sshd_disable_empty_passwords_ocil:questionnaire:1">76 ····<ocil:questionnaire·id="ocil:ssg-sshd_print_last_log_ocil:questionnaire:1">
83 ······<ocil:title>Disable·SSH·Access·via·Empty·Passwords</ocil:title>77 ······<ocil:title>Enable·SSH·Print·Last·Log</ocil:title>
84 ······<ocil:actions>78 ······<ocil:actions>
85 ········<ocil:test_action_ref>ocil:ssg-sshd_disable_empty_passwords_action:testaction:1</ocil:test_action_ref>79 ········<ocil:test_action_ref>ocil:ssg-sshd_print_last_log_action:testaction:1</ocil:test_action_ref>
86 ······</ocil:actions>80 ······</ocil:actions>
87 ····</ocil:questionnaire>81 ····</ocil:questionnaire>
88 ····<ocil:questionnaire·id="ocil:ssg-package_chrony_installed_ocil:questionnaire:1">82 ····<ocil:questionnaire·id="ocil:ssg-accounts_password_pam_lcredit_ocil:questionnaire:1">
89 ······<ocil:title>The·Chrony·package·is·installed</ocil:title>83 ······<ocil:title>Ensure·PAM·Enforces·Password·Requirements·-·Minimum·Lowercase·Characters</ocil:title>
90 ······<ocil:actions>84 ······<ocil:actions>
91 ········<ocil:test_action_ref>ocil:ssg-package_chrony_installed_action:testaction:1</ocil:test_action_ref>85 ········<ocil:test_action_ref>ocil:ssg-accounts_password_pam_lcredit_action:testaction:1</ocil:test_action_ref>
92 ······</ocil:actions>86 ······</ocil:actions>
93 ····</ocil:questionnaire>87 ····</ocil:questionnaire>
94 ····<ocil:questionnaire·id="ocil:ssg-postfix_client_configure_mail_alias_ocil:questionnaire:1">88 ····<ocil:questionnaire·id="ocil:ssg-disable_host_auth_ocil:questionnaire:1">
95 ······<ocil:title>Configure·System·to·Forward·All·Mail·For·The·Root·Account</ocil:title>89 ······<ocil:title>Disable·Host-Based·Authentication</ocil:title>
96 ······<ocil:actions>90 ······<ocil:actions>
97 ········<ocil:test_action_ref>ocil:ssg-postfix_client_configure_mail_alias_action:testaction:1</ocil:test_action_ref>91 ········<ocil:test_action_ref>ocil:ssg-disable_host_auth_action:testaction:1</ocil:test_action_ref>
98 ······</ocil:actions>92 ······</ocil:actions>
99 ····</ocil:questionnaire>93 ····</ocil:questionnaire>
100 ····<ocil:questionnaire·id="ocil:ssg-accounts_umask_etc_bashrc_ocil:questionnaire:1">94 ····<ocil:questionnaire·id="ocil:ssg-no_empty_passwords_etc_shadow_ocil:questionnaire:1">
101 ······<ocil:title>Ensure·the·Default·Bash·Umask·is·Set·Correctly</ocil:title>95 ······<ocil:title>Ensure·There·Are·No·Accounts·With·Blank·or·Null·Passwords</ocil:title>
102 ······<ocil:actions>96 ······<ocil:actions>
103 ········<ocil:test_action_ref>ocil:ssg-accounts_umask_etc_bashrc_action:testaction:1</ocil:test_action_ref>97 ········<ocil:test_action_ref>ocil:ssg-no_empty_passwords_etc_shadow_action:testaction:1</ocil:test_action_ref>
104 ······</ocil:actions>98 ······</ocil:actions>
105 ····</ocil:questionnaire>99 ····</ocil:questionnaire>
106 ····<ocil:questionnaire·id="ocil:ssg-dconf_gnome_screensaver_mode_blank_ocil:questionnaire:1">100 ····<ocil:questionnaire·id="ocil:ssg-accounts_minimum_age_login_defs_ocil:questionnaire:1">
107 ······<ocil:title>Implement·Blank·Screensaver</ocil:title>101 ······<ocil:title>Set·Password·Minimum·Age</ocil:title>
108 ······<ocil:actions>102 ······<ocil:actions>
109 ········<ocil:test_action_ref>ocil:ssg-dconf_gnome_screensaver_mode_blank_action:testaction:1</ocil:test_action_ref>103 ········<ocil:test_action_ref>ocil:ssg-accounts_minimum_age_login_defs_action:testaction:1</ocil:test_action_ref>
110 ······</ocil:actions>104 ······</ocil:actions>
111 ····</ocil:questionnaire>105 ····</ocil:questionnaire>
112 ····<ocil:questionnaire·id="ocil:ssg-service_auditd_enabled_ocil:questionnaire:1">106 ····<ocil:questionnaire·id="ocil:ssg-file_permissions_ungroupowned_ocil:questionnaire:1">
113 ······<ocil:title>Enable·auditd·Service</ocil:title>107 ······<ocil:title>Ensure·All·Files·Are·Owned·by·a·Group</ocil:title>
114 ······<ocil:actions>108 ······<ocil:actions>
115 ········<ocil:test_action_ref>ocil:ssg-service_auditd_enabled_action:testaction:1</ocil:test_action_ref>109 ········<ocil:test_action_ref>ocil:ssg-file_permissions_ungroupowned_action:testaction:1</ocil:test_action_ref>
116 ······</ocil:actions>110 ······</ocil:actions>
117 ····</ocil:questionnaire>111 ····</ocil:questionnaire>
118 ····<ocil:questionnaire·id="ocil:ssg-use_pam_wheel_for_su_ocil:questionnaire:1"> 
119 ······<ocil:title>Enforce·usage·of·pam_wheel·for·su·authentication</ocil:title>112 ····<ocil:questionnaire·id="ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_ocil:questionnaire:1">
 113 ······<ocil:title>Enable·Kernel·Parameter·to·Use·Reverse·Path·Filtering·on·all·IPv4·Interfaces·by·Default</ocil:title>
120 ······<ocil:actions>114 ······<ocil:actions>
121 ········<ocil:test_action_ref>ocil:ssg-use_pam_wheel_for_su_action:testaction:1</ocil:test_action_ref>115 ········<ocil:test_action_ref>ocil:ssg-sysctl_net_ipv4_conf_default_rp_filter_action:testaction:1</ocil:test_action_ref>
122 ······</ocil:actions>116 ······</ocil:actions>
123 ····</ocil:questionnaire>117 ····</ocil:questionnaire>
124 ····<ocil:questionnaire·id="ocil:ssg-package_binutils_installed_ocil:questionnaire:1">118 ····<ocil:questionnaire·id="ocil:ssg-service_rsyslog_enabled_ocil:questionnaire:1">
125 ······<ocil:title>Install·binutils·Package</ocil:title>119 ······<ocil:title>Enable·rsyslog·Service</ocil:title>
Max diff block lines reached; 220026/232136 bytes (94.78%) of diff not shown.
33.0 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-xccdf.xml
32.9 KB
./usr/share/xml/scap/ssg/content/ssg-kylinserver10-xccdf.xml
Ordering differences only
    
Offset 71, 83 lines modifiedOffset 71, 83 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="package_shadow-utils">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
81 ······</cpe-lang:logical-test>81 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>82 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="system_with_kernel">83 ····<cpe-lang:platform·id="package_firewalld">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
86 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="uefi">88 ····<cpe-lang:platform·id="package_rsyslog">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">89 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
91 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
92 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
93 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">93 ····<cpe-lang:platform·id="system_with_kernel">
94 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/> 
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
97 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_pam">98 ····<cpe-lang:platform·id="package_chrony">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
102 ······</cpe-lang:logical-test>101 ······</cpe-lang:logical-test>
103 ····</cpe-lang:platform>102 ····</cpe-lang:platform>
104 ····<cpe-lang:platform·id="package_audit">103 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
105 ······<cpe-lang:logical-test·operator="AND"·negate="false">104 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
107 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="non-uefi">109 ····<cpe-lang:platform·id="uefi">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
112 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_gdm">114 ····<cpe-lang:platform·id="non-uefi">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
117 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_chrony">119 ····<cpe-lang:platform·id="machine">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
122 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_dnf">124 ····<cpe-lang:platform·id="package_dnf">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_dnf:def:1"/>
127 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="package_shadow-utils">129 ····<cpe-lang:platform·id="package_pam">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
132 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="package_rsyslog">134 ····<cpe-lang:platform·id="package_bash">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>
137 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="package_firewalld">139 ····<cpe-lang:platform·id="package_gdm">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>
142 ······</cpe-lang:logical-test>142 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>143 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="package_bash">144 ····<cpe-lang:platform·id="package_audit">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">145 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_bash:def:1"/>146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>
147 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="package_sudo">149 ····<cpe-lang:platform·id="package_sudo">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">150 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-kylinserver10-cpe-oval.xml"·id-ref="oval:ssg-package_sudo:def:1"/>
152 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
Offset 802, 17 lines modifiedOffset 802, 14 lines modified
802 ··············<xccdf-1.2:reference·href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-3</xccdf-1.2:reference>802 ··············<xccdf-1.2:reference·href="https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.04162018.pdf">PR.IP-3</xccdf-1.2:reference>
803 ··············<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>803 ··············<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">Req-11.5</xccdf-1.2:reference>
804 ··············<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000445-GPOS-00199</xccdf-1.2:reference>804 ··············<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">SRG-OS-000445-GPOS-00199</xccdf-1.2:reference>
805 ··············<xccdf-1.2:reference·href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>805 ··············<xccdf-1.2:reference·href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R76</xccdf-1.2:reference>
806 ··············<xccdf-1.2:reference·href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R79</xccdf-1.2:reference>806 ··············<xccdf-1.2:reference·href="https://cyber.gouv.fr/sites/default/files/document/linux_configuration-en-v2.pdf">R79</xccdf-1.2:reference>
807 ··············<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>807 ··············<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">11.5.2</xccdf-1.2:reference>
808 ··············<xccdf-1.2:rationale>The·AIDE·package·must·be·installed·if·it·is·to·be·available·for·integrity·checking.</xccdf-1.2:rationale>808 ··············<xccdf-1.2:rationale>The·AIDE·package·must·be·installed·if·it·is·to·be·available·for·integrity·checking.</xccdf-1.2:rationale>
809 ··············<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="package_aide_installed">[[packages]] 
810 name·=·"aide" 
811 version·=·"*"</xccdf-1.2:fix> 
812 ··············<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="package_aide_installed"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">-·name:·Gather·the·package·facts809 ··············<xccdf-1.2:fix·system="urn:xccdf:fix:script:ansible"·id="package_aide_installed"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">-·name:·Gather·the·package·facts
813 ··package_facts:810 ··package_facts:
814 ····manager:·auto811 ····manager:·auto
815 ··tags:812 ··tags:
816 ··-·CJIS-5.10.1.3813 ··-·CJIS-5.10.1.3
817 ··-·NIST-800-53-CM-6(a)814 ··-·NIST-800-53-CM-6(a)
818 ··-·PCI-DSS-Req-11.5815 ··-·PCI-DSS-Req-11.5
Offset 836, 14 lines modifiedOffset 833, 17 lines modified
836 ··-·PCI-DSSv4-11.5.2833 ··-·PCI-DSSv4-11.5.2
837 ··-·enable_strategy834 ··-·enable_strategy
838 ··-·low_complexity835 ··-·low_complexity
839 ··-·low_disruption836 ··-·low_disruption
840 ··-·medium_severity837 ··-·medium_severity
841 ··-·no_reboot_needed838 ··-·no_reboot_needed
842 ··-·package_aide_installed</xccdf-1.2:fix>839 ··-·package_aide_installed</xccdf-1.2:fix>
 840 ··············<xccdf-1.2:fix·system="urn:redhat:osbuild:blueprint"·id="package_aide_installed">[[packages]]
 841 name·=·"aide"
 842 version·=·"*"</xccdf-1.2:fix>
843 ··············<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="package_aide_installed"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·install_aide843 ··············<xccdf-1.2:fix·system="urn:xccdf:fix:script:puppet"·id="package_aide_installed"·complexity="low"·disruption="low"·reboot="false"·strategy="enable">include·install_aide
  
844 class·install_aide·{844 class·install_aide·{
845 ··package·{·'aide':845 ··package·{·'aide':
846 ····ensure·=&gt;·'installed',846 ····ensure·=&gt;·'installed',
847 ··}847 ··}
848 }</xccdf-1.2:fix>848 }</xccdf-1.2:fix>
Offset 2318, 28 lines modifiedOffset 2318, 28 lines modified
2318 ············<html:code>nm</html:code>2318 ············<html:code>nm</html:code>
2319 ············,2319 ············,
2320 ············<html:code>objcopy</html:code>2320 ············<html:code>objcopy</html:code>
2321 ············and2321 ············and
2322 ············<html:code>readelf</html:code>2322 ············<html:code>readelf</html:code>
2323 ············.2323 ············.
Max diff block lines reached; 22141/33542 bytes (66.01%) of diff not shown.
9.12 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
9.02 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ds.xml
    
Offset 19, 23 lines modifiedOffset 19, 23 lines modified
19 ····</ds:checklists>19 ····</ds:checklists>
20 ····<ds:checks>20 ····<ds:checks>
21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>21 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-oval.xml"/>
22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>22 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-ocil.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-ocil.xml"/>
23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>23 ······<ds:component-ref·id="scap_org.open-scap_cref_ssg-macos1015-cpe-oval.xml"·xlink:href="#scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"/>
24 ····</ds:checks>24 ····</ds:checks>
25 ··</ds:data-stream>25 ··</ds:data-stream>
26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-02-28T20:08:00">26 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-dictionary.xml"·timestamp="2025-03-01T22:08:00">
27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">27 ····<cpe-dict:cpe-list·xsi:schemaLocation="http://cpe.mitre.org/dictionary/2.0·http://cpe.mitre.org/files/cpe-dictionary_2.1.xsd">
28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">28 ······<cpe-dict:cpe-item·name="cpe:/o:apple:macos:10.15">
29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>29 ········<cpe-dict:title·xml:lang="en-us">Apple·macOS·10.15</cpe-dict:title>
30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>30 ········<cpe-dict:check·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-macos1015-cpe-oval.xml">oval:ssg-installed_OS_is_macos1015:def:1</cpe-dict:check>
31 ······</cpe-dict:cpe-item>31 ······</cpe-dict:cpe-item>
32 ····</cpe-dict:cpe-list>32 ····</cpe-dict:cpe-list>
33 ··</ds:component>33 ··</ds:component>
34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-02-28T20:08:00">34 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-xccdf.xml"·timestamp="2025-03-01T22:08:00">
35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">35 ····<xccdf-1.2:Benchmark·id="xccdf_org.ssgproject.content_benchmark_macOS-1015"·xsi:schemaLocation="http://checklists.nist.gov/xccdf/1.2·xccdf-1.2.xsd"·style="SCAP_1.2"·resolved="true"·xml:lang="en-US">
36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>36 ······<xccdf-1.2:status·date="2025-03-01">draft</xccdf-1.2:status>
37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>37 ······<xccdf-1.2:title>Guide·to·the·Secure·Configuration·of·Apple·macOS·10.15</xccdf-1.2:title>
38 ······<xccdf-1.2:description>38 ······<xccdf-1.2:description>
39 ········This·guide·presents·a·catalog·of·security-relevant39 ········This·guide·presents·a·catalog·of·security-relevant
40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of40 configuration·settings·for·Apple·macOS·10.15.·It·is·a·rendering·of
41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)41 content·structured·in·the·eXtensible·Configuration·Checklist·Description·Format·(XCCDF)
Offset 563, 15 lines modifiedOffset 563, 15 lines modified
563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>563 ··············<xccdf-1.2:check-content-ref·href="ssg-macos1015-ocil.xml"·name="ocil:ssg-audit_failure_halt_ocil:questionnaire:1"/>
564 ············</xccdf-1.2:check>564 ············</xccdf-1.2:check>
565 ··········</xccdf-1.2:Rule>565 ··········</xccdf-1.2:Rule>
566 ········</xccdf-1.2:Group>566 ········</xccdf-1.2:Group>
567 ······</xccdf-1.2:Group>567 ······</xccdf-1.2:Group>
568 ····</xccdf-1.2:Benchmark>568 ····</xccdf-1.2:Benchmark>
569 ··</ds:component>569 ··</ds:component>
570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-02-28T20:08:00">570 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-oval.xml"·timestamp="2025-03-01T22:08:00">
571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">571 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
572 ······<oval-def:generator>572 ······<oval-def:generator>
573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>573 ········<oval:product_name>OVALFileLinker·from·SCAP·Security·Guide</oval:product_name>
574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>574 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
575 ········<oval:schema_version>5.11</oval:schema_version>575 ········<oval:schema_version>5.11</oval:schema_version>
576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>576 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
577 ······</oval-def:generator>577 ······</oval-def:generator>
Offset 600, 74 lines modifiedOffset 600, 74 lines modified
600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>600 ··········<ind:filepath>/etc/security/audit_control</ind:filepath>
601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>601 ··········<ind:pattern·operation="pattern·match">^policy:.*,ahlt.*$</ind:pattern>
602 ··········<ind:instance·datatype="int">1</ind:instance>602 ··········<ind:instance·datatype="int">1</ind:instance>
603 ········</ind:textfilecontent54_object>603 ········</ind:textfilecontent54_object>
604 ······</oval-def:objects>604 ······</oval-def:objects>
605 ····</oval-def:oval_definitions>605 ····</oval-def:oval_definitions>
606 ··</ds:component>606 ··</ds:component>
607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-02-28T20:08:00">607 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-ocil.xml"·timestamp="2025-03-01T22:08:00">
608 ····<ocil:ocil>608 ····<ocil:ocil>
609 ······<ocil:generator>609 ······<ocil:generator>
610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>610 ········<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>611 ········<ocil:product_version>ssg:·0.1.76</ocil:product_version>
612 ········<ocil:schema_version>2.0</ocil:schema_version>612 ········<ocil:schema_version>2.0</ocil:schema_version>
613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>613 ········<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
614 ······</ocil:generator>614 ······</ocil:generator>
615 ······<ocil:questionnaires>615 ······<ocil:questionnaires>
616 ········<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> 
617 ··········<ocil:title>Enable·audit·Service</ocil:title> 
618 ··········<ocil:actions> 
619 ············<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> 
620 ··········</ocil:actions> 
621 ········</ocil:questionnaire> 
622 ········<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">616 ········<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">
623 ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>617 ··········<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>
624 ··········<ocil:actions>618 ··········<ocil:actions>
625 ············<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>619 ············<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>
626 ··········</ocil:actions>620 ··········</ocil:actions>
627 ········</ocil:questionnaire>621 ········</ocil:questionnaire>
 622 ········<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1">
 623 ··········<ocil:title>Enable·audit·Service</ocil:title>
 624 ··········<ocil:actions>
 625 ············<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref>
 626 ··········</ocil:actions>
 627 ········</ocil:questionnaire>
628 ······</ocil:questionnaires>628 ······</ocil:questionnaires>
629 ······<ocil:test_actions>629 ······<ocil:test_actions>
630 ········<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">630 ········<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">
631 ··········<ocil:when_true>631 ··········<ocil:when_true>
632 ············<ocil:result>PASS</ocil:result>632 ············<ocil:result>PASS</ocil:result>
633 ··········</ocil:when_true>633 ··········</ocil:when_true>
634 ··········<ocil:when_false>634 ··········<ocil:when_false>
635 ············<ocil:result>FAIL</ocil:result>635 ············<ocil:result>FAIL</ocil:result>
636 ··········</ocil:when_false>636 ··········</ocil:when_false>
637 ········</ocil:boolean_question_test_action>637 ········</ocil:boolean_question_test_action>
638 ········<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">638 ········<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
639 ··········<ocil:when_true>639 ··········<ocil:when_true>
640 ············<ocil:result>PASS</ocil:result>640 ············<ocil:result>PASS</ocil:result>
641 ··········</ocil:when_true>641 ··········</ocil:when_true>
642 ··········<ocil:when_false>642 ··········<ocil:when_false>
643 ············<ocil:result>FAIL</ocil:result>643 ············<ocil:result>FAIL</ocil:result>
644 ··········</ocil:when_false>644 ··········</ocil:when_false>
645 ········</ocil:boolean_question_test_action>645 ········</ocil:boolean_question_test_action>
646 ······</ocil:test_actions>646 ······</ocil:test_actions>
647 ······<ocil:questions>647 ······<ocil:questions>
 648 ········<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1">
 649 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
 650 following·command:
 651 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control
 652 The·output·should·contain·ahlt
 653 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>
 654 ········</ocil:boolean_question>
648 ········<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">655 ········<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
649 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the656 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
650 following·command:657 following·command:
651 $·sudo·launchctl·list·com.apple.auditd658 $·sudo·launchctl·list·com.apple.auditd
652 The·output·should·return·process·information·for659 The·output·should·return·process·information·for
653 com.apple.auditd660 com.apple.auditd
654 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>661 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>
655 ········</ocil:boolean_question>662 ········</ocil:boolean_question>
656 ········<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> 
657 ··········<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the 
658 following·command: 
659 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control 
660 The·output·should·contain·ahlt 
661 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> 
662 ········</ocil:boolean_question> 
663 ······</ocil:questions>663 ······</ocil:questions>
664 ····</ocil:ocil>664 ····</ocil:ocil>
665 ··</ds:component>665 ··</ds:component>
666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-02-28T20:08:00">666 ··<ds:component·id="scap_org.open-scap_comp_ssg-macos1015-cpe-oval.xml"·timestamp="2025-03-01T22:08:00">
667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">667 ····<oval-def:oval_definitions·xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5·oval-common-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5·oval-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#independent·independent-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#unix·unix-definitions-schema.xsd··http://oval.mitre.org/XMLSchema/oval-definitions-5#linux·linux-definitions-schema.xsd">
668 ······<oval-def:generator>668 ······<oval-def:generator>
669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>669 ········<oval:product_name>build_cpe.py·from·SCAP·Security·Guide</oval:product_name>
670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>670 ········<oval:product_version>ssg:·[0,·1,·76],·python:·3.13.2</oval:product_version>
671 ········<oval:schema_version>5.11</oval:schema_version>671 ········<oval:schema_version>5.11</oval:schema_version>
672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>672 ········<oval:timestamp>2025-03-01T08:08:00</oval:timestamp>
673 ······</oval-def:generator>673 ······</oval-def:generator>
Max diff block lines reached; -1/9126 bytes (-0.01%) of diff not shown.
4.0 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ocil.xml
3.89 KB
./usr/share/xml/scap/ssg/content/ssg-macos1015-ocil.xml
Ordering differences only
    
Offset 3, 56 lines modifiedOffset 3, 56 lines modified
3 ··<ocil:generator>3 ··<ocil:generator>
4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>4 ····<ocil:product_name>build_shorthand.py·from·SCAP·Security·Guide</ocil:product_name>
5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>5 ····<ocil:product_version>ssg:·0.1.76</ocil:product_version>
6 ····<ocil:schema_version>2.0</ocil:schema_version>6 ····<ocil:schema_version>2.0</ocil:schema_version>
7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>7 ····<ocil:timestamp>2025-03-01T08:08:00</ocil:timestamp>
8 ··</ocil:generator>8 ··</ocil:generator>
9 ··<ocil:questionnaires>9 ··<ocil:questionnaires>
10 ····<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1"> 
11 ······<ocil:title>Enable·audit·Service</ocil:title> 
12 ······<ocil:actions> 
13 ········<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref> 
14 ······</ocil:actions> 
15 ····</ocil:questionnaire> 
16 ····<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">10 ····<ocil:questionnaire·id="ocil:ssg-audit_failure_halt_ocil:questionnaire:1">
17 ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>11 ······<ocil:title>Shutdown·System·When·Auditing·Failures·Occur</ocil:title>
18 ······<ocil:actions>12 ······<ocil:actions>
19 ········<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>13 ········<ocil:test_action_ref>ocil:ssg-audit_failure_halt_action:testaction:1</ocil:test_action_ref>
20 ······</ocil:actions>14 ······</ocil:actions>
21 ····</ocil:questionnaire>15 ····</ocil:questionnaire>
 16 ····<ocil:questionnaire·id="ocil:ssg-service_com_apple_auditd_enabled_ocil:questionnaire:1">
 17 ······<ocil:title>Enable·audit·Service</ocil:title>
 18 ······<ocil:actions>
 19 ········<ocil:test_action_ref>ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1</ocil:test_action_ref>
 20 ······</ocil:actions>
 21 ····</ocil:questionnaire>
22 ··</ocil:questionnaires>22 ··</ocil:questionnaires>
23 ··<ocil:test_actions>23 ··<ocil:test_actions>
24 ····<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">24 ····<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">
25 ······<ocil:when_true>25 ······<ocil:when_true>
26 ········<ocil:result>PASS</ocil:result>26 ········<ocil:result>PASS</ocil:result>
27 ······</ocil:when_true>27 ······</ocil:when_true>
28 ······<ocil:when_false>28 ······<ocil:when_false>
29 ········<ocil:result>FAIL</ocil:result>29 ········<ocil:result>FAIL</ocil:result>
30 ······</ocil:when_false>30 ······</ocil:when_false>
31 ····</ocil:boolean_question_test_action>31 ····</ocil:boolean_question_test_action>
32 ····<ocil:boolean_question_test_action·id="ocil:ssg-audit_failure_halt_action:testaction:1"·question_ref="ocil:ssg-audit_failure_halt_question:question:1">32 ····<ocil:boolean_question_test_action·id="ocil:ssg-service_com_apple_auditd_enabled_action:testaction:1"·question_ref="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
33 ······<ocil:when_true>33 ······<ocil:when_true>
34 ········<ocil:result>PASS</ocil:result>34 ········<ocil:result>PASS</ocil:result>
35 ······</ocil:when_true>35 ······</ocil:when_true>
36 ······<ocil:when_false>36 ······<ocil:when_false>
37 ········<ocil:result>FAIL</ocil:result>37 ········<ocil:result>FAIL</ocil:result>
38 ······</ocil:when_false>38 ······</ocil:when_false>
39 ····</ocil:boolean_question_test_action>39 ····</ocil:boolean_question_test_action>
40 ··</ocil:test_actions>40 ··</ocil:test_actions>
41 ··<ocil:questions>41 ··<ocil:questions>
 42 ····<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1">
 43 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
 44 following·command:
 45 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control
 46 The·output·should·contain·ahlt
 47 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text>
 48 ····</ocil:boolean_question>
42 ····<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">49 ····<ocil:boolean_question·id="ocil:ssg-service_com_apple_auditd_enabled_question:question:1">
43 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the50 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the
44 following·command:51 following·command:
45 $·sudo·launchctl·list·com.apple.auditd52 $·sudo·launchctl·list·com.apple.auditd
46 The·output·should·return·process·information·for53 The·output·should·return·process·information·for
47 com.apple.auditd54 com.apple.auditd
48 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>55 ······Is·it·the·case·that·auditing·is·not·enabled·or·running?</ocil:question_text>
49 ····</ocil:boolean_question>56 ····</ocil:boolean_question>
50 ····<ocil:boolean_question·id="ocil:ssg-audit_failure_halt_question:question:1"> 
51 ······<ocil:question_text>To·verify·that·auditing·is·enabled·and·running,·run·the 
52 following·command: 
53 $·sudo·grep·-E·"^policy.*ahlt"·/etc/security/audit_control 
54 The·output·should·contain·ahlt 
55 ······Is·it·the·case·that·auditing·is·not·configured·to·shut·down·on·audit·failure?</ocil:question_text> 
56 ····</ocil:boolean_question> 
57 ··</ocil:questions>57 ··</ocil:questions>
58 </ocil:ocil>58 </ocil:ocil>
910 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
910 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ds.xml
Max HTML report size reached
846 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
845 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-ocil.xml
Max HTML report size reached
26.6 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-xccdf.xml
26.5 KB
./usr/share/xml/scap/ssg/content/ssg-ocp4-xccdf.xml
Ordering differences only
    
Offset 72, 129 lines modifiedOffset 72, 113 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="ocp4-node">79 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.12_or_ocp4.13">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="OR"·negate="false">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>
 86 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/>
 87 ········</cpe-lang:logical-test>
82 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted">90 ····<cpe-lang:platform·id="ocp4-node-on-sdn">
85 ······<cpe-lang:logical-test·operator="AND"·negate="true">91 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-sdn:def:1"/>
87 ······</cpe-lang:logical-test>93 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>94 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="ocp4-on-hypershift">95 ····<cpe-lang:platform·id="ocp4-on-gcp">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_gcp:def:1"/>
92 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="ocp4-master-node">100 ····<cpe-lang:platform·id="ocp4-on-aws">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-node_is_ocp4_master_node:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_aws:def:1"/>
97 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6_or_ocp4.7_or_ocp4.8">105 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
101 ········<cpe-lang:logical-test·operator="AND"·negate="true">106 ······<cpe-lang:logical-test·operator="AND"·negate="true">
102 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
103 ········</cpe-lang:logical-test> 
104 ········<cpe-lang:logical-test·operator="OR"·negate="false"> 
105 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/> 
106 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/> 
107 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/> 
108 ········</cpe-lang:logical-test> 
109 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.10_or_ocp4.11_or_ocp4.12_or_ocp4.13_or_ocp4.14_or_ocp4.15_or_ocp4.16_or_ocp4.17_or_ocp4.9">110 ····<cpe-lang:platform·id="ocp4-node">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
114 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/> 
115 ········</cpe-lang:logical-test> 
116 ········<cpe-lang:logical-test·operator="OR"·negate="false"> 
117 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_10:def:1"/> 
118 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_11:def:1"/> 
119 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/> 
120 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/> 
121 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_14:def:1"/> 
122 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_15:def:1"/> 
123 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_16:def:1"/> 
124 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_17:def:1"/> 
125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>
126 ········</cpe-lang:logical-test> 
127 ······</cpe-lang:logical-test>113 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>114 ····</cpe-lang:platform>
 115 ····<cpe-lang:platform·id="ocp4.6_or_ocp4.7_or_ocp4.8">
 116 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
 118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_7:def:1"/>
 119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
 120 ······</cpe-lang:logical-test>
 121 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.12_or_ocp4.13">122 ····<cpe-lang:platform·id="not_ocp4-on-hypershift-hosted_and_ocp4.6">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:logical-test·operator="AND"·negate="true">124 ········<cpe-lang:logical-test·operator="AND"·negate="true">
132 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>125 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
133 ········</cpe-lang:logical-test>126 ········</cpe-lang:logical-test>
134 ········<cpe-lang:logical-test·operator="OR"·negate="false"> 
135 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_12:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_6:def:1"/>
136 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_13:def:1"/> 
137 ········</cpe-lang:logical-test> 
138 ······</cpe-lang:logical-test> 
139 ····</cpe-lang:platform> 
140 ····<cpe-lang:platform·id="ocp4-node-on-sdn"> 
141 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-sdn:def:1"/> 
143 ······</cpe-lang:logical-test>128 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>129 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="ocp4-node-on-ovn">130 ····<cpe-lang:platform·id="ocp4-node-on-ovn">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">131 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-ovn:def:1"/>132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node_on_openshift-ovn:def:1"/>
148 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="ocp4.10_or_ocp4.8_or_ocp4.9">135 ····<cpe-lang:platform·id="ocp4.10_or_ocp4.8_or_ocp4.9">
151 ······<cpe-lang:logical-test·operator="OR"·negate="false">136 ······<cpe-lang:logical-test·operator="OR"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_10:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_10:def:1"/>
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_8:def:1"/>
154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_9:def:1"/>
155 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
156 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
157 ····<cpe-lang:platform·id="ocp4-on-gcp">142 ····<cpe-lang:platform·id="ocp4-node_and_s390x_arch">
158 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_gcp:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>
160 ······</cpe-lang:logical-test> 
161 ····</cpe-lang:platform> 
162 ····<cpe-lang:platform·id="not_ocp4-on-hypershift"> 
163 ······<cpe-lang:logical-test·operator="AND"·negate="true"> 
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
165 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="ocp4.16">148 ····<cpe-lang:platform·id="not_ocp4-on-hypershift_and_not_ocp4-on-hypershift-hosted">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 150 ········<cpe-lang:logical-test·operator="AND"·negate="true">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_16:def:1"/>151 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift:def:1"/>
 152 ········</cpe-lang:logical-test>
 153 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 154 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_on_hypershift_hosted:def:1"/>
 155 ········</cpe-lang:logical-test>
170 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="ocp4-node_and_s390x_arch">158 ····<cpe-lang:platform·id="not_s390x_arch_and_ocp4-node">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-installed_app_is_ocp4_node:def:1"/>
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ocp4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/> 
176 ······</cpe-lang:logical-test> 
177 ····</cpe-lang:platform> 
178 ····<cpe-lang:platform·id="ocp4.11_or_ocp4.12_or_ocp4.13_or_ocp4.14_or_ocp4.15"> 
179 ······<cpe-lang:logical-test·operator="OR"·negate="false"> 
Max diff block lines reached; 12135/27041 bytes (44.88%) of diff not shown.
2.11 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
2.11 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ds.xml
Max HTML report size reached
1.73 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
1.73 MB
./usr/share/xml/scap/ssg/content/ssg-ol10-ocil.xml
Max HTML report size reached
295 KB
./usr/share/xml/scap/ssg/content/ssg-ol10-xccdf.xml
295 KB
./usr/share/xml/scap/ssg/content/ssg-ol10-xccdf.xml
Ordering differences only
    
Offset 72, 376 lines modifiedOffset 72, 376 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ····<cpe-lang:platform·id="package_net-snmp"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_net-snmp:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="machine"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="not_bootc">89 ····<cpe-lang:platform·id="not_aarch64_arch">
90 ······<cpe-lang:logical-test·operator="AND"·negate="true">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
97 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
98 ········</cpe-lang:logical-test> 
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
100 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="system_with_kernel">99 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
105 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
106 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
107 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">105 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
111 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
112 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
113 ····<cpe-lang:platform·id="selinux"> 
114 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/> 
116 ······</cpe-lang:logical-test> 
117 ····</cpe-lang:platform> 
118 ····<cpe-lang:platform·id="package_systemd">111 ····<cpe-lang:platform·id="package_systemd">
119 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
121 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
122 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
123 ····<cpe-lang:platform·id="uefi">116 ····<cpe-lang:platform·id="package_postfix">
124 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
126 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
127 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
128 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">121 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
129 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
133 ······</cpe-lang:logical-test>126 ······</cpe-lang:logical-test>
134 ····</cpe-lang:platform>127 ····</cpe-lang:platform>
135 ····<cpe-lang:platform·id="mount_home">128 ····<cpe-lang:platform·id="package_shadow-utils">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false">129 ······<cpe-lang:logical-test·operator="AND"·negate="false">
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
138 ······</cpe-lang:logical-test>131 ······</cpe-lang:logical-test>
139 ····</cpe-lang:platform>132 ····</cpe-lang:platform>
140 ····<cpe-lang:platform·id="mount_var-tmp">133 ····<cpe-lang:platform·id="mount_var">
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">134 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
143 ······</cpe-lang:logical-test>136 ······</cpe-lang:logical-test>
144 ····</cpe-lang:platform>137 ····</cpe-lang:platform>
145 ····<cpe-lang:platform·id="mount_var-log">138 ····<cpe-lang:platform·id="package_firewalld">
146 ······<cpe-lang:logical-test·operator="AND"·negate="false">139 ······<cpe-lang:logical-test·operator="AND"·negate="false">
147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
148 ······</cpe-lang:logical-test>141 ······</cpe-lang:logical-test>
149 ····</cpe-lang:platform>142 ····</cpe-lang:platform>
150 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">143 ····<cpe-lang:platform·id="package_rsyslog">
151 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="AND"·negate="false">
152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
154 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="x86_64_arch">148 ····<cpe-lang:platform·id="system_with_kernel">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
159 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">153 ····<cpe-lang:platform·id="package_chrony">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
164 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">158 ····<cpe-lang:platform·id="mount_tmp">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/> 
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
170 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
171 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
172 ····<cpe-lang:platform·id="package_polkit">163 ····<cpe-lang:platform·id="not_s390x_arch">
173 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
175 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
176 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
177 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">168 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
178 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
179 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
180 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/> 
181 ········</cpe-lang:logical-test> 
182 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
183 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_ppc64le:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
184 ········</cpe-lang:logical-test> 
185 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
186 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
187 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
188 ····<cpe-lang:platform·id="wifi-iface">174 ····<cpe-lang:platform·id="mount_var-log-audit">
189 ······<cpe-lang:logical-test·operator="AND"·negate="false">175 ······<cpe-lang:logical-test·operator="AND"·negate="false">
190 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol10-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/>
191 ······</cpe-lang:logical-test>177 ······</cpe-lang:logical-test>
Max diff block lines reached; 288766/302070 bytes (95.60%) of diff not shown.
2.54 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
2.54 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ds.xml
Max HTML report size reached
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
2.1 MB
./usr/share/xml/scap/ssg/content/ssg-ol7-ocil.xml
Max HTML report size reached
350 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
350 KB
./usr/share/xml/scap/ssg/content/ssg-ol7-xccdf.xml
Ordering differences only
    
Offset 72, 437 lines modifiedOffset 72, 437 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ····<cpe-lang:platform·id="package_net-snmp"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_net-snmp:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="machine"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="not_bootc">89 ····<cpe-lang:platform·id="not_aarch64_arch">
90 ······<cpe-lang:logical-test·operator="AND"·negate="true">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
92 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
97 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
98 ········</cpe-lang:logical-test> 
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
100 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">99 ····<cpe-lang:platform·id="os_linux_ol_le_7_4">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_le_7_4:def:1"/>
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
106 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="system_with_kernel">104 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
111 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
112 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
113 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">110 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
114 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
117 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="selinux"> 
120 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/> 
122 ······</cpe-lang:logical-test> 
123 ····</cpe-lang:platform> 
124 ····<cpe-lang:platform·id="package_systemd">116 ····<cpe-lang:platform·id="package_systemd">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
127 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">121 ····<cpe-lang:platform·id="package_postfix">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
134 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="uefi">126 ····<cpe-lang:platform·id="package_shadow-utils">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
139 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
140 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
141 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">131 ····<cpe-lang:platform·id="mount_var">
142 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
143 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
144 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
145 ········</cpe-lang:logical-test> 
146 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
147 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
148 ········</cpe-lang:logical-test> 
149 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="mount_home">136 ····<cpe-lang:platform·id="package_firewalld">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
154 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="mount_var-tmp">141 ····<cpe-lang:platform·id="package_rsyslog">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
159 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="mount_var-log">146 ····<cpe-lang:platform·id="system_with_kernel">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
164 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
165 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
166 ····<cpe-lang:platform·id="x86_64_arch">151 ····<cpe-lang:platform·id="package_chrony">
167 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
169 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">156 ····<cpe-lang:platform·id="mount_tmp">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
174 ······</cpe-lang:logical-test>159 ······</cpe-lang:logical-test>
175 ····</cpe-lang:platform>160 ····</cpe-lang:platform>
176 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">161 ····<cpe-lang:platform·id="not_s390x_arch">
177 ······<cpe-lang:logical-test·operator="AND"·negate="false">162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
178 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
179 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
180 ········</cpe-lang:logical-test> 
181 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
182 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
183 ········</cpe-lang:logical-test> 
184 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
185 ······</cpe-lang:logical-test>164 ······</cpe-lang:logical-test>
186 ····</cpe-lang:platform>165 ····</cpe-lang:platform>
187 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">166 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
188 ······<cpe-lang:logical-test·operator="AND"·negate="false">167 ······<cpe-lang:logical-test·operator="AND"·negate="false">
189 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
190 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol7-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
191 ······</cpe-lang:logical-test>170 ······</cpe-lang:logical-test>
Max diff block lines reached; 344705/358122 bytes (96.25%) of diff not shown.
2.96 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
2.96 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ds.xml
Max HTML report size reached
2.46 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
2.46 MB
./usr/share/xml/scap/ssg/content/ssg-ol8-ocil.xml
Max HTML report size reached
388 KB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
388 KB
./usr/share/xml/scap/ssg/content/ssg-ol8-xccdf.xml
Ordering differences only
    
Offset 72, 482 lines modifiedOffset 72, 482 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
 79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ····<cpe-lang:platform·id="package_net-snmp"> 
80 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_net-snmp:def:1"/> 
82 ······</cpe-lang:logical-test> 
83 ····</cpe-lang:platform> 
84 ····<cpe-lang:platform·id="machine"> 
85 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
87 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="not_bootc">89 ····<cpe-lang:platform·id="not_aarch64_arch">
90 ······<cpe-lang:logical-test·operator="AND"·negate="true">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
92 ······</cpe-lang:logical-test> 
93 ····</cpe-lang:platform> 
94 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel"> 
95 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
96 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
97 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/> 
98 ········</cpe-lang:logical-test> 
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
100 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
106 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="system_with_kernel">99 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
111 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
112 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
113 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">105 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
114 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
117 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="selinux"> 
120 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/> 
122 ······</cpe-lang:logical-test> 
123 ····</cpe-lang:platform> 
124 ····<cpe-lang:platform·id="package_systemd">111 ····<cpe-lang:platform·id="package_systemd">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
127 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="os_linux_ol_le_8_4_or_not_runtime_kernel_fips_enabled">116 ····<cpe-lang:platform·id="package_postfix">
130 ······<cpe-lang:logical-test·operator="OR"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
132 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/> 
133 ········</cpe-lang:logical-test> 
134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_le_8_4:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
135 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
136 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
137 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">121 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
138 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
142 ······</cpe-lang:logical-test>126 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>127 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="uefi">128 ····<cpe-lang:platform·id="package_shadow-utils">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">129 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
147 ······</cpe-lang:logical-test>131 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>132 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="machine_and_not_kernel_uek_or_not_secure_boot">133 ····<cpe-lang:platform·id="mount_var">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">134 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:logical-test·operator="OR"·negate="false"> 
152 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
153 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-kernel_uek:def:1"/> 
154 ··········</cpe-lang:logical-test> 
155 ··········<cpe-lang:logical-test·operator="AND"·negate="true"> 
156 ············<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-secure_boot_enabled:def:1"/> 
157 ··········</cpe-lang:logical-test> 
158 ········</cpe-lang:logical-test> 
159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
160 ······</cpe-lang:logical-test>136 ······</cpe-lang:logical-test>
161 ····</cpe-lang:platform>137 ····</cpe-lang:platform>
162 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">138 ····<cpe-lang:platform·id="package_firewalld">
163 ······<cpe-lang:logical-test·operator="AND"·negate="false">139 ······<cpe-lang:logical-test·operator="AND"·negate="false">
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
167 ······</cpe-lang:logical-test>141 ······</cpe-lang:logical-test>
168 ····</cpe-lang:platform>142 ····</cpe-lang:platform>
169 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">143 ····<cpe-lang:platform·id="package_rsyslog">
170 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="AND"·negate="false">
171 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
172 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
173 ········</cpe-lang:logical-test> 
174 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
175 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
176 ········</cpe-lang:logical-test> 
177 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
178 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
179 ····<cpe-lang:platform·id="mount_home">148 ····<cpe-lang:platform·id="system_with_kernel">
180 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
181 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
182 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
183 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
184 ····<cpe-lang:platform·id="mount_var-tmp">153 ····<cpe-lang:platform·id="package_chrony">
185 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
186 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol8-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
187 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
188 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
189 ····<cpe-lang:platform·id="mount_var-log">158 ····<cpe-lang:platform·id="mount_tmp">
190 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Max diff block lines reached; 384166/397236 bytes (96.71%) of diff not shown.
2.39 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
2.39 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ds.xml
Max HTML report size reached
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
1.97 MB
./usr/share/xml/scap/ssg/content/ssg-ol9-ocil.xml
Max HTML report size reached
335 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
335 KB
./usr/share/xml/scap/ssg/content/ssg-ol9-xccdf.xml
Ordering differences only
    
Offset 73, 446 lines modifiedOffset 73, 446 lines modified
73 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
78 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>78 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
79 ··<cpe-lang:platform-specification>79 ··<cpe-lang:platform-specification>
80 ····<cpe-lang:platform·id="package_net-snmp">80 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
81 ······<cpe-lang:logical-test·operator="AND"·negate="false">81 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 82 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 83 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 84 ········</cpe-lang:logical-test>
 85 ········<cpe-lang:logical-test·operator="AND"·negate="true">
82 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_net-snmp:def:1"/>86 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 87 ········</cpe-lang:logical-test>
83 ······</cpe-lang:logical-test>88 ······</cpe-lang:logical-test>
84 ····</cpe-lang:platform>89 ····</cpe-lang:platform>
 90 ····<cpe-lang:platform·id="not_aarch64_arch">
 91 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 93 ······</cpe-lang:logical-test>
 94 ····</cpe-lang:platform>
85 ····<cpe-lang:platform·id="machine">95 ····<cpe-lang:platform·id="ipv6_enabled">
86 ······<cpe-lang:logical-test·operator="AND"·negate="false">96 ······<cpe-lang:logical-test·operator="AND"·negate="false">
87 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>97 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
88 ······</cpe-lang:logical-test>98 ······</cpe-lang:logical-test>
89 ····</cpe-lang:platform>99 ····</cpe-lang:platform>
90 ····<cpe-lang:platform·id="not_bootc">100 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
91 ······<cpe-lang:logical-test·operator="AND"·negate="true">101 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
93 ······</cpe-lang:logical-test>104 ······</cpe-lang:logical-test>
94 ····</cpe-lang:platform>105 ····</cpe-lang:platform>
95 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">106 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
96 ······<cpe-lang:logical-test·operator="AND"·negate="false">107 ······<cpe-lang:logical-test·operator="AND"·negate="false">
97 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
98 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
99 ········</cpe-lang:logical-test> 
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
101 ······</cpe-lang:logical-test>110 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>111 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">112 ····<cpe-lang:platform·id="package_systemd">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">113 ······<cpe-lang:logical-test·operator="AND"·negate="false">
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
107 ······</cpe-lang:logical-test>115 ······</cpe-lang:logical-test>
108 ····</cpe-lang:platform>116 ····</cpe-lang:platform>
109 ····<cpe-lang:platform·id="system_with_kernel">117 ····<cpe-lang:platform·id="package_postfix">
110 ······<cpe-lang:logical-test·operator="AND"·negate="false">118 ······<cpe-lang:logical-test·operator="AND"·negate="false">
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
112 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">122 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
118 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="selinux">129 ····<cpe-lang:platform·id="package_shadow-utils">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
123 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="package_systemd">134 ····<cpe-lang:platform·id="mount_var">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
128 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
129 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
130 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">139 ····<cpe-lang:platform·id="package_firewalld">
131 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
135 ······</cpe-lang:logical-test>142 ······</cpe-lang:logical-test>
136 ····</cpe-lang:platform>143 ····</cpe-lang:platform>
137 ····<cpe-lang:platform·id="uefi">144 ····<cpe-lang:platform·id="package_rsyslog">
138 ······<cpe-lang:logical-test·operator="AND"·negate="false">145 ······<cpe-lang:logical-test·operator="AND"·negate="false">
139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
140 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
141 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
142 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">149 ····<cpe-lang:platform·id="system_with_kernel">
143 ······<cpe-lang:logical-test·operator="AND"·negate="false">150 ······<cpe-lang:logical-test·operator="AND"·negate="false">
144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/> 
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
147 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">154 ····<cpe-lang:platform·id="package_chrony">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
152 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
153 ········</cpe-lang:logical-test> 
154 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
155 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
156 ········</cpe-lang:logical-test> 
157 ······</cpe-lang:logical-test>157 ······</cpe-lang:logical-test>
158 ····</cpe-lang:platform>158 ····</cpe-lang:platform>
159 ····<cpe-lang:platform·id="mount_home">159 ····<cpe-lang:platform·id="mount_tmp">
160 ······<cpe-lang:logical-test·operator="AND"·negate="false">160 ······<cpe-lang:logical-test·operator="AND"·negate="false">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
162 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
163 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
164 ····<cpe-lang:platform·id="mount_var-tmp">164 ····<cpe-lang:platform·id="not_s390x_arch">
165 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
167 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
168 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
169 ····<cpe-lang:platform·id="mount_var-log">169 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
170 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
 172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
172 ······</cpe-lang:logical-test>173 ······</cpe-lang:logical-test>
173 ····</cpe-lang:platform>174 ····</cpe-lang:platform>
174 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">175 ····<cpe-lang:platform·id="mount_var-log-audit">
175 ······<cpe-lang:logical-test·operator="AND"·negate="false">176 ······<cpe-lang:logical-test·operator="AND"·negate="false">
176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/> 
177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/>
178 ······</cpe-lang:logical-test>178 ······</cpe-lang:logical-test>
179 ····</cpe-lang:platform>179 ····</cpe-lang:platform>
180 ····<cpe-lang:platform·id="x86_64_arch">180 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
181 ······<cpe-lang:logical-test·operator="AND"·negate="false">181 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
182 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>183 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-ol9-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
183 ······</cpe-lang:logical-test>184 ······</cpe-lang:logical-test>
184 ····</cpe-lang:platform>185 ····</cpe-lang:platform>
185 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">186 ····<cpe-lang:platform·id="x86_64_arch">
Max diff block lines reached; 328586/342791 bytes (95.86%) of diff not shown.
1.02 MB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
1.02 MB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ds.xml
Max HTML report size reached
896 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
896 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-ocil.xml
Max HTML report size reached
101 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-xccdf.xml
101 KB
./usr/share/xml/scap/ssg/content/ssg-openembedded-xccdf.xml
Ordering differences only
    
Offset 71, 69 lines modifiedOffset 71, 87 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 85 ········</cpe-lang:logical-test>
81 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="not_bootc">88 ····<cpe-lang:platform·id="not_aarch64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="true">89 ······<cpe-lang:logical-test·operator="AND"·negate="true">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
86 ······</cpe-lang:logical-test> 
87 ····</cpe-lang:platform> 
88 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel"> 
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
92 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="system_with_kernel">93 ····<cpe-lang:platform·id="ipv6_enabled">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
97 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">98 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
103 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
104 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
105 ····<cpe-lang:platform·id="package_systemd">104 ····<cpe-lang:platform·id="package_systemd">
106 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
108 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
109 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
110 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">109 ····<cpe-lang:platform·id="package_postfix">
 110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
 112 ······</cpe-lang:logical-test>
 113 ····</cpe-lang:platform>
 114 ····<cpe-lang:platform·id="package_shadow-utils">
 115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
 117 ······</cpe-lang:logical-test>
 118 ····</cpe-lang:platform>
 119 ····<cpe-lang:platform·id="package_firewalld">
 120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
 122 ······</cpe-lang:logical-test>
 123 ····</cpe-lang:platform>
 124 ····<cpe-lang:platform·id="package_rsyslog">
 125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 127 ······</cpe-lang:logical-test>
 128 ····</cpe-lang:platform>
 129 ····<cpe-lang:platform·id="system_with_kernel">
111 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
115 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">134 ····<cpe-lang:platform·id="package_chrony">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
120 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
121 ········</cpe-lang:logical-test> 
122 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
123 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
124 ········</cpe-lang:logical-test> 
125 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
126 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
127 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">139 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
128 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
131 ······</cpe-lang:logical-test>143 ······</cpe-lang:logical-test>
132 ····</cpe-lang:platform>144 ····</cpe-lang:platform>
 145 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 146 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 149 ······</cpe-lang:logical-test>
 150 ····</cpe-lang:platform>
133 ····<cpe-lang:platform·id="x86_64_arch">151 ····<cpe-lang:platform·id="x86_64_arch">
134 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
136 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">156 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
Offset 142, 157 lines modifiedOffset 160, 139 lines modified
142 ········</cpe-lang:logical-test>160 ········</cpe-lang:logical-test>
143 ········<cpe-lang:logical-test·operator="AND"·negate="true">161 ········<cpe-lang:logical-test·operator="AND"·negate="true">
144 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>162 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
145 ········</cpe-lang:logical-test>163 ········</cpe-lang:logical-test>
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
147 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="wifi-iface"> 
150 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
152 ······</cpe-lang:logical-test> 
153 ····</cpe-lang:platform> 
154 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">167 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">168 ······<cpe-lang:logical-test·operator="AND"·negate="false">
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
158 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="package_rsh-server">173 ····<cpe-lang:platform·id="package_rsh-server">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
163 ······</cpe-lang:logical-test>176 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>177 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="package_pam">178 ····<cpe-lang:platform·id="package_iptables">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openembedded-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/> 
Max diff block lines reached; 91384/103215 bytes (88.54%) of diff not shown.
611 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
611 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ds.xml
Max HTML report size reached
532 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
532 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-ocil.xml
Max HTML report size reached
49.9 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-xccdf.xml
49.8 KB
./usr/share/xml/scap/ssg/content/ssg-openeuler2203-xccdf.xml
Ordering differences only
    
Offset 71, 174 lines modifiedOffset 71, 174 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="system_with_kernel">78 ····<cpe-lang:platform·id="not_aarch64_arch">
 79 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 81 ······</cpe-lang:logical-test>
 82 ····</cpe-lang:platform>
 83 ····<cpe-lang:platform·id="ipv6_enabled">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">84 ······<cpe-lang:logical-test·operator="AND"·negate="false">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
81 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">88 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">89 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
87 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">94 ····<cpe-lang:platform·id="package_shadow-utils">
 95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
 97 ······</cpe-lang:logical-test>
 98 ····</cpe-lang:platform>
 99 ····<cpe-lang:platform·id="package_firewalld">
 100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
 102 ······</cpe-lang:logical-test>
 103 ····</cpe-lang:platform>
 104 ····<cpe-lang:platform·id="package_rsyslog">
 105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
 107 ······</cpe-lang:logical-test>
 108 ····</cpe-lang:platform>
 109 ····<cpe-lang:platform·id="system_with_kernel">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
92 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
94 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="uefi">114 ····<cpe-lang:platform·id="package_chrony">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
99 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
100 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
101 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">119 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
102 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
103 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
104 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
105 ········</cpe-lang:logical-test> 
106 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
107 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
108 ········</cpe-lang:logical-test> 
109 ······</cpe-lang:logical-test>123 ······</cpe-lang:logical-test>
110 ····</cpe-lang:platform>124 ····</cpe-lang:platform>
111 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">125 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">
112 ······<cpe-lang:logical-test·operator="AND"·negate="false">126 ······<cpe-lang:logical-test·operator="AND"·negate="false">
113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/> 
116 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
117 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
118 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">131 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
119 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
120 ········<cpe-lang:logical-test·operator="AND"·negate="true">133 ········<cpe-lang:logical-test·operator="AND"·negate="true">
121 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>134 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
122 ········</cpe-lang:logical-test>135 ········</cpe-lang:logical-test>
123 ········<cpe-lang:logical-test·operator="AND"·negate="true">136 ········<cpe-lang:logical-test·operator="AND"·negate="true">
124 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>137 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
125 ········</cpe-lang:logical-test>138 ········</cpe-lang:logical-test>
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
127 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld"> 
130 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
133 ······</cpe-lang:logical-test> 
134 ····</cpe-lang:platform> 
135 ····<cpe-lang:platform·id="wifi-iface">142 ····<cpe-lang:platform·id="package_iptables">
136 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/> 
138 ······</cpe-lang:logical-test> 
139 ····</cpe-lang:platform> 
140 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_system_with_kernel"> 
141 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
142 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
145 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
146 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
147 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">147 ····<cpe-lang:platform·id="not_bootc_and_not_container">
148 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>149 ········<cpe-lang:logical-test·operator="AND"·negate="true">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>150 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 151 ········</cpe-lang:logical-test>
 152 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 153 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 154 ········</cpe-lang:logical-test>
151 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="package_pam">157 ····<cpe-lang:platform·id="uefi">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>
156 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
157 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
158 ····<cpe-lang:platform·id="package_audit">162 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
 165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
 166 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/>
161 ······</cpe-lang:logical-test>167 ······</cpe-lang:logical-test>
162 ····</cpe-lang:platform>168 ····</cpe-lang:platform>
163 ····<cpe-lang:platform·id="non-uefi">169 ····<cpe-lang:platform·id="non-uefi">
164 ······<cpe-lang:logical-test·operator="AND"·negate="false">170 ······<cpe-lang:logical-test·operator="AND"·negate="false">
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_non_uefi:def:1"/>
166 ······</cpe-lang:logical-test>172 ······</cpe-lang:logical-test>
167 ····</cpe-lang:platform>173 ····</cpe-lang:platform>
168 ····<cpe-lang:platform·id="package_ntp">174 ····<cpe-lang:platform·id="grub2">
169 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-openeuler2203-cpe-oval.xml"·id-ref="oval:ssg-package_ntp:def:1"/> 
171 ······</cpe-lang:logical-test> 
Max diff block lines reached; 37860/50850 bytes (74.45%) of diff not shown.
740 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
740 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ds.xml
Max HTML report size reached
645 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
645 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-ocil.xml
Max HTML report size reached
59.2 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-xccdf.xml
59.1 KB
./usr/share/xml/scap/ssg/content/ssg-opensuse-xccdf.xml
Ordering differences only
    
Offset 71, 50 lines modifiedOffset 71, 69 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 85 ········</cpe-lang:logical-test>
81 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
 88 ····<cpe-lang:platform·id="not_aarch64_arch">
 89 ······<cpe-lang:logical-test·operator="AND"·negate="true">
 90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 91 ······</cpe-lang:logical-test>
 92 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">93 ····<cpe-lang:platform·id="package_systemd">
84 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
 96 ······</cpe-lang:logical-test>
 97 ····</cpe-lang:platform>
 98 ····<cpe-lang:platform·id="package_postfix">
 99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
 101 ······</cpe-lang:logical-test>
 102 ····</cpe-lang:platform>
 103 ····<cpe-lang:platform·id="package_shadow-utils">
 104 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
 106 ······</cpe-lang:logical-test>
 107 ····</cpe-lang:platform>
 108 ····<cpe-lang:platform·id="package_rsyslog">
 109 ······<cpe-lang:logical-test·operator="AND"·negate="false">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
87 ······</cpe-lang:logical-test>111 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>112 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="system_with_kernel">113 ····<cpe-lang:platform·id="system_with_kernel">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">114 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
92 ······</cpe-lang:logical-test>116 ······</cpe-lang:logical-test>
93 ····</cpe-lang:platform>117 ····</cpe-lang:platform>
94 ····<cpe-lang:platform·id="package_systemd">118 ····<cpe-lang:platform·id="package_chrony">
95 ······<cpe-lang:logical-test·operator="AND"·negate="false">119 ······<cpe-lang:logical-test·operator="AND"·negate="false">
96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
97 ······</cpe-lang:logical-test>121 ······</cpe-lang:logical-test>
98 ····</cpe-lang:platform>122 ····</cpe-lang:platform>
99 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">123 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
100 ······<cpe-lang:logical-test·operator="AND"·negate="false">124 ······<cpe-lang:logical-test·operator="AND"·negate="false">
101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
103 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
104 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
105 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
106 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">129 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
107 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="OR"·negate="false">
108 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
109 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
110 ········</cpe-lang:logical-test> 
111 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
112 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>132 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
113 ········</cpe-lang:logical-test> 
114 ······</cpe-lang:logical-test>133 ······</cpe-lang:logical-test>
115 ····</cpe-lang:platform>134 ····</cpe-lang:platform>
116 ····<cpe-lang:platform·id="x86_64_arch">135 ····<cpe-lang:platform·id="x86_64_arch">
117 ······<cpe-lang:logical-test·operator="AND"·negate="false">136 ······<cpe-lang:logical-test·operator="AND"·negate="false">
118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>137 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
119 ······</cpe-lang:logical-test>138 ······</cpe-lang:logical-test>
120 ····</cpe-lang:platform>139 ····</cpe-lang:platform>
Offset 125, 111 lines modifiedOffset 144, 92 lines modified
125 ········</cpe-lang:logical-test>144 ········</cpe-lang:logical-test>
126 ········<cpe-lang:logical-test·operator="AND"·negate="true">145 ········<cpe-lang:logical-test·operator="AND"·negate="true">
127 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>146 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
128 ········</cpe-lang:logical-test>147 ········</cpe-lang:logical-test>
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
130 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
132 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">151 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
133 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
136 ······</cpe-lang:logical-test>155 ······</cpe-lang:logical-test>
137 ····</cpe-lang:platform>156 ····</cpe-lang:platform>
138 ····<cpe-lang:platform·id="package_rsh-server">157 ····<cpe-lang:platform·id="package_rsh-server">
139 ······<cpe-lang:logical-test·operator="AND"·negate="false">158 ······<cpe-lang:logical-test·operator="AND"·negate="false">
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>159 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_rsh-server:def:1"/>
141 ······</cpe-lang:logical-test>160 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>161 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="package_pam">162 ····<cpe-lang:platform·id="package_iptables">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">163 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
146 ······</cpe-lang:logical-test>165 ······</cpe-lang:logical-test>
147 ····</cpe-lang:platform>166 ····</cpe-lang:platform>
148 ····<cpe-lang:platform·id="aarch64_arch">167 ····<cpe-lang:platform·id="not_bootc_and_not_container">
149 ······<cpe-lang:logical-test·operator="AND"·negate="false">168 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 169 ········<cpe-lang:logical-test·operator="AND"·negate="true">
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>170 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
 171 ········</cpe-lang:logical-test>
 172 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 173 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_container:def:1"/>
 174 ········</cpe-lang:logical-test>
151 ······</cpe-lang:logical-test>175 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>176 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="package_audit">177 ····<cpe-lang:platform·id="machine">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">178 ······<cpe-lang:logical-test·operator="AND"·negate="false">
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_audit:def:1"/>179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>
156 ······</cpe-lang:logical-test>180 ······</cpe-lang:logical-test>
157 ····</cpe-lang:platform>181 ····</cpe-lang:platform>
158 ····<cpe-lang:platform·id="package_gdm">182 ····<cpe-lang:platform·id="package_pam">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">183 ······<cpe-lang:logical-test·operator="AND"·negate="false">
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_gdm:def:1"/>184 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_pam:def:1"/>
161 ······</cpe-lang:logical-test>185 ······</cpe-lang:logical-test>
162 ····</cpe-lang:platform>186 ····</cpe-lang:platform>
163 ····<cpe-lang:platform·id="package_chrony">187 ····<cpe-lang:platform·id="aarch64_arch">
164 ······<cpe-lang:logical-test·operator="AND"·negate="false">188 ······<cpe-lang:logical-test·operator="AND"·negate="false">
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>189 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
166 ······</cpe-lang:logical-test>190 ······</cpe-lang:logical-test>
167 ····</cpe-lang:platform>191 ····</cpe-lang:platform>
168 ····<cpe-lang:platform·id="package_logrotate">192 ····<cpe-lang:platform·id="package_logrotate">
169 ······<cpe-lang:logical-test·operator="AND"·negate="false">193 ······<cpe-lang:logical-test·operator="AND"·negate="false">
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>194 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-opensuse-cpe-oval.xml"·id-ref="oval:ssg-package_logrotate:def:1"/>
171 ······</cpe-lang:logical-test>195 ······</cpe-lang:logical-test>
Max diff block lines reached; 47911/60411 bytes (79.31%) of diff not shown.
1.67 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
1.67 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ds.xml
Max HTML report size reached
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
1.55 MB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-ocil.xml
Max HTML report size reached
51.7 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
51.6 KB
./usr/share/xml/scap/ssg/content/ssg-rhcos4-xccdf.xml
Ordering differences only
    
Offset 71, 353 lines modifiedOffset 71, 353 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=container-platform">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 85 ········</cpe-lang:logical-test>
81 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="not_bootc">88 ····<cpe-lang:platform·id="not_aarch64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="true">89 ······<cpe-lang:logical-test·operator="AND"·negate="true">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
86 ······</cpe-lang:logical-test> 
87 ····</cpe-lang:platform> 
88 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel"> 
89 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
90 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
91 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/> 
92 ········</cpe-lang:logical-test> 
93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
94 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">93 ····<cpe-lang:platform·id="ipv6_enabled">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
100 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="system_with_kernel">98 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
105 ······</cpe-lang:logical-test>102 ······</cpe-lang:logical-test>
106 ····</cpe-lang:platform>103 ····</cpe-lang:platform>
107 ····<cpe-lang:platform·id="package_systemd">104 ····<cpe-lang:platform·id="package_systemd">
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">105 ······<cpe-lang:logical-test·operator="AND"·negate="false">
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>106 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
110 ······</cpe-lang:logical-test>107 ······</cpe-lang:logical-test>
111 ····</cpe-lang:platform>108 ····</cpe-lang:platform>
112 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel"> 
113 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/> 
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
117 ······</cpe-lang:logical-test> 
118 ····</cpe-lang:platform> 
119 ····<cpe-lang:platform·id="uefi">109 ····<cpe-lang:platform·id="package_postfix">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">110 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
122 ······</cpe-lang:logical-test>112 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>113 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">114 ····<cpe-lang:platform·id="rhcos4-rhel9">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">115 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
127 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>
128 ········</cpe-lang:logical-test> 
129 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
130 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
131 ········</cpe-lang:logical-test> 
132 ······</cpe-lang:logical-test>117 ······</cpe-lang:logical-test>
133 ····</cpe-lang:platform>118 ····</cpe-lang:platform>
134 ····<cpe-lang:platform·id="mount_home">119 ····<cpe-lang:platform·id="package_shadow-utils">
135 ······<cpe-lang:logical-test·operator="AND"·negate="false">120 ······<cpe-lang:logical-test·operator="AND"·negate="false">
136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
137 ······</cpe-lang:logical-test>122 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>123 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="mount_var-tmp">124 ····<cpe-lang:platform·id="mount_var">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">125 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
142 ······</cpe-lang:logical-test>127 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>128 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="mount_var-log">129 ····<cpe-lang:platform·id="package_firewalld">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">130 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>131 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
147 ······</cpe-lang:logical-test>132 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>133 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="x86_64_arch">134 ····<cpe-lang:platform·id="package_rsyslog">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">135 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>136 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
152 ······</cpe-lang:logical-test>137 ······</cpe-lang:logical-test>
153 ····</cpe-lang:platform>138 ····</cpe-lang:platform>
154 ····<cpe-lang:platform·id="os_linux_ol_gt_or_eq_8_7">139 ····<cpe-lang:platform·id="system_with_kernel">
155 ······<cpe-lang:logical-test·operator="AND"·negate="false">140 ······<cpe-lang:logical-test·operator="AND"·negate="false">
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_ol_gt_or_eq_8_7:def:1"/>141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
157 ······</cpe-lang:logical-test>142 ······</cpe-lang:logical-test>
158 ····</cpe-lang:platform>143 ····</cpe-lang:platform>
159 ····<cpe-lang:platform·id="rhcos4-rhel9">144 ····<cpe-lang:platform·id="package_chrony">
160 ······<cpe-lang:logical-test·operator="AND"·negate="false">145 ······<cpe-lang:logical-test·operator="AND"·negate="false">
161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_OS_is_rhcos4_rhel9:def:1"/>146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
162 ······</cpe-lang:logical-test>147 ······</cpe-lang:logical-test>
163 ····</cpe-lang:platform>148 ····</cpe-lang:platform>
164 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">149 ····<cpe-lang:platform·id="mount_tmp">
165 ······<cpe-lang:logical-test·operator="AND"·negate="false">150 ······<cpe-lang:logical-test·operator="AND"·negate="false">
166 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
167 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
168 ········</cpe-lang:logical-test> 
169 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
170 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
171 ········</cpe-lang:logical-test> 
172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>151 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
173 ······</cpe-lang:logical-test>152 ······</cpe-lang:logical-test>
174 ····</cpe-lang:platform>153 ····</cpe-lang:platform>
175 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">154 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
176 ······<cpe-lang:logical-test·operator="AND"·negate="false">155 ······<cpe-lang:logical-test·operator="AND"·negate="false">
177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
179 ······</cpe-lang:logical-test>158 ······</cpe-lang:logical-test>
180 ····</cpe-lang:platform>159 ····</cpe-lang:platform>
181 ····<cpe-lang:platform·id="package_polkit">160 ····<cpe-lang:platform·id="mount_var-log-audit">
182 ······<cpe-lang:logical-test·operator="AND"·negate="false">161 ······<cpe-lang:logical-test·operator="AND"·negate="false">
183 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log-audit:def:1"/>
184 ······</cpe-lang:logical-test>163 ······</cpe-lang:logical-test>
185 ····</cpe-lang:platform>164 ····</cpe-lang:platform>
186 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">165 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
187 ······<cpe-lang:logical-test·operator="AND"·negate="false">166 ······<cpe-lang:logical-test·operator="OR"·negate="false">
188 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
189 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>167 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhcos4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
190 ········</cpe-lang:logical-test> 
191 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
Max diff block lines reached; 38270/52732 bytes (72.57%) of diff not shown.
3.02 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
3.02 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ds.xml
Max HTML report size reached
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
2.06 MB
./usr/share/xml/scap/ssg/content/ssg-rhel10-ocil.xml
Max HTML report size reached
878 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
878 KB
./usr/share/xml/scap/ssg/content/ssg-rhel10-xccdf.xml
Max HTML report size reached
4.56 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
4.56 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ds.xml
Max HTML report size reached
3.26 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
3.26 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-ocil.xml
Max HTML report size reached
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
1.14 MB
./usr/share/xml/scap/ssg/content/ssg-rhel8-xccdf.xml
Max HTML report size reached
4.35 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
4.35 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ds.xml
Max HTML report size reached
3.13 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
3.13 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-ocil.xml
Max HTML report size reached
1.07 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
1.07 MB
./usr/share/xml/scap/ssg/content/ssg-rhel9-xccdf.xml
Max HTML report size reached
1.82 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
1.82 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ds.xml
Max HTML report size reached
1.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
1.5 MB
./usr/share/xml/scap/ssg/content/ssg-rhv4-ocil.xml
Max HTML report size reached
243 KB
./usr/share/xml/scap/ssg/content/ssg-rhv4-xccdf.xml
243 KB
./usr/share/xml/scap/ssg/content/ssg-rhv4-xccdf.xml
Ordering differences only
    
Offset 71, 318 lines modifiedOffset 71, 318 lines modified
71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>71 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
77 ··<cpe-lang:platform-specification>77 ··<cpe-lang:platform-specification>
78 ····<cpe-lang:platform·id="machine">78 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
79 ······<cpe-lang:logical-test·operator="AND"·negate="false">79 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 80 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 81 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 82 ········</cpe-lang:logical-test>
 83 ········<cpe-lang:logical-test·operator="AND"·negate="true">
80 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>84 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 85 ········</cpe-lang:logical-test>
81 ······</cpe-lang:logical-test>86 ······</cpe-lang:logical-test>
82 ····</cpe-lang:platform>87 ····</cpe-lang:platform>
83 ····<cpe-lang:platform·id="not_bootc">88 ····<cpe-lang:platform·id="not_aarch64_arch">
84 ······<cpe-lang:logical-test·operator="AND"·negate="true">89 ······<cpe-lang:logical-test·operator="AND"·negate="true">
85 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>90 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
86 ······</cpe-lang:logical-test>91 ······</cpe-lang:logical-test>
87 ····</cpe-lang:platform>92 ····</cpe-lang:platform>
88 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">93 ····<cpe-lang:platform·id="ipv6_enabled">
89 ······<cpe-lang:logical-test·operator="AND"·negate="false">94 ······<cpe-lang:logical-test·operator="AND"·negate="false">
90 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
91 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>95 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
92 ········</cpe-lang:logical-test> 
93 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
94 ······</cpe-lang:logical-test>96 ······</cpe-lang:logical-test>
95 ····</cpe-lang:platform>97 ····</cpe-lang:platform>
96 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">98 ····<cpe-lang:platform·id="package_systemd">
97 ······<cpe-lang:logical-test·operator="AND"·negate="false">99 ······<cpe-lang:logical-test·operator="AND"·negate="false">
98 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
100 ······</cpe-lang:logical-test>101 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>102 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="system_with_kernel">103 ····<cpe-lang:platform·id="package_postfix">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">104 ······<cpe-lang:logical-test·operator="AND"·negate="false">
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
105 ······</cpe-lang:logical-test>106 ······</cpe-lang:logical-test>
106 ····</cpe-lang:platform>107 ····</cpe-lang:platform>
107 ····<cpe-lang:platform·id="selinux">108 ····<cpe-lang:platform·id="package_shadow-utils">
108 ······<cpe-lang:logical-test·operator="AND"·negate="false">109 ······<cpe-lang:logical-test·operator="AND"·negate="false">
109 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/>110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
110 ······</cpe-lang:logical-test>111 ······</cpe-lang:logical-test>
111 ····</cpe-lang:platform>112 ····</cpe-lang:platform>
112 ····<cpe-lang:platform·id="package_systemd">113 ····<cpe-lang:platform·id="mount_var">
113 ······<cpe-lang:logical-test·operator="AND"·negate="false">114 ······<cpe-lang:logical-test·operator="AND"·negate="false">
114 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
115 ······</cpe-lang:logical-test>116 ······</cpe-lang:logical-test>
116 ····</cpe-lang:platform>117 ····</cpe-lang:platform>
117 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">118 ····<cpe-lang:platform·id="package_firewalld">
118 ······<cpe-lang:logical-test·operator="AND"·negate="false">119 ······<cpe-lang:logical-test·operator="AND"·negate="false">
119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
120 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
122 ······</cpe-lang:logical-test>121 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>122 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="uefi">123 ····<cpe-lang:platform·id="package_rsyslog">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">124 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
127 ······</cpe-lang:logical-test>126 ······</cpe-lang:logical-test>
128 ····</cpe-lang:platform>127 ····</cpe-lang:platform>
129 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">128 ····<cpe-lang:platform·id="system_with_kernel">
130 ······<cpe-lang:logical-test·operator="AND"·negate="false">129 ······<cpe-lang:logical-test·operator="AND"·negate="false">
131 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
132 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
133 ········</cpe-lang:logical-test> 
134 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
135 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
136 ········</cpe-lang:logical-test> 
137 ······</cpe-lang:logical-test>131 ······</cpe-lang:logical-test>
138 ····</cpe-lang:platform>132 ····</cpe-lang:platform>
139 ····<cpe-lang:platform·id="mount_home">133 ····<cpe-lang:platform·id="package_chrony">
140 ······<cpe-lang:logical-test·operator="AND"·negate="false">134 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 136 ······</cpe-lang:logical-test>
 137 ····</cpe-lang:platform>
 138 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
 139 ······<cpe-lang:logical-test·operator="AND"·negate="false">
141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
 141 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 142 ······</cpe-lang:logical-test>
 143 ····</cpe-lang:platform>
 144 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 145 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 147 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
142 ······</cpe-lang:logical-test>148 ······</cpe-lang:logical-test>
143 ····</cpe-lang:platform>149 ····</cpe-lang:platform>
144 ····<cpe-lang:platform·id="x86_64_arch">150 ····<cpe-lang:platform·id="x86_64_arch">
145 ······<cpe-lang:logical-test·operator="AND"·negate="false">151 ······<cpe-lang:logical-test·operator="AND"·negate="false">
146 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>152 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
147 ······</cpe-lang:logical-test>153 ······</cpe-lang:logical-test>
148 ····</cpe-lang:platform>154 ····</cpe-lang:platform>
149 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">155 ····<cpe-lang:platform·id="selinux">
150 ······<cpe-lang:logical-test·operator="AND"·negate="false">156 ······<cpe-lang:logical-test·operator="AND"·negate="false">
151 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
152 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
153 ········</cpe-lang:logical-test> 
154 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
155 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/> 
156 ········</cpe-lang:logical-test> 
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/>
158 ······</cpe-lang:logical-test>158 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>159 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="package_polkit">160 ····<cpe-lang:platform·id="package_polkit">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">161 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>162 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_polkit:def:1"/>
163 ······</cpe-lang:logical-test>163 ······</cpe-lang:logical-test>
164 ····</cpe-lang:platform>164 ····</cpe-lang:platform>
165 ····<cpe-lang:platform·id="not_runtime_kernel_fips_enabled_and_system_with_kernel">165 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
166 ······<cpe-lang:logical-test·operator="AND"·negate="false">166 ······<cpe-lang:logical-test·operator="AND"·negate="false">
167 ········<cpe-lang:logical-test·operator="AND"·negate="true">167 ········<cpe-lang:logical-test·operator="AND"·negate="true">
168 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-runtime_kernel_fips_enabled:def:1"/>168 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
169 ········</cpe-lang:logical-test>169 ········</cpe-lang:logical-test>
 170 ········<cpe-lang:logical-test·operator="AND"·negate="true">
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>171 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
 172 ········</cpe-lang:logical-test>
 173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
171 ······</cpe-lang:logical-test>174 ······</cpe-lang:logical-test>
172 ····</cpe-lang:platform>175 ····</cpe-lang:platform>
173 ····<cpe-lang:platform·id="wifi-iface">176 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">
174 ······<cpe-lang:logical-test·operator="AND"·negate="false">177 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 178 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_wifi_interface:def:1"/>179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-rhv4-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
176 ······</cpe-lang:logical-test>180 ······</cpe-lang:logical-test>
Max diff block lines reached; 235683/249112 bytes (94.61%) of diff not shown.
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
1.96 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ds.xml
Max HTML report size reached
1.71 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
1.7 MB
./usr/share/xml/scap/ssg/content/ssg-sle12-ocil.xml
Max HTML report size reached
175 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
175 KB
./usr/share/xml/scap/ssg/content/ssg-sle12-xccdf.xml
Ordering differences only
    
Offset 72, 385 lines modifiedOffset 72, 385 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
82 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="not_bootc">89 ····<cpe-lang:platform·id="not_aarch64_arch">
85 ······<cpe-lang:logical-test·operator="AND"·negate="true">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
87 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
88 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
89 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
90 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
91 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
92 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
93 ········</cpe-lang:logical-test> 
94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
95 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
96 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
97 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">99 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
98 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
101 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="system_with_kernel">105 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
106 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">111 ····<cpe-lang:platform·id="package_systemd">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
112 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="selinux">116 ····<cpe-lang:platform·id="package_openssh_le_7_4">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_openssh_le_7_4:def:1"/>
117 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_systemd">121 ····<cpe-lang:platform·id="package_postfix">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
122 ······</cpe-lang:logical-test>124 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>125 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">126 ····<cpe-lang:platform·id="package_shadow-utils">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">127 ······<cpe-lang:logical-test·operator="AND"·negate="false">
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
129 ······</cpe-lang:logical-test>129 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>130 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="uefi">131 ····<cpe-lang:platform·id="mount_var">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">132 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
134 ······</cpe-lang:logical-test>134 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>135 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">136 ····<cpe-lang:platform·id="package_zypper">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">137 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
139 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
140 ········</cpe-lang:logical-test> 
141 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
142 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_zypper:def:1"/>
143 ········</cpe-lang:logical-test> 
144 ······</cpe-lang:logical-test>139 ······</cpe-lang:logical-test>
145 ····</cpe-lang:platform>140 ····</cpe-lang:platform>
146 ····<cpe-lang:platform·id="mount_home">141 ····<cpe-lang:platform·id="package_firewalld">
147 ······<cpe-lang:logical-test·operator="AND"·negate="false">142 ······<cpe-lang:logical-test·operator="AND"·negate="false">
148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>143 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
149 ······</cpe-lang:logical-test>144 ······</cpe-lang:logical-test>
150 ····</cpe-lang:platform>145 ····</cpe-lang:platform>
151 ····<cpe-lang:platform·id="mount_var-tmp">146 ····<cpe-lang:platform·id="package_rsyslog">
152 ······<cpe-lang:logical-test·operator="AND"·negate="false">147 ······<cpe-lang:logical-test·operator="AND"·negate="false">
153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>148 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
154 ······</cpe-lang:logical-test>149 ······</cpe-lang:logical-test>
155 ····</cpe-lang:platform>150 ····</cpe-lang:platform>
156 ····<cpe-lang:platform·id="mount_var-log">151 ····<cpe-lang:platform·id="system_with_kernel">
157 ······<cpe-lang:logical-test·operator="AND"·negate="false">152 ······<cpe-lang:logical-test·operator="AND"·negate="false">
158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>153 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
159 ······</cpe-lang:logical-test>154 ······</cpe-lang:logical-test>
160 ····</cpe-lang:platform>155 ····</cpe-lang:platform>
161 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">156 ····<cpe-lang:platform·id="package_chrony">
162 ······<cpe-lang:logical-test·operator="AND"·negate="false">157 ······<cpe-lang:logical-test·operator="AND"·negate="false">
163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>158 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
 159 ······</cpe-lang:logical-test>
 160 ····</cpe-lang:platform>
 161 ····<cpe-lang:platform·id="mount_tmp">
 162 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 163 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
 164 ······</cpe-lang:logical-test>
 165 ····</cpe-lang:platform>
 166 ····<cpe-lang:platform·id="not_s390x_arch">
 167 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
 169 ······</cpe-lang:logical-test>
 170 ····</cpe-lang:platform>
 171 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
 172 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 173 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
164 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>174 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
165 ······</cpe-lang:logical-test>175 ······</cpe-lang:logical-test>
166 ····</cpe-lang:platform>176 ····</cpe-lang:platform>
 177 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 178 ······<cpe-lang:logical-test·operator="OR"·negate="false">
 179 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 180 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
 181 ······</cpe-lang:logical-test>
 182 ····</cpe-lang:platform>
167 ····<cpe-lang:platform·id="x86_64_arch">183 ····<cpe-lang:platform·id="x86_64_arch">
168 ······<cpe-lang:logical-test·operator="AND"·negate="false">184 ······<cpe-lang:logical-test·operator="AND"·negate="false">
169 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>185 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle12-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_x86_64:def:1"/>
170 ······</cpe-lang:logical-test>186 ······</cpe-lang:logical-test>
Max diff block lines reached; 165896/179192 bytes (92.58%) of diff not shown.
2.07 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
2.07 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ds.xml
Max HTML report size reached
1.8 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
1.8 MB
./usr/share/xml/scap/ssg/content/ssg-sle15-ocil.xml
Max HTML report size reached
190 KB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
189 KB
./usr/share/xml/scap/ssg/content/ssg-sle15-xccdf.xml
Ordering differences only
    
Offset 72, 420 lines modifiedOffset 72, 420 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
82 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="not_bootc">89 ····<cpe-lang:platform·id="not_aarch64_arch">
85 ······<cpe-lang:logical-test·operator="AND"·negate="true">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
87 ······</cpe-lang:logical-test> 
88 ····</cpe-lang:platform> 
89 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel"> 
90 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
91 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
92 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/> 
93 ········</cpe-lang:logical-test> 
94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
95 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
96 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
97 ····<cpe-lang:platform·id="package_ufw_and_system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
98 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
100 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
101 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
102 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
103 ····<cpe-lang:platform·id="system_with_kernel">99 ····<cpe-lang:platform·id="os_linux_rhel_gt_or_eq_8_7_and_os_linux_rhel_ne_9_0">
104 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_gt_or_eq_8_7:def:1"/>
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-os_linux_rhel_ne_9_0:def:1"/>
106 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">105 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
111 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>108 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
112 ······</cpe-lang:logical-test>109 ······</cpe-lang:logical-test>
113 ····</cpe-lang:platform>110 ····</cpe-lang:platform>
114 ····<cpe-lang:platform·id="selinux">111 ····<cpe-lang:platform·id="package_systemd">
115 ······<cpe-lang:logical-test·operator="AND"·negate="false">112 ······<cpe-lang:logical-test·operator="AND"·negate="false">
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-selinux_is_enabled:def:1"/>113 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
117 ······</cpe-lang:logical-test>114 ······</cpe-lang:logical-test>
118 ····</cpe-lang:platform>115 ····</cpe-lang:platform>
119 ····<cpe-lang:platform·id="package_systemd">116 ····<cpe-lang:platform·id="package_postfix">
120 ······<cpe-lang:logical-test·operator="AND"·negate="false">117 ······<cpe-lang:logical-test·operator="AND"·negate="false">
121 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
122 ······</cpe-lang:logical-test>119 ······</cpe-lang:logical-test>
123 ····</cpe-lang:platform>120 ····</cpe-lang:platform>
124 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">121 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
125 ······<cpe-lang:logical-test·operator="AND"·negate="false">122 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 123 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
126 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>125 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
129 ······</cpe-lang:logical-test>126 ······</cpe-lang:logical-test>
130 ····</cpe-lang:platform>127 ····</cpe-lang:platform>
131 ····<cpe-lang:platform·id="uefi">128 ····<cpe-lang:platform·id="package_shadow-utils">
132 ······<cpe-lang:logical-test·operator="AND"·negate="false">129 ······<cpe-lang:logical-test·operator="AND"·negate="false">
133 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>130 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
134 ······</cpe-lang:logical-test>131 ······</cpe-lang:logical-test>
135 ····</cpe-lang:platform>132 ····</cpe-lang:platform>
136 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">133 ····<cpe-lang:platform·id="mount_var">
 134 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 135 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var:def:1"/>
 136 ······</cpe-lang:logical-test>
 137 ····</cpe-lang:platform>
 138 ····<cpe-lang:platform·id="package_zypper">
 139 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_zypper:def:1"/>
 141 ······</cpe-lang:logical-test>
 142 ····</cpe-lang:platform>
 143 ····<cpe-lang:platform·id="package_firewalld">
137 ······<cpe-lang:logical-test·operator="AND"·negate="false">144 ······<cpe-lang:logical-test·operator="AND"·negate="false">
138 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>145 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
140 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/> 
141 ······</cpe-lang:logical-test>146 ······</cpe-lang:logical-test>
142 ····</cpe-lang:platform>147 ····</cpe-lang:platform>
143 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">148 ····<cpe-lang:platform·id="package_rsyslog">
144 ······<cpe-lang:logical-test·operator="AND"·negate="false">149 ······<cpe-lang:logical-test·operator="AND"·negate="false">
145 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
146 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
147 ········</cpe-lang:logical-test> 
148 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
149 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_rsyslog:def:1"/>
150 ········</cpe-lang:logical-test> 
151 ······</cpe-lang:logical-test>151 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>152 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="mount_home">153 ····<cpe-lang:platform·id="system_with_kernel">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">154 ······<cpe-lang:logical-test·operator="AND"·negate="false">
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
156 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
157 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
158 ····<cpe-lang:platform·id="mount_var-tmp">158 ····<cpe-lang:platform·id="package_chrony">
159 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-tmp:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
161 ······</cpe-lang:logical-test>161 ······</cpe-lang:logical-test>
162 ····</cpe-lang:platform>162 ····</cpe-lang:platform>
163 ····<cpe-lang:platform·id="mount_var-log">163 ····<cpe-lang:platform·id="mount_tmp">
164 ······<cpe-lang:logical-test·operator="AND"·negate="false">164 ······<cpe-lang:logical-test·operator="AND"·negate="false">
165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_var-log:def:1"/>165 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_tmp:def:1"/>
166 ······</cpe-lang:logical-test>166 ······</cpe-lang:logical-test>
167 ····</cpe-lang:platform>167 ····</cpe-lang:platform>
168 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">168 ····<cpe-lang:platform·id="not_s390x_arch">
169 ······<cpe-lang:logical-test·operator="AND"·negate="false">169 ······<cpe-lang:logical-test·operator="AND"·negate="false">
170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/> 
171 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>170 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
172 ······</cpe-lang:logical-test>171 ······</cpe-lang:logical-test>
173 ····</cpe-lang:platform>172 ····</cpe-lang:platform>
174 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">173 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
175 ······<cpe-lang:logical-test·operator="AND"·negate="false">174 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 175 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>176 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-sle15-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
 177 ······</cpe-lang:logical-test>
 178 ····</cpe-lang:platform>
 179 ····<cpe-lang:platform·id="aarch64_arch_or_x86_64_arch">
 180 ······<cpe-lang:logical-test·operator="OR"·negate="false">
Max diff block lines reached; 179618/193843 bytes (92.66%) of diff not shown.
1.12 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
1.12 MB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ds.xml
Max HTML report size reached
985 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
985 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-ocil.xml
Max HTML report size reached
109 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-xccdf.xml
109 KB
./usr/share/xml/scap/ssg/content/ssg-slmicro5-xccdf.xml
Ordering differences only
    
Offset 72, 307 lines modifiedOffset 72, 307 lines modified
72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>72 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cgeneral-purpose-os">os-srg</xccdf-1.2:reference>
73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>73 ··<xccdf-1.2:reference·href="https://www.niap-ccevs.org/Profile/PP.cfm">ospp</xccdf-1.2:reference>
74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>74 ··<xccdf-1.2:reference·href="https://www.pcisecuritystandards.org/documents/PCI_DSS_v3-2-1.pdf">pcidss</xccdf-1.2:reference>
75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>75 ··<xccdf-1.2:reference·href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0.pdf">pcidss4</xccdf-1.2:reference>
76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>76 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/downloads/?_dl_facet_stigs=operating-systems%2Cunix-linux">stigid</xccdf-1.2:reference>
77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>77 ··<xccdf-1.2:reference·href="https://public.cyber.mil/stigs/srg-stig-tools/">stigref</xccdf-1.2:reference>
78 ··<cpe-lang:platform-specification>78 ··<cpe-lang:platform-specification>
79 ····<cpe-lang:platform·id="machine">79 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_s390x_arch">
80 ······<cpe-lang:logical-test·operator="AND"·negate="false">80 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 81 ········<cpe-lang:logical-test·operator="AND"·negate="true">
 82 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
 83 ········</cpe-lang:logical-test>
 84 ········<cpe-lang:logical-test·operator="AND"·negate="true">
81 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_a_machine:def:1"/>85 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_s390x:def:1"/>
 86 ········</cpe-lang:logical-test>
82 ······</cpe-lang:logical-test>87 ······</cpe-lang:logical-test>
83 ····</cpe-lang:platform>88 ····</cpe-lang:platform>
84 ····<cpe-lang:platform·id="not_bootc">89 ····<cpe-lang:platform·id="not_aarch64_arch">
85 ······<cpe-lang:logical-test·operator="AND"·negate="true">90 ······<cpe-lang:logical-test·operator="AND"·negate="true">
86 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/> 
87 ······</cpe-lang:logical-test> 
88 ····</cpe-lang:platform> 
89 ····<cpe-lang:platform·id="not_osbuild_and_system_with_kernel"> 
90 ······<cpe-lang:logical-test·operator="AND"·negate="false"> 
91 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
92 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_is_osbuild:def:1"/> 
93 ········</cpe-lang:logical-test> 
94 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>91 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>
95 ······</cpe-lang:logical-test>92 ······</cpe-lang:logical-test>
96 ····</cpe-lang:platform>93 ····</cpe-lang:platform>
97 ····<cpe-lang:platform·id="system_with_kernel">94 ····<cpe-lang:platform·id="ipv6_enabled">
98 ······<cpe-lang:logical-test·operator="AND"·negate="false">95 ······<cpe-lang:logical-test·operator="AND"·negate="false">
99 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>96 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-ipv6_enabled:def:1"/>
100 ······</cpe-lang:logical-test>97 ······</cpe-lang:logical-test>
101 ····</cpe-lang:platform>98 ····</cpe-lang:platform>
102 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">99 ····<cpe-lang:platform·id="package_avahi_and_system_with_kernel">
103 ······<cpe-lang:logical-test·operator="AND"·negate="false">100 ······<cpe-lang:logical-test·operator="AND"·negate="false">
104 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>101 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_avahi:def:1"/>
105 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>102 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
106 ······</cpe-lang:logical-test>103 ······</cpe-lang:logical-test>
107 ····</cpe-lang:platform>104 ····</cpe-lang:platform>
108 ····<cpe-lang:platform·id="package_systemd">105 ····<cpe-lang:platform·id="package_systemd">
109 ······<cpe-lang:logical-test·operator="AND"·negate="false">106 ······<cpe-lang:logical-test·operator="AND"·negate="false">
110 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>107 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_systemd:def:1"/>
111 ······</cpe-lang:logical-test>108 ······</cpe-lang:logical-test>
112 ····</cpe-lang:platform>109 ····</cpe-lang:platform>
113 ····<cpe-lang:platform·id="package_iptables_and_service_disabled_firewalld_and_system_with_kernel">110 ····<cpe-lang:platform·id="package_postfix">
114 ······<cpe-lang:logical-test·operator="AND"·negate="false">111 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 112 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_postfix:def:1"/>
 113 ······</cpe-lang:logical-test>
 114 ····</cpe-lang:platform>
 115 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">
 116 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
115 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>118 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
116 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/> 
117 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>119 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
118 ······</cpe-lang:logical-test>120 ······</cpe-lang:logical-test>
119 ····</cpe-lang:platform>121 ····</cpe-lang:platform>
120 ····<cpe-lang:platform·id="uefi">122 ····<cpe-lang:platform·id="package_shadow-utils">
121 ······<cpe-lang:logical-test·operator="AND"·negate="false">123 ······<cpe-lang:logical-test·operator="AND"·negate="false">
122 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_boot_mode_is_uefi:def:1"/>124 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_shadow-utils:def:1"/>
123 ······</cpe-lang:logical-test>125 ······</cpe-lang:logical-test>
124 ····</cpe-lang:platform>126 ····</cpe-lang:platform>
125 ····<cpe-lang:platform·id="package_firewalld_and_package_nftables_and_system_with_kernel">127 ····<cpe-lang:platform·id="package_zypper">
 128 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_zypper:def:1"/>
 130 ······</cpe-lang:logical-test>
 131 ····</cpe-lang:platform>
 132 ····<cpe-lang:platform·id="package_firewalld">
126 ······<cpe-lang:logical-test·operator="AND"·negate="false">133 ······<cpe-lang:logical-test·operator="AND"·negate="false">
127 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>134 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_firewalld:def:1"/>
128 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>135 ······</cpe-lang:logical-test>
 136 ····</cpe-lang:platform>
 137 ····<cpe-lang:platform·id="system_with_kernel">
 138 ······<cpe-lang:logical-test·operator="AND"·negate="false">
129 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>139 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
130 ······</cpe-lang:logical-test>140 ······</cpe-lang:logical-test>
131 ····</cpe-lang:platform>141 ····</cpe-lang:platform>
132 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw">142 ····<cpe-lang:platform·id="package_chrony">
133 ······<cpe-lang:logical-test·operator="AND"·negate="false">143 ······<cpe-lang:logical-test·operator="AND"·negate="false">
134 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
135 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/> 
136 ········</cpe-lang:logical-test> 
137 ········<cpe-lang:logical-test·operator="AND"·negate="true"> 
138 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_chrony:def:1"/>
139 ········</cpe-lang:logical-test> 
140 ······</cpe-lang:logical-test>145 ······</cpe-lang:logical-test>
141 ····</cpe-lang:platform>146 ····</cpe-lang:platform>
142 ····<cpe-lang:platform·id="mount_home">147 ····<cpe-lang:platform·id="not_s390x_arch">
143 ······<cpe-lang:logical-test·operator="AND"·negate="false">148 ······<cpe-lang:logical-test·operator="AND"·negate="false">
144 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_mount_home:def:1"/>149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_not_s390x:def:1"/>
145 ······</cpe-lang:logical-test>150 ······</cpe-lang:logical-test>
146 ····</cpe-lang:platform>151 ····</cpe-lang:platform>
147 ····<cpe-lang:platform·id="package_snmpd_and_system_with_kernel">152 ····<cpe-lang:platform·id="grub2_and_system_with_kernel">
148 ······<cpe-lang:logical-test·operator="AND"·negate="false">153 ······<cpe-lang:logical-test·operator="AND"·negate="false">
149 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_snmpd:def:1"/>154 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-installed_env_has_grub2_package:def:1"/>
150 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-system_with_kernel:def:1"/>
151 ······</cpe-lang:logical-test>156 ······</cpe-lang:logical-test>
152 ····</cpe-lang:platform>157 ····</cpe-lang:platform>
153 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld_and_service_disabled_ufw">158 ····<cpe-lang:platform·id="package_nftables_and_service_disabled_firewalld">
154 ······<cpe-lang:logical-test·operator="AND"·negate="false">159 ······<cpe-lang:logical-test·operator="AND"·negate="false">
155 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>160 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
156 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>161 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_firewalld:def:1"/>
157 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-service_disabled_ufw:def:1"/> 
158 ······</cpe-lang:logical-test>162 ······</cpe-lang:logical-test>
159 ····</cpe-lang:platform>163 ····</cpe-lang:platform>
160 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">164 ····<cpe-lang:platform·id="not_package_nftables_and_not_package_ufw_and_package_iptables">
161 ······<cpe-lang:logical-test·operator="AND"·negate="false">165 ······<cpe-lang:logical-test·operator="AND"·negate="false">
162 ········<cpe-lang:logical-test·operator="AND"·negate="true">166 ········<cpe-lang:logical-test·operator="AND"·negate="true">
163 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>167 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_nftables:def:1"/>
164 ········</cpe-lang:logical-test>168 ········</cpe-lang:logical-test>
165 ········<cpe-lang:logical-test·operator="AND"·negate="true">169 ········<cpe-lang:logical-test·operator="AND"·negate="true">
166 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>170 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_ufw:def:1"/>
167 ········</cpe-lang:logical-test>171 ········</cpe-lang:logical-test>
168 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>172 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
169 ······</cpe-lang:logical-test>173 ······</cpe-lang:logical-test>
170 ····</cpe-lang:platform>174 ····</cpe-lang:platform>
171 ····<cpe-lang:platform·id="not_aarch64_arch_and_not_ppc64le_arch_and_system_with_kernel">175 ····<cpe-lang:platform·id="package_iptables">
 176 ······<cpe-lang:logical-test·operator="AND"·negate="false">
 177 ········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-package_iptables:def:1"/>
 178 ······</cpe-lang:logical-test>
 179 ····</cpe-lang:platform>
 180 ····<cpe-lang:platform·id="not_bootc_and_not_container">
172 ······<cpe-lang:logical-test·operator="AND"·negate="false">181 ······<cpe-lang:logical-test·operator="AND"·negate="false">
173 ········<cpe-lang:logical-test·operator="AND"·negate="true">182 ········<cpe-lang:logical-test·operator="AND"·negate="true">
174 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-proc_sys_kernel_osrelease_arch_aarch64:def:1"/>183 ··········<cpe-lang:check-fact-ref·system="http://oval.mitre.org/XMLSchema/oval-definitions-5"·href="ssg-slmicro5-cpe-oval.xml"·id-ref="oval:ssg-bootc:def:1"/>
Max diff block lines reached; 98411/111177 bytes (88.52%) of diff not shown.